{"slug":"ietf-puts-agent-to-agent-communication-on-a-standards-track","citations":[{"url":"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto","committed_hash":"sha256:b19285277d2f97a707bf3d280a6fc65e6fa226c883a9ade742882073fef85a6b","committed_hash_short":"sha256:b1928527…fef85a6b","mime_type":"text/html","committed_at":"2026-07-28T18:00:25.787077+00:00","content_snapshot":"<!DOCTYPE html><html lang=\"en\" dir=\"ltr\" class=\"__variable_bbcc58 __variable_948ce5 __variable_9ded40 __variable_3f4575 __variable_16cd69\"><head><meta charSet=\"utf-8\"/><meta name=\"viewport\" content=\"width=device-width, initial-scale=1, viewport-fit=cover\"/><link rel=\"preload\" as=\"image\" href=\"https://www.facebook.com/tr?id=1937494190493436&amp;ev=PageView&amp;noscript=1\"/><link rel=\"stylesheet\" href=\"/_next/static/css/a78fa145c089ec40.css?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" data-precedence=\"next\"/><link rel=\"stylesheet\" href=\"/_next/static/css/470dc7a093659a24.css?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" data-precedence=\"next\"/><link rel=\"stylesheet\" href=\"/_next/static/css/d7a984aa9a9fcc2c.css?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" data-precedence=\"next\"/><link rel=\"preload\" as=\"script\" fetchPriority=\"low\" href=\"/_next/static/chunks/webpack-dfed7d1a04fd289f.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\"/><script src=\"/_next/static/chunks/fd9d1056-3473d42f2c06b95a.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/2117-7782567365cf43d1.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/main-app-be3d940aef6bd3eb.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/5878-dbd6ed66767b4bc6.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/2957-135fdf77983e5820.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/7363-1b3fd7d0da0ebc28.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/4182-aee685f13a26bbd8.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/8041-f3df4595b34e4e85.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/482-5c810f0566082c89.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/app/%5Blang%5D/%5Bslug%5D/page-e0c122d0071f8e69.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/app/layout-4e6ae73d356025e1.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script src=\"/_next/static/chunks/app/not-found-c019844bdcd8d240.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script><script async=\"\" src=\"https://www.googletagmanager.com/gtag/js?id=G-7LWRNQMJYQ\"></script><title>IETF Weighs an AI Agent Protocol Standard in 2026 | Nerd Level Tech</title><meta name=\"description\" content=\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\"/><link rel=\"canonical\" href=\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"/><link rel=\"alternate\" hrefLang=\"en-US\" href=\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"/><link rel=\"alternate\" hrefLang=\"ar-EG\" href=\"https://nerdleveltech.com/ar/ietf-ai-agent-protocol-standard-agentproto\"/><meta property=\"og:title\" content=\"IETF Weighs an AI Agent Protocol Standard in 2026\"/><meta property=\"og:description\" content=\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\"/><meta property=\"og:url\" content=\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"/><meta property=\"og:image\" content=\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\"/><meta property=\"og:image:width\" content=\"1200\"/><meta property=\"og:image:height\" content=\"630\"/><meta property=\"og:image:alt\" content=\"IETF Weighs an AI Agent Protocol Standard in 2026\"/><meta property=\"og:type\" content=\"article\"/><meta property=\"article:published_time\" content=\"2026-07-24T00:00:00.000Z\"/><meta name=\"twitter:card\" content=\"summary_large_image\"/><meta name=\"twitter:title\" content=\"IETF Weighs an AI Agent Protocol Standard in 2026\"/><meta name=\"twitter:description\" content=\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\"/><meta name=\"twitter:image\" content=\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\"/><meta name=\"twitter:image:width\" content=\"1200\"/><meta name=\"twitter:image:height\" content=\"630\"/><meta name=\"twitter:image:alt\" content=\"IETF Weighs an AI Agent Protocol Standard in 2026\"/><link rel=\"icon\" href=\"/favicon.svg\" type=\"image/svg+xml\"/><link rel=\"icon\" href=\"/icon.svg\" type=\"image/svg+xml\"/><meta name=\"next-size-adjust\"/><meta name=\"msvalidate.01\" content=\"63B94FDFC56A65B5E9E316E474AB9D0D\"/><link rel=\"alternate\" type=\"application/rss+xml\" title=\"NerdLevelTech — Articles\" href=\"/rss.xml\"/><link rel=\"alternate\" type=\"application/atom+xml\" title=\"NerdLevelTech — Articles\" href=\"/atom.xml\"/><link rel=\"alternate\" type=\"application/rss+xml\" title=\"NerdLevelTech — Podcast\" href=\"/podcast.xml\"/><link rel=\"alternate\" type=\"application/rss+xml\" title=\"NerdLevelTech — Courses\" href=\"/courses-rss.xml\"/><link rel=\"alternate\" type=\"application/rss+xml\" title=\"NerdLevelTech — Remote Tech Jobs\" href=\"/jobs-rss.xml\"/><script>(() => {\n var t = localStorage.getItem('theme');\n var d = document.documentElement;\n if (t === 'dark' || (!t || t === 'system') && window.matchMedia('(prefers-color-scheme: dark)').matches) {\n d.classList.add('dark');\n } else {\n d.classList.remove('dark');\n }\n try {\n var consent = localStorage.getItem('nlt-cookie-consent');\n if (consent) d.setAttribute('data-nlt-consent', consent);\n } catch (e) {}\n})();</script><script>(function(){\n  window.clarity = window.clarity || function(){ (window.clarity.q = window.clarity.q || []).push(arguments); };\n  var loaded = false;\n  function loadClarity() {\n    if (loaded) return;\n    loaded = true;\n    var s = document.createElement('script');\n    s.async = true;\n    s.src = 'https://www.clarity.ms/tag/uiskr3p74z';\n    document.head.appendChild(s);\n    ['scroll','click','mousemove','touchstart'].forEach(function(e){\n      document.removeEventListener(e, loadClarity);\n    });\n  }\n  if (document.readyState === 'complete') {\n    setTimeout(loadClarity, 3000);\n  } else {\n    window.addEventListener('load', function() { setTimeout(loadClarity, 3000); });\n  }\n  ['scroll','click','mousemove','touchstart'].forEach(function(e){\n    document.addEventListener(e, loadClarity, { once: true, passive: true });\n  });\n})();</script><script>\n window.dataLayer = window.dataLayer || [];\n function gtag(){dataLayer.push(arguments);}\n\n // Default consent to 'denied' for GDPR compliance (EU/EEA users)\n gtag('consent', 'default', {\n 'ad_storage': 'denied',\n 'ad_user_data': 'denied',\n 'ad_personalization': 'denied',\n 'analytics_storage': 'denied'\n });\n\n gtag('js', new Date());\n // Skip the initial config + pageview for admin routes. SPA navigations\n // away from /admin still work — AnalyticsListeners fires page_view on\n // route change for any non-admin path it sees next.\n if (!/^\\/admin(\\/|$)/.test(window.location.pathname)) {\n gtag('config', 'G-7LWRNQMJYQ');\n }\n\n // Check if user already consented and update consent accordingly\n try {\n var consent = localStorage.getItem('nlt-cookie-consent');\n if (consent === 'accepted') {\n gtag('consent', 'update', {\n 'ad_storage': 'granted',\n 'ad_user_data': 'granted',\n 'ad_personalization': 'granted',\n 'analytics_storage': 'granted'\n });\n }\n } catch(e) {}\n</script><script>(function(){\n var loaded = false;\n function loadBrevo() {\n if (loaded) return;\n loaded = true;\n var s = document.createElement('script');\n s.src = 'https://cdn.brevo.com/js/sdk-loader.js';\n s.async = true;\n s.onload = function() {\n window.Brevo = window.Brevo || [];\n Brevo.push([\"init\", { client_key:\"07ps0c5debu6rk7jhbq1fkyj\" }]);\n };\n document.head.appendChild(s);\n ['scroll','click','mousemove','touchstart'].forEach(function(e){\n document.removeEventListener(e, loadBrevo);\n });\n }\n if (document.readyState === 'complete') {\n setTimeout(loadBrevo, 3000);\n } else {\n window.addEventListener('load', function() { setTimeout(loadBrevo, 3000); });\n }\n ['scroll','click','mousemove','touchstart'].forEach(function(e){\n document.addEventListener(e, loadBrevo, { once: true, passive: true });\n });\n})();</script><script>(function(){\n  if (window.fbq) return;\n  var n = window.fbq = function(){ n.callMethod ? n.callMethod.apply(n, arguments) : n.queue.push(arguments); };\n  if (!window._fbq) window._fbq = n;\n  n.push = n; n.loaded = true; n.version = '2.0'; n.queue = [];\n  fbq('init', '1937494190493436');\n  fbq('track', 'PageView');\n  var loaded = false;\n  function loadPixel() {\n    if (loaded) return;\n    loaded = true;\n    var s = document.createElement('script');\n    s.async = true;\n    s.src = 'https://connect.facebook.net/en_US/fbevents.js';\n    document.head.appendChild(s);\n    ['scroll','click','mousemove','touchstart'].forEach(function(e){\n      document.removeEventListener(e, loadPixel);\n    });\n  }\n  if (document.readyState === 'complete') {\n    setTimeout(loadPixel, 3000);\n  } else {\n    window.addEventListener('load', function() { setTimeout(loadPixel, 3000); });\n  }\n  ['scroll','click','mousemove','touchstart'].forEach(function(e){\n    document.addEventListener(e, loadPixel, { once: true, passive: true });\n  });\n})();</script><noscript><img height=\"1\" width=\"1\" style=\"display:none\" src=\"https://www.facebook.com/tr?id=1937494190493436&amp;ev=PageView&amp;noscript=1\" alt=\"\"/></noscript><script src=\"/_next/static/chunks/polyfills-42372ed130431b0a.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" noModule=\"\"></script><style id=\"__jsx-69e97639d407de6e\">.nlt-nav-link{padding:8px 14px;-webkit-border-radius:999px;-moz-border-radius:999px;border-radius:999px;font-size:16px;color:var(--txt-1);font-weight:500;text-decoration:none;-webkit-transition:color.2s ease,background.2s ease;-moz-transition:color.2s ease,background.2s ease;-o-transition:color.2s ease,background.2s ease;transition:color.2s ease,background.2s ease}.nlt-nav-link:hover{color:var(--txt-0);background:rgba(10,14,22,.04)}.dark .nlt-nav-link:hover{background:rgba(255,255,255,.04)}.nlt-icon-btn{width:38px;height:38px;-webkit-border-radius:12px;-moz-border-radius:12px;border-radius:12px;display:-webkit-inline-box;display:-webkit-inline-flex;display:-moz-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:center;-webkit-justify-content:center;-moz-box-pack:center;-ms-flex-pack:center;justify-content:center;background:transparent;border:1px solid var(--line);color:var(--txt-1);-webkit-transition:all.2s ease;-moz-transition:all.2s ease;-o-transition:all.2s ease;transition:all.2s ease;text-decoration:none;cursor:pointer}.nlt-icon-btn:hover{color:var(--brand-300);border-color:var(--line-strong)}.nlt-avatar-btn{width:34px;height:34px;-webkit-border-radius:999px;-moz-border-radius:999px;border-radius:999px;display:-webkit-inline-box;display:-webkit-inline-flex;display:-moz-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:center;-webkit-justify-content:center;-moz-box-pack:center;-ms-flex-pack:center;justify-content:center;background:-webkit-linear-gradient(315deg,var(--brand-500),var(--brand-700));background:-moz-linear-gradient(315deg,var(--brand-500),var(--brand-700));background:-o-linear-gradient(315deg,var(--brand-500),var(--brand-700));background:linear-gradient(135deg,var(--brand-500),var(--brand-700));color:#001520;font-weight:700;font-size:13px;border:1px solid rgba(56,182,240,.4);cursor:pointer}.nlt-avatar-btn:hover{-webkit-box-shadow:0 0 0 4px rgba(56,182,240,.12);-moz-box-shadow:0 0 0 4px rgba(56,182,240,.12);box-shadow:0 0 0 4px rgba(56,182,240,.12)}.nlt-user-wrap{position:relative;display:-webkit-inline-box;display:-webkit-inline-flex;display:-moz-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;gap:8px}.nlt-user-menu{position:absolute;top:46px;inset-inline-end:0;min-width:220px;padding:8px;background:var(--ink-2);border:1px solid var(--line-strong);-webkit-border-radius:14px;-moz-border-radius:14px;border-radius:14px;-webkit-box-shadow:0 30px 60px -20px rgba(0,0,0,.5);-moz-box-shadow:0 30px 60px -20px rgba(0,0,0,.5);box-shadow:0 30px 60px -20px rgba(0,0,0,.5);z-index:60}.nlt-user-menu-head{padding:8px 10px 10px;border-bottom:1px solid var(--line);margin-bottom:4px}.nlt-user-menu-item{display:block;width:100%;padding:8px 10px;-webkit-border-radius:8px;-moz-border-radius:8px;border-radius:8px;font-size:13px;color:var(--txt-1);background:transparent;border:0;font-family:inherit;text-align:start;cursor:pointer;text-decoration:none}.nlt-user-menu-item:hover{color:var(--txt-0);background:rgba(10,14,22,.04)}.dark .nlt-user-menu-item:hover{background:rgba(255,255,255,.04)}.nlt-user-menu-danger{color:#f87171}.nlt-user-menu-danger:hover{color:#fca5a5!important}.nlt-mobile-only.jsx-69e97639d407de6e{position:relative;display:none}.nlt-mobile-drawer{position:absolute;top:46px;inset-inline-end:0;min-width:240px;padding:8px;background:var(--ink-2);border:1px solid var(--line-strong);-webkit-border-radius:14px;-moz-border-radius:14px;border-radius:14px;-webkit-box-shadow:0 30px 60px -20px rgba(0,0,0,.5);-moz-box-shadow:0 30px 60px -20px rgba(0,0,0,.5);box-shadow:0 30px 60px -20px rgba(0,0,0,.5);z-index:60}.nlt-mobile-nav{display:-webkit-box;display:-webkit-flex;display:-moz-box;display:-ms-flexbox;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;-webkit-flex-direction:column;-moz-box-orient:vertical;-moz-box-direction:normal;-ms-flex-direction:column;flex-direction:column;gap:2px}.nlt-mobile-link{padding:10px 12px;-webkit-border-radius:10px;-moz-border-radius:10px;border-radius:10px;font-size:14px;color:var(--txt-1);background:transparent;border:0;font-family:inherit;text-align:start;cursor:pointer;text-decoration:none}.nlt-mobile-link:hover{color:var(--txt-0);background:rgba(10,14,22,.04)}.dark .nlt-mobile-link:hover{background:rgba(255,255,255,.04)}@media(max-width:980px){.nlt-nav-desk{display:none!important}.nlt-mobile-only.jsx-69e97639d407de6e{display:block}.nlt-signin-btn{display:none}}@media(max-width:540px){.nlt-topbar-root .nlt-btn-primary{padding:8px 12px!important;font-size:12.5px!important}}</style><style id=\"__jsx-6d81f11809c7f54d\">.nlt-foot.jsx-6d81f11809c7f54d{padding:64px 0 36px;border-top:1px solid var(--line);margin-top:40px}.nlt-foot-top.jsx-6d81f11809c7f54d{display:grid;grid-template-columns:1.6fr repeat(5,1fr);gap:32px;padding-bottom:56px}@media(max-width:1080px){.nlt-foot-top.jsx-6d81f11809c7f54d{grid-template-columns:1fr 1fr 1fr}}@media(max-width:600px){.nlt-foot-top.jsx-6d81f11809c7f54d{grid-template-columns:1fr 1fr}}.nlt-foot-col ul{list-style:none;padding:0;margin:14px 0 0;display:-webkit-box;display:-webkit-flex;display:-moz-box;display:-ms-flexbox;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;-webkit-flex-direction:column;-moz-box-orient:vertical;-moz-box-direction:normal;-ms-flex-direction:column;flex-direction:column;gap:10px}.nlt-foot-col a{color:var(--txt-1);font-size:13.5px;-webkit-transition:color.15s ease;-moz-transition:color.15s ease;-o-transition:color.15s ease;transition:color.15s ease;text-decoration:none}.nlt-foot-col a:hover{color:var(--brand-300)}.nlt-foot-bot.jsx-6d81f11809c7f54d{display:-webkit-box;display:-webkit-flex;display:-moz-box;display:-ms-flexbox;display:flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:justify;-webkit-justify-content:space-between;-moz-box-pack:justify;-ms-flex-pack:justify;justify-content:space-between;gap:24px;padding-top:22px;border-top:1px solid var(--line);-webkit-flex-wrap:wrap;-ms-flex-wrap:wrap;flex-wrap:wrap}.nlt-foot-socials.jsx-6d81f11809c7f54d{display:-webkit-box;display:-webkit-flex;display:-moz-box;display:-ms-flexbox;display:flex;gap:8px}.nlt-social{width:34px;height:34px;-webkit-border-radius:10px;-moz-border-radius:10px;border-radius:10px;display:-webkit-inline-box;display:-webkit-inline-flex;display:-moz-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-webkit-align-items:center;-moz-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:center;-webkit-justify-content:center;-moz-box-pack:center;-ms-flex-pack:center;justify-content:center;background:var(--ink-2);border:1px solid var(--line);color:var(--txt-1);font-size:13px;font-weight:600;-webkit-transition:all.2s ease;-moz-transition:all.2s ease;-o-transition:all.2s ease;transition:all.2s ease;text-decoration:none}.nlt-social:hover{color:var(--brand-300);border-color:var(--brand-500)}.nlt-lang{padding:5px 10px;-webkit-border-radius:8px;-moz-border-radius:8px;border-radius:8px;background:transparent;border:1px solid var(--line);color:var(--txt-2);font-family:var(--f-mono);font-size:11px;letter-spacing:.1em;cursor:pointer}.nlt-lang.on{background:rgba(56,182,240,.12);color:var(--brand-300);border-color:rgba(56,182,240,.3)}.nlt-foot-pub.jsx-6d81f11809c7f54d{margin-top:22px;text-align:center}.nlt-foot-pub-link{font-family:var(--f-mono);font-size:11.5px;letter-spacing:.08em;color:var(--txt-3);text-decoration:none;-webkit-transition:color.15s ease;-moz-transition:color.15s ease;-o-transition:color.15s ease;transition:color.15s ease}.nlt-foot-pub-link:hover{color:var(--brand-300)}.nlt-foot-pub-brand{color:var(--txt-1);font-weight:600}.nlt-foot-pub-link:hover .nlt-foot-pub-brand{color:var(--brand-300)}</style></head><body class=\"nlt-newlook\"><script>(() => {\n var RTL_LANGS = ['ar', 'he', 'fa', 'ur'];\n var pathname = window.location.pathname;\n var langMatch = pathname.match(/^\\/([a-z]{2})(\\/|$)/);\n var lang = langMatch ? langMatch[1] : 'en';\n var isRTL = RTL_LANGS.indexOf(lang) !== -1;\n document.documentElement.dir = isRTL ? 'rtl' : 'ltr';\n document.documentElement.lang = lang;\n})();</script><div style=\"min-height:100vh;display:flex;flex-direction:column;background:var(--ink-1);color:var(--txt-0)\"><header style=\"position:sticky;top:0;z-index:50;background:transparent;backdrop-filter:none;-webkit-backdrop-filter:none;border-bottom:1px solid transparent;transition:all .25s ease\" class=\"jsx-69e97639d407de6e nlt-topbar-root\"><div style=\"display:flex;align-items:center;gap:16px;height:68px\" class=\"jsx-69e97639d407de6e nlt-shell\"><a style=\"display:flex;align-items:center;gap:10px;text-decoration:none;color:inherit\" href=\"/\"><svg width=\"26\" height=\"26\" viewBox=\"0 0 80 80\" aria-hidden=\"true\"><defs><linearGradient id=\"nlt-bm\" x1=\"0\" y1=\"0\" x2=\"1\" y2=\"1\"><stop offset=\"0%\" stop-color=\"#5ec8f7\"></stop><stop offset=\"100%\" stop-color=\"#1e96d4\"></stop></linearGradient></defs><circle cx=\"40\" cy=\"40\" r=\"30\" fill=\"url(#nlt-bm)\" opacity=\"0.18\"></circle><circle cx=\"40\" cy=\"40\" r=\"18\" fill=\"url(#nlt-bm)\"></circle><circle cx=\"46\" cy=\"34\" r=\"5\" fill=\"#fff\"></circle><path d=\"M8 14h12M60 14h12M8 66h12M60 66h12\" stroke=\"url(#nlt-bm)\" stroke-width=\"4\" stroke-linecap=\"round\"></path></svg><span style=\"font-weight:600;letter-spacing:-0.02em;font-size:16px;color:var(--txt-0)\">Nerd<em style=\"font-family:var(--f-display);font-style:italic;color:var(--accent-italic);margin:0 2px;font-weight:400\">Level</em>Tech</span></a><nav style=\"display:flex;gap:4px;margin-inline-start:16px\" class=\"jsx-69e97639d407de6e nlt-nav-desk\"><a class=\"nlt-nav-link\" href=\"/nerdo\">Nerdo</a><a class=\"nlt-nav-link\" href=\"/courses\">Courses</a><a class=\"nlt-nav-link\" href=\"/guides\">Guides</a><a class=\"nlt-nav-link\" href=\"/tools\">Tools</a><a class=\"nlt-nav-link\" href=\"/podcast\">Cast</a><a class=\"nlt-nav-link\" href=\"/jobs\">Jobs</a><a class=\"nlt-nav-link\" href=\"/posts\">Blog</a><a class=\"nlt-nav-link\" href=\"/trending\">Trending</a><a class=\"nlt-nav-link\" href=\"/posts?category=news\">News</a></nav><div style=\"flex:1\" class=\"jsx-69e97639d407de6e\"></div><button type=\"button\" aria-label=\"Search\" title=\"Search (⌘K)\" class=\"jsx-69e97639d407de6e nlt-icon-btn\"><svg width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" class=\"jsx-69e97639d407de6e\"><circle cx=\"11\" cy=\"11\" r=\"7\" class=\"jsx-69e97639d407de6e\"></circle><path d=\"m20 20-3.5-3.5\" class=\"jsx-69e97639d407de6e\"></path></svg></button><button type=\"button\" aria-label=\"Switch to Arabic\" title=\"العربية\" style=\"font-weight:600;font-size:12px;letter-spacing:0.05em;font-family:system-ui, sans-serif\" class=\"jsx-69e97639d407de6e nlt-icon-btn\">ع</button><button aria-label=\"Toggle theme\" type=\"button\" class=\"jsx-69e97639d407de6e nlt-icon-btn\"><svg width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" class=\"jsx-69e97639d407de6e\"><path d=\"M21 12.79A9 9 0 1 1 11.21 3 7 7 0 0 0 21 12.79z\" class=\"jsx-69e97639d407de6e\"></path></svg></button><button type=\"button\" style=\"padding:8px 14px;font-size:13px\" class=\"jsx-69e97639d407de6e nlt-btn nlt-btn-ghost nlt-signin-btn\">Sign in</button><button type=\"button\" style=\"padding:10px 16px\" class=\"jsx-69e97639d407de6e nlt-btn nlt-btn-primary\">Start free<svg width=\"14\" height=\"14\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2.5\" style=\"transform:none\" class=\"jsx-69e97639d407de6e\"><path d=\"M5 12h14M13 5l7 7-7 7\" class=\"jsx-69e97639d407de6e\"></path></svg></button><div class=\"jsx-69e97639d407de6e nlt-mobile-only\"><button type=\"button\" aria-label=\"Open menu\" aria-expanded=\"false\" class=\"jsx-69e97639d407de6e nlt-icon-btn\"><svg width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" class=\"jsx-69e97639d407de6e\"><line x1=\"3\" y1=\"6\" x2=\"21\" y2=\"6\" class=\"jsx-69e97639d407de6e\"></line><line x1=\"3\" y1=\"12\" x2=\"21\" y2=\"12\" class=\"jsx-69e97639d407de6e\"></line><line x1=\"3\" y1=\"18\" x2=\"21\" y2=\"18\" class=\"jsx-69e97639d407de6e\"></line></svg></button></div></div></header><main class=\"nlt-shell nlt-main-shell\" style=\"flex:1;width:100%;min-width:0\"><div style=\"width:100%;min-width:0\"><script type=\"application/ld+json\">[{\"@context\":\"https://schema.org\",\"@type\":\"Article\",\"headline\":\"IETF Weighs an AI Agent Protocol Standard in 2026\",\"description\":\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\",\"image\":\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\",\"author\":{\"@type\":\"Person\",\"name\":\"Nerd Level Tech\",\"url\":\"https://nerdleveltech.com\"},\"publisher\":{\"@type\":\"Organization\",\"name\":\"Nerd Level Tech\",\"url\":\"https://nerdleveltech.com\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https://nerdleveltech.com/images/logo.png\",\"width\":512,\"height\":512}},\"datePublished\":\"2026-07-24T00:00:00.000Z\",\"dateModified\":\"2026-07-24T00:00:00.000Z\",\"mainEntityOfPage\":{\"@type\":\"WebPage\",\"@id\":\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"},\"url\":\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\",\"keywords\":\"IETF, AI agent protocol, agentproto, MCP, A2A, agent interoperability, agentic ai\",\"articleSection\":\"ai-ml\"},{\"@context\":\"https://schema.org\",\"@type\":\"BreadcrumbList\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https://nerdleveltech.com/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https://nerdleveltech.com/blog\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"IETF Weighs an AI Agent Protocol Standard in 2026\",\"item\":\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\"}]},{\"@context\":\"https://schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Is the IETF standardizing AI agent protocols?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Not yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.1 A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.10 The authoritative outcome of the session is posted to the IETF Datatracker.\"}},{\"@type\":\"Question\",\"name\":\"What is the agentproto BoF at IETF 126?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Agentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.17\"}},{\"@type\":\"Question\",\"name\":\"How is MCP different from A2A?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"MCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.35 They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.7\"}},{\"@type\":\"Question\",\"name\":\"What would an IETF RFC add that MCP and A2A don't cover?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.7 These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\"}},{\"@type\":\"Question\",\"name\":\"Why is prompt injection worse in multi-agent systems?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Because it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.7 OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.9 Footnotes\\n\\n\\n\\\"Birds of a Feather at IETF 126,\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). https://www.ietf.org/blog/ietf126-bofs/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7\\n\\n\\n\\\"Birds of a Feather (BOF),\\\" IETF process documentation, and \\\"Introduction to the IETF\\\" (rough consensus and running code). https://www.ietf.org/process/bofs/ ↩ ↩2 ↩3 ↩4\\n\\n\\n\\\"MCP joins the Agentic AI Foundation,\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/ ↩ ↩2 ↩3\\n\\n\\n\\\"The 2026-07-28 MCP Specification Release Candidate,\\\" Model Context Protocol Blog. https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/ ↩\\n\\n\\n\\\"Google Cloud donates A2A to Linux Foundation,\\\" Google Developers Blog, 23 June 2025. https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/ ↩ ↩2\\n\\n\\n\\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\" Google Open Source Blog, 16 April 2026 (\\\"over 100 technology companies now supporting the project\\\"; A2A announced 9 April 2025, donated 23 June 2025). https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html ↩\\n\\n\\n\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\"Prompt injection attacks are notoriously difficult to prevent\\\"). This individual Internet-Draft is expired and \\\"has no formal standing in the IETF standards process.\\\" Full text: https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt — status: https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10\\n\\n\\n\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-agentproto-usecases (the current, active revision). https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/ ↩\\n\\n\\n\\\"OWASP Top 10 for LLM Applications 2025,\\\" LLM01: Prompt Injection. https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf ↩ ↩2\\n\\n\\n\\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm ↩ ↩2\"}}]}]</script><div class=\"lg:grid lg:grid-cols-[auto_minmax(0,1fr)_17.5rem] lg:gap-8\" dir=\"ltr\"><aside class=\"hidden lg:block w-14\"><div class=\"sticky top-32 flex flex-col items-center gap-4\"><div class=\"flex flex-col items-center gap-4 rounded-2xl border border-[var(--line)] bg-[color:var(--ink-2)] px-3 py-3 shadow-[0_20px_40px_-30px_rgba(15,23,42,0.45)] dark:border-[var(--line)] dark:bg-[color:var(--ink-1)]\"><button class=\"group flex items-center justify-center rounded-full bg-[color:var(--ink-2)] p-3 shadow-md backdrop-blur-sm transition-all duration-200 hover:bg-[color:var(--ink-2)] hover:shadow-lg hover:scale-110 dark:bg-[color:var(--ink-2)] dark:hover:bg-[color:var(--ink-4)]\" aria-label=\"Share this content\"><svg class=\"h-5 w-5 text-[color:var(--txt-2)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-3)]\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M8.684 13.342C8.886 12.938 9 12.482 9 12c0-.482-.114-.938-.316-1.342m0 2.684a3 3 0 110-2.684m0 2.684l6.632 3.316m-6.632-6l6.632-3.316m0 0a3 3 0 105.367-2.684 3 3 0 00-5.367 2.684zm0 9.316a3 3 0 105.367 2.684 3 3 0 00-5.367-2.684z\"></path></svg></button><span class=\"text-xs text-[color:var(--txt-2)]\">Share</span></div></div></aside><article class=\"prose dark:prose-invert max-w-none\"><div class=\"not-prose mb-3\"><span class=\"font-mono text-[11px] tracking-[0.18em] uppercase text-brand-300\">ai-ml</span></div><h1 class=\"nlt-h-display !mt-0 !mb-2\" style=\"font-size:clamp(32px, 4.6vw, 56px)\">IETF Weighs an AI Agent Protocol Standard in 2026</h1><div class=\"not-prose !mt-3 flex flex-wrap items-center gap-3\"><p class=\"font-mono text-[11px] tracking-[0.14em] uppercase text-[color:var(--txt-2)]\">July 24, 2026</p><div class=\"relative inline-flex \" dir=\"ltr\"><button type=\"button\" title=\"Bookmark\" aria-label=\"Bookmark this item\" aria-pressed=\"false\" class=\"inline-flex items-center gap-1 rounded-s-md border transition-colors disabled:opacity-50 h-7 px-2 border-[var(--line-strong)] bg-[color:var(--ink-2)] text-[color:var(--txt-2)] hover:border-brand-mid hover:text-brand-mid dark:border-[var(--line-strong)] dark:bg-[color:var(--ink-1)] dark:text-[color:var(--txt-3)]\"><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-bookmark h-3.5 w-3.5\" aria-hidden=\"true\"><path d=\"m19 21-7-4-7 4V5a2 2 0 0 1 2-2h10a2 2 0 0 1 2 2v16z\"></path></svg><span class=\"text-xs\">Save</span></button><button type=\"button\" title=\"Choose collection\" aria-label=\"Choose collection\" class=\"inline-flex items-center justify-center rounded-e-md border border-s-0 transition-colors h-7 px-2 border-[var(--line-strong)] bg-[color:var(--ink-2)] text-[color:var(--txt-2)] hover:border-brand-mid hover:text-brand-mid dark:border-[var(--line-strong)] dark:bg-[color:var(--ink-1)] dark:text-[color:var(--txt-3)]\"><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down h-3.5 w-3.5\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div></div><div class=\"not-prose mt-2 flex flex-wrap gap-2\"><a aria-label=\"Tag IETF\" href=\"/tags/ietf\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->IETF</span></a><a aria-label=\"Tag AI agent protocol\" href=\"/tags/ai-agent-protocol\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->AI agent protocol</span></a><a aria-label=\"Tag agentproto\" href=\"/tags/agentproto\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->agentproto</span></a><a aria-label=\"Tag MCP\" href=\"/tags/mcp\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->MCP</span></a><a aria-label=\"Tag A2A\" href=\"/tags/a2a\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->A2A</span></a><a aria-label=\"Tag agent interoperability\" href=\"/tags/agent-interoperability\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->agent interoperability</span></a><a aria-label=\"Tag agentic ai\" href=\"/tags/agentic-ai\"><span class=\"inline-flex items-center rounded-full px-3 py-1 font-mono text-[10.5px] uppercase tracking-[0.16em] text-brand-300 bg-brand-500/10 border border-brand-500/20 hover:bg-brand-500/16 transition-colors\">#<!-- -->agentic ai</span></a></div><div class=\"not-prose mt-7\"><div class=\"relative overflow-hidden rounded-2xl bg-[color:var(--ink-3)] border border-[var(--line)] pb-[56%]\"><img alt=\"IETF Weighs an AI Agent Protocol Standard in 2026\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"absolute inset-0 h-full w-full object-cover\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\"/></div></div><div class=\"not-prose mt-6 lg:hidden\"><button class=\"group flex items-center justify-center rounded-full bg-[color:var(--ink-2)] p-2 shadow-md backdrop-blur-sm transition-all duration-200 hover:bg-[color:var(--ink-2)] hover:shadow-lg hover:scale-110 dark:bg-[color:var(--ink-2)] dark:hover:bg-[color:var(--ink-4)] justify-center rounded-full border border-[var(--line)] bg-[color:var(--ink-2)] px-4 py-2 shadow-sm dark:border-[var(--line)] dark:bg-[color:var(--ink-1)]\" aria-label=\"Share this content\"><svg class=\"h-4 w-4 text-[color:var(--txt-2)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-3)]\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M8.684 13.342C8.886 12.938 9 12.482 9 12c0-.482-.114-.938-.316-1.342m0 2.684a3 3 0 110-2.684m0 2.684l6.632 3.316m-6.632-6l6.632-3.316m0 0a3 3 0 105.367-2.684 3 3 0 00-5.367 2.684zm0 9.316a3 3 0 105.367 2.684 3 3 0 00-5.367-2.684z\"></path></svg></button></div><div class=\"lg:hidden\"><aside class=\"not-prose mb-8 rounded-lg border border-[var(--line)] bg-[color:var(--ink-2)] p-4\" dir=\"ltr\"><div class=\"text-sm font-semibold mb-2 brand-text\" style=\"text-align:left\">Table of contents</div><nav aria-label=\"Table of contents\"><ul class=\"space-y-0.5\"><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#what-youll-learn\">What you&#x27;ll learn</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#what-happened-at-the-agentproto-bof\">What happened at the agentproto BoF</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#why-it-is-rough-consensus-not-a-vote\">Why it is rough consensus, not a vote</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#mcp-vs-a2a-two-layers-one-missing-piece\">MCP vs A2A: two layers, one missing piece</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#the-problems-the-framework-says-still-need-a-standard\">The problems the framework says still need a standard</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#why-prompt-injection-is-the-security-test\">Why prompt injection is the security test</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#the-realistic-timeline--and-what-to-watch\">The realistic timeline — and what to watch</a></li></ul></nav></aside></div><div class=\"mt-6\"><html><head></head><body><p><strong>In one line:</strong> At IETF 126 in Vienna this week, a Birds-of-a-Feather session called agentproto asked whether the internet's standards body should define how AI agents talk to each other across organizations — the gap that today's dominant protocols, MCP and A2A, leave open.<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup></p>\n<p><strong>TL;DR:</strong> For more than a year, vendors shipped competing AI agent protocols — Anthropic's MCP, Google's A2A, and several more — and none of them cleared the one bar that makes a protocol interoperable across organizational boundaries: an IETF RFC. On Thursday, July 23, the agentproto Birds-of-a-Feather (BoF) session at IETF 126 in Vienna brought that question into the Internet Engineering Task Force, with a view toward chartering a Working Group.<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup> This is not a vote and not a product launch; the IETF works by rough consensus, and any resulting standard is years away.<sup><a href=\"#user-content-fn-2\" id=\"user-content-fnref-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">2</a></sup> What is genuinely new is that agent-to-agent communication is now being treated as an internet-infrastructure problem, not just a vendor feature.</p>\n<h2 id=\"what-youll-learn\"><a class=\"anchor\" href=\"#what-youll-learn\">What you'll learn</a></h2>\n<ul>\n<li>What happened at the agentproto BoF at IETF 126, and what a \"Birds-of-a-Feather\" session actually decides</li>\n<li>Why the IETF works by rough consensus rather than a vote — and why that framing matters here</li>\n<li>How MCP and A2A differ, and the interoperability gap neither one closes</li>\n<li>The specific problems the underlying framework draft says still need a standard</li>\n<li>Why prompt injection is the security test any agent protocol standard has to pass</li>\n<li>The realistic timeline from a BoF to a published RFC, and what to watch next</li>\n</ul>\n<h2 id=\"what-happened-at-the-agentproto-bof\"><a class=\"anchor\" href=\"#what-happened-at-the-agentproto-bof\">What happened at the agentproto BoF</a></h2>\n<p>The IETF 126 meeting ran 18–24 July 2026 in Vienna, and among the established Working Group sessions the organization scheduled five Birds-of-a-Feather sessions — early, community-wide discussions about work that might be ready for the IETF to take on.<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1-3\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup> Three of the five touched AI agents directly. The one with the highest stakes for anyone building multi-agent systems was <strong>agentproto</strong> (Agent Communication Protocols), held Thursday, 23 July, 09:00–11:00 CEST.<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1-4\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup></p>\n<p>The IETF's own framing is precise: the past year produced \"a rush of competing, overlapping protocols for connecting AI agents to one another and to the tools they use — Model Context Protocol (MCP), Agent2Agent (A2A), the Agent Communication Protocol (ACP), the Agent Network Protocol (ANP), and more.\" The agentproto session, it says, \"brings that conversation into the IETF,\" building on a well-attended IETF 124 side meeting and on framework and requirements work led by Jonathan Rosenberg and Cullen Jennings, \"with a view toward chartering a Working Group to take that work forward.\"<sup><a href=\"#user-content-fn-1\" id=\"user-content-fnref-1-5\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">1</a></sup></p>\n<p>That phrase — <em>chartering a Working Group</em> — is the actual object of the meeting. A BoF is not where a standard gets written. It is where the community decides whether there is enough consensus, energy, and a tight enough scope to justify starting the multi-year process that eventually produces one.<sup><a href=\"#user-content-fn-2\" id=\"user-content-fnref-2-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">2</a></sup></p>\n<h2 id=\"why-it-is-rough-consensus-not-a-vote\"><a class=\"anchor\" href=\"#why-it-is-rough-consensus-not-a-vote\">Why it is rough consensus, not a vote</a></h2>\n<p>It is tempting to describe Thursday's session as a vote on an IETF AI agent protocol standard. That is the wrong mental model, and the distinction is not pedantic. The IETF does not decide by counting ballots. It decides by \"rough consensus and running code\" — a working agreement in the room and on the mailing list, backed by implementations that actually run.<sup><a href=\"#user-content-fn-2\" id=\"user-content-fnref-2-3\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">2</a></sup> A BoF that is \"working-group-forming,\" as agentproto aims to be, succeeds when it demonstrates that a coherent problem and a willing community exist; it can just as easily send the work back to the mailing list if the discussion reveals too much disagreement about scope.<sup><a href=\"#user-content-fn-2\" id=\"user-content-fnref-2-4\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">2</a></sup></p>\n<p>This is why an IETF outcome carries weight that a vendor announcement does not. The RFCs that came out of this process define TLS, DNS, and the transport underneath modern web traffic, and they endure precisely because they were not imposed by one company. If the IETF eventually charters an agent-protocol Working Group, it is asserting that <strong>an IETF AI agent protocol standard</strong> belongs in the same category as those foundational specifications — an internet-layer concern rather than a product-layer one. As of this writing, the formal result of Thursday's session — whether a Working Group is chartered — follows that consensus process; session materials and minutes are posted to the IETF Datatracker as they are finalized, and that is the authoritative place to confirm the outcome rather than early press summaries.</p>\n<h2 id=\"mcp-vs-a2a-two-layers-one-missing-piece\"><a class=\"anchor\" href=\"#mcp-vs-a2a-two-layers-one-missing-piece\">MCP vs A2A: two layers, one missing piece</a></h2>\n<p>To see why the IETF is interested at all, you have to see what the existing protocols do and do not cover. They are not really competitors so much as neighbors solving different halves of the problem.</p>\n<p><strong>MCP (Model Context Protocol)</strong> is a client-server protocol: an agent reaches out to a tool, database, or API and requests data or an action. Anthropic donated MCP to the Agentic AI Foundation — a directed fund under the Linux Foundation — on 9 December 2025, and by that point the protocol reported \"over 97 million monthly SDK downloads, 10,000 active servers,\" with first-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code.<sup><a href=\"#user-content-fn-3\" id=\"user-content-fnref-3\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">3</a></sup> Its next revision, the 2026-07-28 spec, is the largest since launch and, among other things, realigns authorization with OAuth 2.1; we covered that change in depth in our write-up of <a href=\"/mcp-stateless-protocol-enterprise-authorization\">MCP's stateless 2026-07-28 spec</a>.<sup><a href=\"#user-content-fn-9\" id=\"user-content-fnref-9\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">4</a></sup></p>\n<p><strong>A2A (Agent2Agent)</strong> is a peer-to-peer protocol: two agents discover each other's capabilities and delegate tasks. Google donated A2A to the Linux Foundation on 23 June 2025 at Open Source Summit North America, with Amazon Web Services, Cisco, Microsoft, Salesforce, SAP, and ServiceNow among the founding members; the coalition has since grown to over 100 technology companies.<sup><a href=\"#user-content-fn-4\" id=\"user-content-fnref-4\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">5</a></sup><sup><a href=\"#user-content-fn-5\" id=\"user-content-fnref-5\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">6</a></sup> If you want the hands-on version of how agents advertise capabilities and hand off work, our <a href=\"/a2a-protocol-python-tutorial\">A2A protocol tutorial</a> walks through it.</p>\n<div data-ad-placement=\"post-in-article-mid\" class=\"not-prose my-8\"></div>\n\n<p>Here is the gap. MCP standardizes the agent-to-tool link. A2A standardizes the agent-to-agent link within a broadly cooperating ecosystem. Neither one fully specifies what happens when an agent in <em>your</em> organization needs to prove to an agent in <em>someone else's</em> organization that it is authorized to act on a user's behalf — and to do so in a way both sides can verify without a prior bilateral integration. That cross-domain, no-prior-trust case is exactly the territory internet standards exist to cover.</p>\n<h2 id=\"the-problems-the-framework-says-still-need-a-standard\"><a class=\"anchor\" href=\"#the-problems-the-framework-says-still-need-a-standard\">The problems the framework says still need a standard</a></h2>\n<p>The intellectual basis for agentproto is a framework and requirements document authored by Jonathan Rosenberg, of Five9, and Cullen Jennings, of Cisco.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup> Rosenberg's involvement is a signal in itself: he is a lead author of RFC 3261, the Session Initiation Protocol that governs much of the internet's real-time voice and video. One procedural caveat worth stating plainly: an Internet-Draft is a proposal, not a standard. The datatracker attaches an explicit disclaimer that such drafts are \"not endorsed by the IETF\" and have \"no formal standing in the IETF standards process,\" and the early framework draft has already been superseded — the current document is <code>draft-rosenberg-agentproto-usecases</code>.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup><sup><a href=\"#user-content-fn-7\" id=\"user-content-fnref-7\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">8</a></sup></p>\n<p>With that caveat, the framework's argument is that today's protocols leave a short list of hard problems unsolved, and that these are the ones worth standardizing. Its requirements sections map to them directly: discovery (how agents find each other, especially across domains), authentication and authorization (how identity and credentials are federated so one organization's agent can be trusted by another's), lifecycle management (how a chain of delegated agents is managed across the life of a task), and user confirmation (how a human stays in the loop before an action such as booking a flight is committed).<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-3\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup> The draft frames agent communication as a new application-layer concern — occupying the same tier of the internet stack as HTTP, SIP, and RTP do today.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-4\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup></p>\n<h2 id=\"why-prompt-injection-is-the-security-test\"><a class=\"anchor\" href=\"#why-prompt-injection-is-the-security-test\">Why prompt injection is the security test</a></h2>\n<p>The most concrete technical argument for standardizing this at the protocol layer is a security one, and it centers on prompt injection.</p>\n<p>In a single-agent system, prompt injection means a user crafts input that overrides the agent's instructions. OWASP ranks it as <strong>LLM01 — the number-one risk</strong> in its Top 10 for LLM Applications.<sup><a href=\"#user-content-fn-8\" id=\"user-content-fnref-8\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">9</a></sup> The multi-agent version is structurally worse. A malicious user can craft input for Agent A that is really aimed at Agent B, the agent that A calls next. Because A relays user content to B as part of normal operation, and because B trusts A, the injected instruction can ride the trust relationship straight past A's defenses.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-5\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup> The framework's position is blunt: prompt injection is notoriously difficult to prevent, so the protocol-level answer is not prevention but attribution — mechanisms for logging, diagnosis, and reconstructing which agent did what when an incident happens.<sup><a href=\"#user-content-fn-6\" id=\"user-content-fnref-6-6\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">7</a></sup></p>\n<p>That is a requirement no purely application-level defense can satisfy, because the attack crosses a boundary between two independently operated systems. It is also the clearest illustration of why \"just use MCP and A2A\" is not a complete answer: neither was designed to carry incident attribution across an inter-domain agent cascade.</p>\n<h2 id=\"the-realistic-timeline--and-what-to-watch\"><a class=\"anchor\" href=\"#the-realistic-timeline--and-what-to-watch\">The realistic timeline — and what to watch</a></h2>\n<p>Set expectations accordingly. The IETF process is deliberately slow: a proposal typically moves from a BoF, to a chartered Working Group, through multiple Internet-Draft revisions and reviews, to a published RFC — a path that commonly takes on the order of two to four years.<sup><a href=\"#user-content-fn-10\" id=\"user-content-fnref-10\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">10</a></sup> Nothing shipped in Vienna this week. What the meeting could produce is a decision to <em>start</em>, and that decision then shapes what the RFC pipeline looks like in 2027 and 2028.</p>\n<p>The strategic question underneath is whether an open IETF AI agent protocol standard will define inter-domain agent communication, or whether the market-dominant protocols will harden into de facto standards by deployment momentum alone. MCP's 97-million-downloads-a-month adoption is a real gravitational field, and it is entirely possible that the practical baseline gets set by what is already deployed rather than by what the IETF eventually blesses.<sup><a href=\"#user-content-fn-3\" id=\"user-content-fnref-3-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\">3</a></sup> The tension between those two outcomes is the story worth following. It is also the same interoperability-versus-lock-in tension that regulators are pressing from a different direction, as we covered in <a href=\"/eu-android-ai-agent-interoperability-dma\">the EU's push for AI agent interoperability under the DMA</a>.</p>\n<p>For now, the honest status is: the conversation has arrived at the IETF, the problem statement is well-formed, and the outcome of Thursday's session is a matter of public record on the IETF Datatracker rather than of speculation.</p>\n\n\n\n\n\n\n\n\n\n\n\n</div><div class=\"not-prose\"><section class=\"mt-12 pt-8 border-t border-[var(--line-strong)]\"><h2 id=\"faq\" class=\"text-2xl font-bold text-[color:var(--txt-0)] mb-6\">Frequently Asked Questions</h2><div class=\"bg-[color:var(--ink-2)] rounded-xl p-6\"><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"true\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">Is the IETF standardizing AI agent protocols?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-up w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m18 15-6-6-6 6\"></path></svg></button><div class=\"pb-4 text-[color:var(--txt-2)] leading-relaxed\">Not yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.1 A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.10 The authoritative outcome of the session is posted to the IETF Datatracker.</div></div><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"false\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">What is the agentproto BoF at IETF 126?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"false\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">How is MCP different from A2A?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"false\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">What would an IETF RFC add that MCP and A2A don&#x27;t cover?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div><div class=\"border-b border-[var(--line-strong)] last:border-0\"><button class=\"w-full py-4 flex items-center justify-between text-left hover:text-indigo-600 dark:hover:text-indigo-400 transition-colors\" aria-expanded=\"false\"><span class=\"font-medium text-[color:var(--txt-0)] pr-4\">Why is prompt injection worse in multi-agent systems?</span><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-chevron-down w-5 h-5 flex-shrink-0 text-[color:var(--txt-2)]\" aria-hidden=\"true\"><path d=\"m6 9 6 6 6-6\"></path></svg></button></div></div></section></div><hr class=\"not-prose my-10 border-[var(--line)]\"/><nav class=\"not-prose flex justify-between text-sm text-[color:var(--txt-2)]\"><div><a class=\"hover:text-[color:var(--txt-0)] dark:hover:text-[color:var(--txt-1)] transition-colors\" href=\"/microsoft-agent-framework-go-google-adk\"><span class=\"\">←</span> <!-- -->Previous</a></div><div><a class=\"hover:text-[color:var(--txt-0)] dark:hover:text-[color:var(--txt-1)] transition-colors\" href=\"/pinecone-nexus-knowledge-engine-rag-agents\">Next<!-- --> <span class=\"\">→</span></a></div></nav></article><aside class=\"hidden lg:block\"><div class=\"sticky top-24 space-y-6\"><aside class=\"not-prose mb-8 rounded-lg border border-[var(--line)] bg-[color:var(--ink-2)] p-4\" dir=\"ltr\"><div class=\"text-sm font-semibold mb-2 brand-text\" style=\"text-align:left\">Table of contents</div><nav aria-label=\"Table of contents\"><ul class=\"space-y-0.5\"><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#what-youll-learn\">What you&#x27;ll learn</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#what-happened-at-the-agentproto-bof\">What happened at the agentproto BoF</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#why-it-is-rough-consensus-not-a-vote\">Why it is rough consensus, not a vote</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#mcp-vs-a2a-two-layers-one-missing-piece\">MCP vs A2A: two layers, one missing piece</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#the-problems-the-framework-says-still-need-a-standard\">The problems the framework says still need a standard</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#why-prompt-injection-is-the-security-test\">Why prompt injection is the security test</a></li><li><a class=\"flex min-h-[44px] items-center text-sm hover:underline text-[color:var(--txt-1)] rounded-md hover:bg-[color:var(--ink-3)] px-2 -mx-2 transition-colors pl-2\" href=\"#the-realistic-timeline--and-what-to-watch\">The realistic timeline — and what to watch</a></li></ul></nav></aside></div></aside></div><div class=\"mx-auto max-w-3xl px-4\"><section class=\"mt-16 border-t border-[var(--line)] pt-10 dark:border-[var(--line)]\" dir=\"ltr\"><div class=\"mb-6 flex items-center gap-3\"><div class=\"h-8 w-1 rounded-full bg-gradient-to-b from-brand-begin to-brand-end\"></div><div><p class=\"text-xs font-medium uppercase tracking-wider text-[color:var(--txt-2)]\">Continue Learning</p><h2 class=\"text-xl font-bold text-[color:var(--txt-0)]\">Related Posts</h2></div></div><div class=\"grid grid-cols-1 gap-4 sm:grid-cols-2\"><a class=\"group flex gap-4 rounded-xl border border-[var(--line)] bg-[color:var(--ink-2)] p-3 transition-all hover:border-brand-mid/50 hover:shadow-lg hover:shadow-brand-mid/10 dark:border-[var(--line)] dark:bg-[color:var(--ink-1)] dark:hover:border-brand-mid/40\" href=\"/claude-adobe-creativity-connector-50-creative-cloud-tools\"><div class=\"relative h-20 w-20 flex-shrink-0 overflow-hidden rounded-lg bg-[color:var(--ink-3)]\"><img alt=\"Adobe + Claude: 50+ Creative Tools From One Prompt\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"object-cover transition-transform group-hover:scale-105\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/placeholders/cover-general.svg\"/></div><div class=\"flex flex-1 flex-col justify-center overflow-hidden\"><h3 class=\"line-clamp-2 text-sm font-semibold text-[color:var(--txt-0)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-0)]\">Adobe + Claude: 50+ Creative Tools From One Prompt</h3><div class=\"mt-1.5 flex flex-wrap gap-1\"><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">claude</span><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">adobe</span></div></div></a><a class=\"group flex gap-4 rounded-xl border border-[var(--line)] bg-[color:var(--ink-2)] p-3 transition-all hover:border-brand-mid/50 hover:shadow-lg hover:shadow-brand-mid/10 dark:border-[var(--line)] dark:bg-[color:var(--ink-1)] dark:hover:border-brand-mid/40\" href=\"/claude-managed-agents-deploy-ai-agents-faster\"><div class=\"relative h-20 w-20 flex-shrink-0 overflow-hidden rounded-lg bg-[color:var(--ink-3)]\"><img alt=\"Claude Managed Agents: Build Production AI Agents in Days\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"object-cover transition-transform group-hover:scale-105\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/placeholders/cover-general.svg\"/></div><div class=\"flex flex-1 flex-col justify-center overflow-hidden\"><h3 class=\"line-clamp-2 text-sm font-semibold text-[color:var(--txt-0)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-0)]\">Claude Managed Agents: Build Production AI Agents in Days</h3><div class=\"mt-1.5 flex flex-wrap gap-1\"><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">anthropic</span><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">claude</span></div></div></a><a class=\"group flex gap-4 rounded-xl border border-[var(--line)] bg-[color:var(--ink-2)] p-3 transition-all hover:border-brand-mid/50 hover:shadow-lg hover:shadow-brand-mid/10 dark:border-[var(--line)] dark:bg-[color:var(--ink-1)] dark:hover:border-brand-mid/40\" href=\"/agentic-testing-slack-200-run-data\"><div class=\"relative h-20 w-20 flex-shrink-0 overflow-hidden rounded-lg bg-[color:var(--ink-3)]\"><img alt=\"Agentic Testing in 2026: What Slack&#x27;s 200-Run Data Shows\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"object-cover transition-transform group-hover:scale-105\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/covers/agentic-testing-slack-200-run-data.jpg\"/></div><div class=\"flex flex-1 flex-col justify-center overflow-hidden\"><h3 class=\"line-clamp-2 text-sm font-semibold text-[color:var(--txt-0)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-0)]\">Agentic Testing in 2026: What Slack&#x27;s 200-Run Data Shows</h3><div class=\"mt-1.5 flex flex-wrap gap-1\"><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">agentic testing</span><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">AI agents</span></div></div></a><a class=\"group flex gap-4 rounded-xl border border-[var(--line)] bg-[color:var(--ink-2)] p-3 transition-all hover:border-brand-mid/50 hover:shadow-lg hover:shadow-brand-mid/10 dark:border-[var(--line)] dark:bg-[color:var(--ink-1)] dark:hover:border-brand-mid/40\" href=\"/pinecone-nexus-knowledge-engine-rag-agents\"><div class=\"relative h-20 w-20 flex-shrink-0 overflow-hidden rounded-lg bg-[color:var(--ink-3)]\"><img alt=\"Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"object-cover transition-transform group-hover:scale-105\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent\" src=\"/images/covers/pinecone-nexus-knowledge-engine-rag-agents.jpg\"/></div><div class=\"flex flex-1 flex-col justify-center overflow-hidden\"><h3 class=\"line-clamp-2 text-sm font-semibold text-[color:var(--txt-0)] transition-colors group-hover:text-brand-mid dark:text-[color:var(--txt-0)]\">Pinecone Nexus: Is RAG Ending for AI Agents? (2026)</h3><div class=\"mt-1.5 flex flex-wrap gap-1\"><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">Pinecone Nexus</span><span class=\"rounded bg-[color:var(--ink-3)] px-1.5 py-0.5 text-xs text-[color:var(--txt-2)] dark:bg-[color:var(--ink-2)] dark:text-[color:var(--txt-3)]\">knowledge engine</span></div></div></a></div></section></div></div></main><div class=\"nlt-shell\" style=\"padding-bottom:24px\"></div><footer class=\"jsx-6d81f11809c7f54d nlt-foot\"><div class=\"jsx-6d81f11809c7f54d nlt-shell\"><div class=\"jsx-6d81f11809c7f54d nlt-foot-top\"><div class=\"jsx-6d81f11809c7f54d nlt-foot-brand\"><a style=\"display:inline-flex;align-items:center;gap:10px;text-decoration:none;color:inherit\" href=\"/\"><svg width=\"28\" height=\"28\" viewBox=\"0 0 80 80\" aria-hidden=\"true\"><defs><linearGradient id=\"nlt-bm\" x1=\"0\" y1=\"0\" x2=\"1\" y2=\"1\"><stop offset=\"0%\" stop-color=\"#5ec8f7\"></stop><stop offset=\"100%\" stop-color=\"#1e96d4\"></stop></linearGradient></defs><circle cx=\"40\" cy=\"40\" r=\"30\" fill=\"url(#nlt-bm)\" opacity=\"0.18\"></circle><circle cx=\"40\" cy=\"40\" r=\"18\" fill=\"url(#nlt-bm)\"></circle><circle cx=\"46\" cy=\"34\" r=\"5\" fill=\"#fff\"></circle><path d=\"M8 14h12M60 14h12M8 66h12M60 66h12\" stroke=\"url(#nlt-bm)\" stroke-width=\"4\" stroke-linecap=\"round\"></path></svg><span style=\"font-weight:600;letter-spacing:-0.02em;font-size:18px;color:var(--txt-0)\">Nerd<em style=\"font-family:var(--f-display);font-style:italic;color:var(--accent-italic);margin:0 2px;font-weight:400\">Level</em>Tech</span></a><p style=\"margin-top:14px;color:var(--txt-1);max-width:320px;font-size:13.5px;line-height:1.55\" class=\"jsx-6d81f11809c7f54d\">The AI tutor that levels up with you. Independent, multilingual, made by builders for builders.</p><div style=\"display:flex;gap:8px;margin-top:18px\" class=\"jsx-6d81f11809c7f54d\"><button type=\"button\" class=\"jsx-6d81f11809c7f54d nlt-lang on\">EN</button><button type=\"button\" class=\"jsx-6d81f11809c7f54d nlt-lang\">AR</button></div></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Learn</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/courses\">Courses</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/guides\">Guides</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tutorials\">Tutorials</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/courses/paths\">Roadmaps</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/certificates\">Certificates</a></li></ul></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Tools</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools/resume-optimizer\">Resume Optimizer</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools/regex-tester\">Regex Tester</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools/api-response-mocker\">API Mocker</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools/tech-pulse\">Tech Pulse</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tools\">All tools</a></li></ul></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Read</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/posts\">Blog</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/posts?category=news\">News</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/podcast\">AI Cast</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/subscribe\">Newsletter</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/trending\">Trending</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/tags\">Tags</a></li></ul></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Hire</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/jobs\">Jobs board</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/interview-prep\">Interview prep</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/for-agents\">For agents</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/jobs/post\">Post a job</a></li></ul></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-col\"><div class=\"jsx-6d81f11809c7f54d nlt-eyebrow\">Co.</div><ul class=\"jsx-6d81f11809c7f54d\"><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/about\">About</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/about\">Contact</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/privacy-policy\">Privacy</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/terms-of-service\">Terms</a></li><li class=\"jsx-6d81f11809c7f54d\"><a href=\"/rss.xml\">RSS</a></li></ul></div></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-bot\"><span style=\"color:var(--txt-3);font-size:11.5px\" class=\"jsx-6d81f11809c7f54d nlt-mono\">©<!-- --> <!-- -->2026<!-- --> <!-- -->NerdLevelTech · made with caffeine and curiosity</span><div class=\"jsx-6d81f11809c7f54d nlt-foot-socials\"><a href=\"https://www.instagram.com/nerdleveltech\" aria-label=\"Instagram\" title=\"Instagram\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"jsx-6d81f11809c7f54d nlt-social\"><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-instagram jsx-6d81f11809c7f54d\" aria-hidden=\"true\"><rect width=\"20\" height=\"20\" x=\"2\" y=\"2\" rx=\"5\" ry=\"5\"></rect><path d=\"M16 11.37A4 4 0 1 1 12.63 8 4 4 0 0 1 16 11.37z\"></path><line x1=\"17.5\" x2=\"17.51\" y1=\"6.5\" y2=\"6.5\"></line></svg></a><a href=\"https://www.linkedin.com/company/nerdleveltech\" aria-label=\"LinkedIn\" title=\"LinkedIn\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"jsx-6d81f11809c7f54d nlt-social\"><svg xmlns=\"http://www.w3.org/2000/svg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"lucide lucide-linkedin jsx-6d81f11809c7f54d\" aria-hidden=\"true\"><path d=\"M16 8a6 6 0 0 1 6 6v7h-4v-7a2 2 0 0 0-2-2 2 2 0 0 0-2 2v7h-4v-7a6 6 0 0 1 6-6z\"></path><rect width=\"4\" height=\"12\" x=\"2\" y=\"9\"></rect><circle cx=\"4\" cy=\"4\" r=\"2\"></circle></svg></a><a href=\"https://x.com/nerdleveltech\" aria-label=\"X\" title=\"X\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"jsx-6d81f11809c7f54d nlt-social\"><svg viewBox=\"0 0 24 24\" width=\"16\" height=\"16\" aria-hidden=\"true\" class=\"jsx-6d81f11809c7f54d\" fill=\"currentColor\"><path d=\"M18.244 2.25h3.308l-7.227 8.26 8.502 11.24h-6.66l-5.214-6.817L4.97 21.75H1.658l7.73-8.835L1.25 2.25h6.834l4.713 6.231L18.244 2.25Zm-1.161 17.52h1.833L7.084 4.126H5.117L17.083 19.77Z\"></path></svg></a></div></div><div class=\"jsx-6d81f11809c7f54d nlt-foot-pub\"><a href=\"https://lumabyte.co\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"jsx-6d81f11809c7f54d nlt-foot-pub-link\">A <span class=\"jsx-6d81f11809c7f54d nlt-foot-pub-brand\">LumaByte</span> publication</a></div></div></footer><aside id=\"nlt-cookie-banner\" class=\"fixed inset-x-0 bottom-0 z-50 px-4 pb-6\" dir=\"ltr\"><div class=\"mx-auto max-w-4xl rounded-2xl border border-[var(--line-strong)] bg-[color:var(--ink-2)] p-5 shadow-2xl backdrop-blur\"><div class=\"flex flex-col gap-4 sm:flex-row sm:items-center sm:justify-between\"><div class=\"text-sm text-[color:var(--txt-1)]\"><p class=\"font-medium text-[color:var(--txt-0)]\">Cookies help keep Nerd Level Tech running smoothly.</p><p class=\"mt-1 leading-relaxed text-xs sm:text-sm\">We use cookies for analytics (Google Analytics), to remember your theme preferences, and to improve our content. By accepting, you consent to analytics and personalized ads. You can decline or opt out at any time.</p></div><div class=\"flex flex-col gap-2 sm:flex-row sm:items-center\"><button type=\"button\" class=\"rounded-full bg-brand-500 px-4 py-2 text-xs font-semibold text-[#001520] shadow-[0_0_0_1px_rgba(255,255,255,0.06)_inset,0_18px_40px_-16px_var(--glow-strong)] transition-all hover:-translate-y-px hover:bg-brand-400\">Accept</button><button type=\"button\" class=\"rounded-full px-4 py-2 text-xs font-semibold text-[color:var(--txt-1)] transition hover:bg-[color:var(--ink-3)]\">Decline</button></div></div></div></aside><!--$--><!--/$--><!--$--><!--/$--></div><script src=\"/_next/static/chunks/webpack-dfed7d1a04fd289f.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\" async=\"\"></script></body></html><script>(self.__next_f=self.__next_f||[]).push([0]);self.__next_f.push([2,null])</script><script>self.__next_f.push([1,\"1:HL[\\\"/_next/static/media/9cc5b37ab1350db7.p.woff2\\\",\\\"font\\\",{\\\"crossOrigin\\\":\\\"\\\",\\\"type\\\":\\\"font/woff2\\\"}]\\n2:HL[\\\"/_next/static/media/e4af272ccee01ff0.p.woff2\\\",\\\"font\\\",{\\\"crossOrigin\\\":\\\"\\\",\\\"type\\\":\\\"font/woff2\\\"}]\\n3:HL[\\\"/_next/static/media/e6099e249fd938cc.p.woff2\\\",\\\"font\\\",{\\\"crossOrigin\\\":\\\"\\\",\\\"type\\\":\\\"font/woff2\\\"}]\\n4:HL[\\\"/_next/static/css/a78fa145c089ec40.css?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"style\\\"]\\n5:HL[\\\"/_next/static/css/470dc7a093659a24.css?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"style\\\"]\\n6:HL[\\\"/_next/static/css/d7a984aa9a9fcc2c.css?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"style\\\"]\\n\"])</script><script>self.__next_f.push([1,\"7:I[12846,[],\\\"\\\"]\\na:I[4707,[],\\\"\\\"]\\nd:I[36423,[],\\\"\\\"]\\n11:I[61060,[],\\\"\\\"]\\nb:[\\\"lang\\\",\\\"en\\\",\\\"d\\\"]\\nc:[\\\"slug\\\",\\\"ietf-ai-agent-protocol-standard-agentproto\\\",\\\"d\\\"]\\n12:[]\\n0:[\\\"$\\\",\\\"$L7\\\",null,{\\\"buildId\\\":\\\"bvNsB07jq_kpEvgIG413f\\\",\\\"assetPrefix\\\":\\\"\\\",\\\"urlParts\\\":[\\\"\\\",\\\"ietf-ai-agent-protocol-standard-agentproto\\\"],\\\"initialTree\\\":[\\\"\\\",{\\\"children\\\":[[\\\"lang\\\",\\\"en\\\",\\\"d\\\"],{\\\"children\\\":[[\\\"slug\\\",\\\"ietf-ai-agent-protocol-standard-agentproto\\\",\\\"d\\\"],{\\\"children\\\":[\\\"__PAGE__\\\",{}]}]}]},\\\"$undefined\\\",\\\"$undefined\\\",true],\\\"initialSeedData\\\":[\\\"\\\",{\\\"children\\\":[[\\\"lang\\\",\\\"en\\\",\\\"d\\\"],{\\\"children\\\":[[\\\"slug\\\",\\\"ietf-ai-agent-protocol-standard-agentproto\\\",\\\"d\\\"],{\\\"children\\\":[\\\"__PAGE__\\\",{},[[\\\"$L8\\\",\\\"$L9\\\",null],null],null]},[null,[\\\"$\\\",\\\"$La\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"segmentPath\\\":[\\\"children\\\",\\\"$b\\\",\\\"children\\\",\\\"$c\\\",\\\"children\\\"],\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$Ld\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"notFoundStyles\\\":\\\"$undefined\\\"}]],null]},[[null,\\\"$Le\\\"],null],null]},[[[[\\\"$\\\",\\\"link\\\",\\\"0\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/css/a78fa145c089ec40.css?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"link\\\",\\\"1\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/css/470dc7a093659a24.css?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"link\\\",\\\"2\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/css/d7a984aa9a9fcc2c.css?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\"}]],\\\"$Lf\\\"],null],null],\\\"couldBeIntercepted\\\":false,\\\"initialHead\\\":[null,\\\"$L10\\\"],\\\"globalErrorComponent\\\":\\\"$11\\\",\\\"missingSlots\\\":\\\"$W12\\\"}]\\n\"])</script><script>self.__next_f.push([1,\"13:I[34182,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"LanguageProvider\\\"]\\n14:I[44727,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"AuthModalProvider\\\"]\\n15:I[93583,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"ToastProvider\\\"]\\n16:I[56610,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n17:I[10425,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3k\"])</script><script>self.__next_f.push([1,\"ZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n18:I[11176,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n19:I[97526,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n1a:I[5274,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"FeedbackWidget\\\"]\\n1b:I[38156,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZ\"])</script><script>self.__next_f.push([1,\"RCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n1c:I[1880,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n1d:I[38599,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7337\\\",\\\"static/chunks/7337-e05acbb98bffc8ac.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"1084\\\",\\\"static/chunks/app/%5Blang%5D/layout-a724f3979e1466cd.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n1f:I[74048,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"5878\\\",\\\"static/chunks/5878-dbd6ed66767b4bc6.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"2957\\\",\\\"static/chunks/2957-135fdf77983e5820.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7363\\\",\\\"static/chunks/7363-1b3fd7d0da0ebc28.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"4182\\\",\\\"static/chunks/4182-aee685f13a26bbd8.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8041\\\",\\\"static/chunks/8041-f3df4595b34e4e85.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"482\\\",\\\"static/chunks/482-5c810f0566082c89.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7621\\\",\\\"static/chunks/app/%5Blang%5D/%5Bslug%5D/page-e0c122d0071f8e69.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n24:I[86249,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"5878\\\",\\\"static/chunks/5878-dbd6ed66767b4bc6.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFz\"])</script><script>self.__next_f.push([1,\"wCoQ9\\\",\\\"2957\\\",\\\"static/chunks/2957-135fdf77983e5820.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7363\\\",\\\"static/chunks/7363-1b3fd7d0da0ebc28.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"4182\\\",\\\"static/chunks/4182-aee685f13a26bbd8.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8041\\\",\\\"static/chunks/8041-f3df4595b34e4e85.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"482\\\",\\\"static/chunks/482-5c810f0566082c89.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3242\\\",\\\"static/chunks/3242-1d20eeb23b8f6d1c.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"7621\\\",\\\"static/chunks/app/%5Blang%5D/%5Bslug%5D/page-e0c122d0071f8e69.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\ne:[\\\"$\\\",\\\"$L13\\\",null,{\\\"initialLang\\\":\\\"en\\\",\\\"children\\\":[\\\"$\\\",\\\"$L14\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$L15\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"$L16\\\",null,{\\\"headerTranslations\\\":{\\\"navBlog\\\":\\\"Blog\\\",\\\"navGuides\\\":\\\"Guides\\\",\\\"navAICast\\\":\\\"AI Cast\\\",\\\"navAINerdo\\\":\\\"Nerdo\\\",\\\"navCourses\\\":\\\"Courses\\\",\\\"navResources\\\":\\\"Resources\\\",\\\"navTools\\\":\\\"Tools\\\",\\\"searchPlaceholder\\\":\\\"Search articles, tools, or topics...\\\",\\\"searchButton\\\":\\\"Search\\\",\\\"ariaOpenSearch\\\":\\\"Open search\\\",\\\"ariaCloseSearch\\\":\\\"Close search\\\",\\\"ariaOpenMenu\\\":\\\"Open menu\\\",\\\"ariaCloseMenu\\\":\\\"Close menu\\\"},\\\"footerTranslations\\\":{\\\"privacyPolicy\\\":\\\"Privacy Policy\\\",\\\"termsOfService\\\":\\\"Service Terms\\\",\\\"about\\\":\\\"About\\\",\\\"copyright\\\":\\\"© 2026 Nerd Level Tech\\\"},\\\"children\\\":[\\\"$\\\",\\\"$La\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"segmentPath\\\":[\\\"children\\\",\\\"$b\\\",\\\"children\\\"],\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$Ld\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"notFoundStyles\\\":\\\"$undefined\\\"}]}],[\\\"$\\\",\\\"$L17\\\",null,{}],[\\\"$\\\",\\\"$L18\\\",null,{}],[\\\"$\\\",\\\"$L19\\\",null,{}],[\\\"$\\\",\\\"$L1a\\\",null,{}],[\\\"$\\\",\\\"$L1b\\\",null,{}],[\\\"$\\\",\\\"$L1c\\\",null,{}],[\\\"$\\\",\\\"$L1d\\\",null,{}]]}]}]}]\\n1e:T1afb,\"])</script><script>self.__next_f.push([1,\"[{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"Article\\\",\\\"headline\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\",\\\"description\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\",\\\"image\\\":\\\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\\\",\\\"author\\\":{\\\"@type\\\":\\\"Person\\\",\\\"name\\\":\\\"Nerd Level Tech\\\",\\\"url\\\":\\\"https://nerdleveltech.com\\\"},\\\"publisher\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Nerd Level Tech\\\",\\\"url\\\":\\\"https://nerdleveltech.com\\\",\\\"logo\\\":{\\\"@type\\\":\\\"ImageObject\\\",\\\"url\\\":\\\"https://nerdleveltech.com/images/logo.png\\\",\\\"width\\\":512,\\\"height\\\":512}},\\\"datePublished\\\":\\\"2026-07-24T00:00:00.000Z\\\",\\\"dateModified\\\":\\\"2026-07-24T00:00:00.000Z\\\",\\\"mainEntityOfPage\\\":{\\\"@type\\\":\\\"WebPage\\\",\\\"@id\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"},\\\"url\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\",\\\"keywords\\\":\\\"IETF, AI agent protocol, agentproto, MCP, A2A, agent interoperability, agentic ai\\\",\\\"articleSection\\\":\\\"ai-ml\\\"},{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"BreadcrumbList\\\",\\\"itemListElement\\\":[{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":1,\\\"name\\\":\\\"Home\\\",\\\"item\\\":\\\"https://nerdleveltech.com/\\\"},{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":2,\\\"name\\\":\\\"Blog\\\",\\\"item\\\":\\\"https://nerdleveltech.com/blog\\\"},{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":3,\\\"name\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\",\\\"item\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"}]},{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"FAQPage\\\",\\\"mainEntity\\\":[{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"Is the IETF standardizing AI agent protocols?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"Not yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.1 A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.10 The authoritative outcome of the session is posted to the IETF Datatracker.\\\"}},{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"What is the agentproto BoF at IETF 126?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"Agentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.17\\\"}},{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"How is MCP different from A2A?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"MCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.35 They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.7\\\"}},{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"What would an IETF RFC add that MCP and A2A don't cover?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"The framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.7 These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\\\"}},{\\\"@type\\\":\\\"Question\\\",\\\"name\\\":\\\"Why is prompt injection worse in multi-agent systems?\\\",\\\"acceptedAnswer\\\":{\\\"@type\\\":\\\"Answer\\\",\\\"text\\\":\\\"Because it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.7 OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.9 Footnotes\\\\n\\\\n\\\\n\\\\\\\"Birds of a Feather at IETF 126,\\\\\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). https://www.ietf.org/blog/ietf126-bofs/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7\\\\n\\\\n\\\\n\\\\\\\"Birds of a Feather (BOF),\\\\\\\" IETF process documentation, and \\\\\\\"Introduction to the IETF\\\\\\\" (rough consensus and running code). https://www.ietf.org/process/bofs/ ↩ ↩2 ↩3 ↩4\\\\n\\\\n\\\\n\\\\\\\"MCP joins the Agentic AI Foundation,\\\\\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/ ↩ ↩2 ↩3\\\\n\\\\n\\\\n\\\\\\\"The 2026-07-28 MCP Specification Release Candidate,\\\\\\\" Model Context Protocol Blog. https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/ ↩\\\\n\\\\n\\\\n\\\\\\\"Google Cloud donates A2A to Linux Foundation,\\\\\\\" Google Developers Blog, 23 June 2025. https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/ ↩ ↩2\\\\n\\\\n\\\\n\\\\\\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\\\\\" Google Open Source Blog, 16 April 2026 (\\\\\\\"over 100 technology companies now supporting the project\\\\\\\"; A2A announced 9 April 2025, donated 23 June 2025). https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html ↩\\\\n\\\\n\\\\n\\\\\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\\\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\\\\\"Prompt injection attacks are notoriously difficult to prevent\\\\\\\"). This individual Internet-Draft is expired and \\\\\\\"has no formal standing in the IETF standards process.\\\\\\\" Full text: https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt — status: https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10\\\\n\\\\n\\\\n\\\\\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\\\\\" draft-rosenberg-agentproto-usecases (the current, active revision). https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/ ↩\\\\n\\\\n\\\\n\\\\\\\"OWASP Top 10 for LLM Applications 2025,\\\\\\\" LLM01: Prompt Injection. https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf ↩ ↩2\\\\n\\\\n\\\\n\\\\\\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\\\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm ↩ ↩2\\\"}}]}]\"])</script><script>self.__next_f.push([1,\"20:T3dfb,\"])</script><script>self.__next_f.push([1,\"\\n# IETF Weighs an AI Agent Protocol Standard in 2026\\n\\n**In one line:** At IETF 126 in Vienna this week, a Birds-of-a-Feather session called agentproto asked whether the internet's standards body should define how AI agents talk to each other across organizations — the gap that today's dominant protocols, MCP and A2A, leave open.[^1]\\n\\n**TL;DR:** For more than a year, vendors shipped competing AI agent protocols — Anthropic's MCP, Google's A2A, and several more — and none of them cleared the one bar that makes a protocol interoperable across organizational boundaries: an IETF RFC. On Thursday, July 23, the agentproto Birds-of-a-Feather (BoF) session at IETF 126 in Vienna brought that question into the Internet Engineering Task Force, with a view toward chartering a Working Group.[^1] This is not a vote and not a product launch; the IETF works by rough consensus, and any resulting standard is years away.[^2] What is genuinely new is that agent-to-agent communication is now being treated as an internet-infrastructure problem, not just a vendor feature.\\n\\n## What you'll learn\\n\\n- What happened at the agentproto BoF at IETF 126, and what a \\\"Birds-of-a-Feather\\\" session actually decides\\n- Why the IETF works by rough consensus rather than a vote — and why that framing matters here\\n- How MCP and A2A differ, and the interoperability gap neither one closes\\n- The specific problems the underlying framework draft says still need a standard\\n- Why prompt injection is the security test any agent protocol standard has to pass\\n- The realistic timeline from a BoF to a published RFC, and what to watch next\\n\\n## What happened at the agentproto BoF\\n\\nThe IETF 126 meeting ran 18–24 July 2026 in Vienna, and among the established Working Group sessions the organization scheduled five Birds-of-a-Feather sessions — early, community-wide discussions about work that might be ready for the IETF to take on.[^1] Three of the five touched AI agents directly. The one with the highest stakes for anyone building multi-agent systems was **agentproto** (Agent Communication Protocols), held Thursday, 23 July, 09:00–11:00 CEST.[^1]\\n\\nThe IETF's own framing is precise: the past year produced \\\"a rush of competing, overlapping protocols for connecting AI agents to one another and to the tools they use — Model Context Protocol (MCP), Agent2Agent (A2A), the Agent Communication Protocol (ACP), the Agent Network Protocol (ANP), and more.\\\" The agentproto session, it says, \\\"brings that conversation into the IETF,\\\" building on a well-attended IETF 124 side meeting and on framework and requirements work led by Jonathan Rosenberg and Cullen Jennings, \\\"with a view toward chartering a Working Group to take that work forward.\\\"[^1]\\n\\nThat phrase — *chartering a Working Group* — is the actual object of the meeting. A BoF is not where a standard gets written. It is where the community decides whether there is enough consensus, energy, and a tight enough scope to justify starting the multi-year process that eventually produces one.[^2]\\n\\n## Why it is rough consensus, not a vote\\n\\nIt is tempting to describe Thursday's session as a vote on an IETF AI agent protocol standard. That is the wrong mental model, and the distinction is not pedantic. The IETF does not decide by counting ballots. It decides by \\\"rough consensus and running code\\\" — a working agreement in the room and on the mailing list, backed by implementations that actually run.[^2] A BoF that is \\\"working-group-forming,\\\" as agentproto aims to be, succeeds when it demonstrates that a coherent problem and a willing community exist; it can just as easily send the work back to the mailing list if the discussion reveals too much disagreement about scope.[^2]\\n\\nThis is why an IETF outcome carries weight that a vendor announcement does not. The RFCs that came out of this process define TLS, DNS, and the transport underneath modern web traffic, and they endure precisely because they were not imposed by one company. If the IETF eventually charters an agent-protocol Working Group, it is asserting that **an IETF AI agent protocol standard** belongs in the same category as those foundational specifications — an internet-layer concern rather than a product-layer one. As of this writing, the formal result of Thursday's session — whether a Working Group is chartered — follows that consensus process; session materials and minutes are posted to the IETF Datatracker as they are finalized, and that is the authoritative place to confirm the outcome rather than early press summaries.\\n\\n## MCP vs A2A: two layers, one missing piece\\n\\nTo see why the IETF is interested at all, you have to see what the existing protocols do and do not cover. They are not really competitors so much as neighbors solving different halves of the problem.\\n\\n**MCP (Model Context Protocol)** is a client-server protocol: an agent reaches out to a tool, database, or API and requests data or an action. Anthropic donated MCP to the Agentic AI Foundation — a directed fund under the Linux Foundation — on 9 December 2025, and by that point the protocol reported \\\"over 97 million monthly SDK downloads, 10,000 active servers,\\\" with first-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code.[^3] Its next revision, the 2026-07-28 spec, is the largest since launch and, among other things, realigns authorization with OAuth 2.1; we covered that change in depth in our write-up of [MCP's stateless 2026-07-28 spec](/mcp-stateless-protocol-enterprise-authorization).[^9]\\n\\n**A2A (Agent2Agent)** is a peer-to-peer protocol: two agents discover each other's capabilities and delegate tasks. Google donated A2A to the Linux Foundation on 23 June 2025 at Open Source Summit North America, with Amazon Web Services, Cisco, Microsoft, Salesforce, SAP, and ServiceNow among the founding members; the coalition has since grown to over 100 technology companies.[^4][^5] If you want the hands-on version of how agents advertise capabilities and hand off work, our [A2A protocol tutorial](/a2a-protocol-python-tutorial) walks through it.\\n\\nHere is the gap. MCP standardizes the agent-to-tool link. A2A standardizes the agent-to-agent link within a broadly cooperating ecosystem. Neither one fully specifies what happens when an agent in *your* organization needs to prove to an agent in *someone else's* organization that it is authorized to act on a user's behalf — and to do so in a way both sides can verify without a prior bilateral integration. That cross-domain, no-prior-trust case is exactly the territory internet standards exist to cover.\\n\\n## The problems the framework says still need a standard\\n\\nThe intellectual basis for agentproto is a framework and requirements document authored by Jonathan Rosenberg, of Five9, and Cullen Jennings, of Cisco.[^6] Rosenberg's involvement is a signal in itself: he is a lead author of RFC 3261, the Session Initiation Protocol that governs much of the internet's real-time voice and video. One procedural caveat worth stating plainly: an Internet-Draft is a proposal, not a standard. The datatracker attaches an explicit disclaimer that such drafts are \\\"not endorsed by the IETF\\\" and have \\\"no formal standing in the IETF standards process,\\\" and the early framework draft has already been superseded — the current document is `draft-rosenberg-agentproto-usecases`.[^6][^7]\\n\\nWith that caveat, the framework's argument is that today's protocols leave a short list of hard problems unsolved, and that these are the ones worth standardizing. Its requirements sections map to them directly: discovery (how agents find each other, especially across domains), authentication and authorization (how identity and credentials are federated so one organization's agent can be trusted by another's), lifecycle management (how a chain of delegated agents is managed across the life of a task), and user confirmation (how a human stays in the loop before an action such as booking a flight is committed).[^6] The draft frames agent communication as a new application-layer concern — occupying the same tier of the internet stack as HTTP, SIP, and RTP do today.[^6]\\n\\n## Why prompt injection is the security test\\n\\nThe most concrete technical argument for standardizing this at the protocol layer is a security one, and it centers on prompt injection.\\n\\nIn a single-agent system, prompt injection means a user crafts input that overrides the agent's instructions. OWASP ranks it as **LLM01 — the number-one risk** in its Top 10 for LLM Applications.[^8] The multi-agent version is structurally worse. A malicious user can craft input for Agent A that is really aimed at Agent B, the agent that A calls next. Because A relays user content to B as part of normal operation, and because B trusts A, the injected instruction can ride the trust relationship straight past A's defenses.[^6] The framework's position is blunt: prompt injection is notoriously difficult to prevent, so the protocol-level answer is not prevention but attribution — mechanisms for logging, diagnosis, and reconstructing which agent did what when an incident happens.[^6]\\n\\nThat is a requirement no purely application-level defense can satisfy, because the attack crosses a boundary between two independently operated systems. It is also the clearest illustration of why \\\"just use MCP and A2A\\\" is not a complete answer: neither was designed to carry incident attribution across an inter-domain agent cascade.\\n\\n## The realistic timeline — and what to watch\\n\\nSet expectations accordingly. The IETF process is deliberately slow: a proposal typically moves from a BoF, to a chartered Working Group, through multiple Internet-Draft revisions and reviews, to a published RFC — a path that commonly takes on the order of two to four years.[^10] Nothing shipped in Vienna this week. What the meeting could produce is a decision to *start*, and that decision then shapes what the RFC pipeline looks like in 2027 and 2028.\\n\\nThe strategic question underneath is whether an open IETF AI agent protocol standard will define inter-domain agent communication, or whether the market-dominant protocols will harden into de facto standards by deployment momentum alone. MCP's 97-million-downloads-a-month adoption is a real gravitational field, and it is entirely possible that the practical baseline gets set by what is already deployed rather than by what the IETF eventually blesses.[^3] The tension between those two outcomes is the story worth following. It is also the same interoperability-versus-lock-in tension that regulators are pressing from a different direction, as we covered in [the EU's push for AI agent interoperability under the DMA](/eu-android-ai-agent-interoperability-dma).\\n\\nFor now, the honest status is: the conversation has arrived at the IETF, the problem statement is well-formed, and the outcome of Thursday's session is a matter of public record on the IETF Datatracker rather than of speculation.\\n\\n## FAQ\\n\\n### Is the IETF standardizing AI agent protocols?\\n\\nNot yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.[^1] A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.[^10] The authoritative outcome of the session is posted to the IETF Datatracker.\\n\\n### What is the agentproto BoF at IETF 126?\\n\\nAgentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.[^1][^6]\\n\\n### How is MCP different from A2A?\\n\\nMCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.[^3][^4] They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.[^6]\\n\\n### What would an IETF RFC add that MCP and A2A don't cover?\\n\\nThe framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.[^6] These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\\n\\n### Why is prompt injection worse in multi-agent systems?\\n\\nBecause it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.[^6] OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.[^8]\\n\\n[^1]: \\\"Birds of a Feather at IETF 126,\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). https://www.ietf.org/blog/ietf126-bofs/\\n[^2]: \\\"Birds of a Feather (BOF),\\\" IETF process documentation, and \\\"Introduction to the IETF\\\" (rough consensus and running code). https://www.ietf.org/process/bofs/\\n[^3]: \\\"MCP joins the Agentic AI Foundation,\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/\\n[^4]: \\\"Google Cloud donates A2A to Linux Foundation,\\\" Google Developers Blog, 23 June 2025. https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/\\n[^5]: \\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\" Google Open Source Blog, 16 April 2026 (\\\"over 100 technology companies now supporting the project\\\"; A2A announced 9 April 2025, donated 23 June 2025). https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html\\n[^6]: \\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\"Prompt injection attacks are notoriously difficult to prevent\\\"). This individual Internet-Draft is expired and \\\"has no formal standing in the IETF standards process.\\\" Full text: https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt — status: https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/\\n[^7]: \\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-agentproto-usecases (the current, active revision). https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/\\n[^8]: \\\"OWASP Top 10 for LLM Applications 2025,\\\" LLM01: Prompt Injection. https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf\\n[^9]: \\\"The 2026-07-28 MCP Specification Release Candidate,\\\" Model Context Protocol Blog. https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/\\n[^10]: \\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm\\n\"])</script><script>self.__next_f.push([1,\"21:T6d06,\"])</script><script>self.__next_f.push([1,\"\\u003cp\\u003e\\u003cstrong\\u003eIn one line:\\u003c/strong\\u003e At IETF 126 in Vienna this week, a Birds-of-a-Feather session called agentproto asked whether the internet's standards body should define how AI agents talk to each other across organizations — the gap that today's dominant protocols, MCP and A2A, leave open.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eTL;DR:\\u003c/strong\\u003e For more than a year, vendors shipped competing AI agent protocols — Anthropic's MCP, Google's A2A, and several more — and none of them cleared the one bar that makes a protocol interoperable across organizational boundaries: an IETF RFC. On Thursday, July 23, the agentproto Birds-of-a-Feather (BoF) session at IETF 126 in Vienna brought that question into the Internet Engineering Task Force, with a view toward chartering a Working Group.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e This is not a vote and not a product launch; the IETF works by rough consensus, and any resulting standard is years away.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e What is genuinely new is that agent-to-agent communication is now being treated as an internet-infrastructure problem, not just a vendor feature.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"what-youll-learn\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-youll-learn\\\"\\u003eWhat you'll learn\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cul\\u003e\\n\\u003cli\\u003eWhat happened at the agentproto BoF at IETF 126, and what a \\\"Birds-of-a-Feather\\\" session actually decides\\u003c/li\\u003e\\n\\u003cli\\u003eWhy the IETF works by rough consensus rather than a vote — and why that framing matters here\\u003c/li\\u003e\\n\\u003cli\\u003eHow MCP and A2A differ, and the interoperability gap neither one closes\\u003c/li\\u003e\\n\\u003cli\\u003eThe specific problems the underlying framework draft says still need a standard\\u003c/li\\u003e\\n\\u003cli\\u003eWhy prompt injection is the security test any agent protocol standard has to pass\\u003c/li\\u003e\\n\\u003cli\\u003eThe realistic timeline from a BoF to a published RFC, and what to watch next\\u003c/li\\u003e\\n\\u003c/ul\\u003e\\n\\u003ch2 id=\\\"what-happened-at-the-agentproto-bof\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-happened-at-the-agentproto-bof\\\"\\u003eWhat happened at the agentproto BoF\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe IETF 126 meeting ran 18–24 July 2026 in Vienna, and among the established Working Group sessions the organization scheduled five Birds-of-a-Feather sessions — early, community-wide discussions about work that might be ready for the IETF to take on.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e Three of the five touched AI agents directly. The one with the highest stakes for anyone building multi-agent systems was \\u003cstrong\\u003eagentproto\\u003c/strong\\u003e (Agent Communication Protocols), held Thursday, 23 July, 09:00–11:00 CEST.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThe IETF's own framing is precise: the past year produced \\\"a rush of competing, overlapping protocols for connecting AI agents to one another and to the tools they use — Model Context Protocol (MCP), Agent2Agent (A2A), the Agent Communication Protocol (ACP), the Agent Network Protocol (ANP), and more.\\\" The agentproto session, it says, \\\"brings that conversation into the IETF,\\\" building on a well-attended IETF 124 side meeting and on framework and requirements work led by Jonathan Rosenberg and Cullen Jennings, \\\"with a view toward chartering a Working Group to take that work forward.\\\"\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThat phrase — \\u003cem\\u003echartering a Working Group\\u003c/em\\u003e — is the actual object of the meeting. A BoF is not where a standard gets written. It is where the community decides whether there is enough consensus, energy, and a tight enough scope to justify starting the multi-year process that eventually produces one.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch2 id=\\\"why-it-is-rough-consensus-not-a-vote\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-it-is-rough-consensus-not-a-vote\\\"\\u003eWhy it is rough consensus, not a vote\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eIt is tempting to describe Thursday's session as a vote on an IETF AI agent protocol standard. That is the wrong mental model, and the distinction is not pedantic. The IETF does not decide by counting ballots. It decides by \\\"rough consensus and running code\\\" — a working agreement in the room and on the mailing list, backed by implementations that actually run.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e A BoF that is \\\"working-group-forming,\\\" as agentproto aims to be, succeeds when it demonstrates that a coherent problem and a willing community exist; it can just as easily send the work back to the mailing list if the discussion reveals too much disagreement about scope.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThis is why an IETF outcome carries weight that a vendor announcement does not. The RFCs that came out of this process define TLS, DNS, and the transport underneath modern web traffic, and they endure precisely because they were not imposed by one company. If the IETF eventually charters an agent-protocol Working Group, it is asserting that \\u003cstrong\\u003ean IETF AI agent protocol standard\\u003c/strong\\u003e belongs in the same category as those foundational specifications — an internet-layer concern rather than a product-layer one. As of this writing, the formal result of Thursday's session — whether a Working Group is chartered — follows that consensus process; session materials and minutes are posted to the IETF Datatracker as they are finalized, and that is the authoritative place to confirm the outcome rather than early press summaries.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"mcp-vs-a2a-two-layers-one-missing-piece\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#mcp-vs-a2a-two-layers-one-missing-piece\\\"\\u003eMCP vs A2A: two layers, one missing piece\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eTo see why the IETF is interested at all, you have to see what the existing protocols do and do not cover. They are not really competitors so much as neighbors solving different halves of the problem.\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eMCP (Model Context Protocol)\\u003c/strong\\u003e is a client-server protocol: an agent reaches out to a tool, database, or API and requests data or an action. Anthropic donated MCP to the Agentic AI Foundation — a directed fund under the Linux Foundation — on 9 December 2025, and by that point the protocol reported \\\"over 97 million monthly SDK downloads, 10,000 active servers,\\\" with first-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e Its next revision, the 2026-07-28 spec, is the largest since launch and, among other things, realigns authorization with OAuth 2.1; we covered that change in depth in our write-up of \\u003ca href=\\\"/mcp-stateless-protocol-enterprise-authorization\\\"\\u003eMCP's stateless 2026-07-28 spec\\u003c/a\\u003e.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-9\\\" id=\\\"user-content-fnref-9\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e4\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eA2A (Agent2Agent)\\u003c/strong\\u003e is a peer-to-peer protocol: two agents discover each other's capabilities and delegate tasks. Google donated A2A to the Linux Foundation on 23 June 2025 at Open Source Summit North America, with Amazon Web Services, Cisco, Microsoft, Salesforce, SAP, and ServiceNow among the founding members; the coalition has since grown to over 100 technology companies.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-4\\\" id=\\\"user-content-fnref-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e5\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-5\\\" id=\\\"user-content-fnref-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e6\\u003c/a\\u003e\\u003c/sup\\u003e If you want the hands-on version of how agents advertise capabilities and hand off work, our \\u003ca href=\\\"/a2a-protocol-python-tutorial\\\"\\u003eA2A protocol tutorial\\u003c/a\\u003e walks through it.\\u003c/p\\u003e\\n\\u003cp\\u003eHere is the gap. MCP standardizes the agent-to-tool link. A2A standardizes the agent-to-agent link within a broadly cooperating ecosystem. Neither one fully specifies what happens when an agent in \\u003cem\\u003eyour\\u003c/em\\u003e organization needs to prove to an agent in \\u003cem\\u003esomeone else's\\u003c/em\\u003e organization that it is authorized to act on a user's behalf — and to do so in a way both sides can verify without a prior bilateral integration. That cross-domain, no-prior-trust case is exactly the territory internet standards exist to cover.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"the-problems-the-framework-says-still-need-a-standard\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#the-problems-the-framework-says-still-need-a-standard\\\"\\u003eThe problems the framework says still need a standard\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe intellectual basis for agentproto is a framework and requirements document authored by Jonathan Rosenberg, of Five9, and Cullen Jennings, of Cisco.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e Rosenberg's involvement is a signal in itself: he is a lead author of RFC 3261, the Session Initiation Protocol that governs much of the internet's real-time voice and video. One procedural caveat worth stating plainly: an Internet-Draft is a proposal, not a standard. The datatracker attaches an explicit disclaimer that such drafts are \\\"not endorsed by the IETF\\\" and have \\\"no formal standing in the IETF standards process,\\\" and the early framework draft has already been superseded — the current document is \\u003ccode\\u003edraft-rosenberg-agentproto-usecases\\u003c/code\\u003e.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-7\\\" id=\\\"user-content-fnref-7\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e8\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eWith that caveat, the framework's argument is that today's protocols leave a short list of hard problems unsolved, and that these are the ones worth standardizing. Its requirements sections map to them directly: discovery (how agents find each other, especially across domains), authentication and authorization (how identity and credentials are federated so one organization's agent can be trusted by another's), lifecycle management (how a chain of delegated agents is managed across the life of a task), and user confirmation (how a human stays in the loop before an action such as booking a flight is committed).\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e The draft frames agent communication as a new application-layer concern — occupying the same tier of the internet stack as HTTP, SIP, and RTP do today.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch2 id=\\\"why-prompt-injection-is-the-security-test\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-prompt-injection-is-the-security-test\\\"\\u003eWhy prompt injection is the security test\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe most concrete technical argument for standardizing this at the protocol layer is a security one, and it centers on prompt injection.\\u003c/p\\u003e\\n\\u003cp\\u003eIn a single-agent system, prompt injection means a user crafts input that overrides the agent's instructions. OWASP ranks it as \\u003cstrong\\u003eLLM01 — the number-one risk\\u003c/strong\\u003e in its Top 10 for LLM Applications.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-8\\\" id=\\\"user-content-fnref-8\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e9\\u003c/a\\u003e\\u003c/sup\\u003e The multi-agent version is structurally worse. A malicious user can craft input for Agent A that is really aimed at Agent B, the agent that A calls next. Because A relays user content to B as part of normal operation, and because B trusts A, the injected instruction can ride the trust relationship straight past A's defenses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e The framework's position is blunt: prompt injection is notoriously difficult to prevent, so the protocol-level answer is not prevention but attribution — mechanisms for logging, diagnosis, and reconstructing which agent did what when an incident happens.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThat is a requirement no purely application-level defense can satisfy, because the attack crosses a boundary between two independently operated systems. It is also the clearest illustration of why \\\"just use MCP and A2A\\\" is not a complete answer: neither was designed to carry incident attribution across an inter-domain agent cascade.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"the-realistic-timeline--and-what-to-watch\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#the-realistic-timeline--and-what-to-watch\\\"\\u003eThe realistic timeline — and what to watch\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eSet expectations accordingly. The IETF process is deliberately slow: a proposal typically moves from a BoF, to a chartered Working Group, through multiple Internet-Draft revisions and reviews, to a published RFC — a path that commonly takes on the order of two to four years.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-10\\\" id=\\\"user-content-fnref-10\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e10\\u003c/a\\u003e\\u003c/sup\\u003e Nothing shipped in Vienna this week. What the meeting could produce is a decision to \\u003cem\\u003estart\\u003c/em\\u003e, and that decision then shapes what the RFC pipeline looks like in 2027 and 2028.\\u003c/p\\u003e\\n\\u003cp\\u003eThe strategic question underneath is whether an open IETF AI agent protocol standard will define inter-domain agent communication, or whether the market-dominant protocols will harden into de facto standards by deployment momentum alone. MCP's 97-million-downloads-a-month adoption is a real gravitational field, and it is entirely possible that the practical baseline gets set by what is already deployed rather than by what the IETF eventually blesses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e The tension between those two outcomes is the story worth following. It is also the same interoperability-versus-lock-in tension that regulators are pressing from a different direction, as we covered in \\u003ca href=\\\"/eu-android-ai-agent-interoperability-dma\\\"\\u003ethe EU's push for AI agent interoperability under the DMA\\u003c/a\\u003e.\\u003c/p\\u003e\\n\\u003cp\\u003eFor now, the honest status is: the conversation has arrived at the IETF, the problem statement is well-formed, and the outcome of Thursday's session is a matter of public record on the IETF Datatracker rather than of speculation.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"faq\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#faq\\\"\\u003eFAQ\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003ch3 id=\\\"is-the-ietf-standardizing-ai-agent-protocols\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#is-the-ietf-standardizing-ai-agent-protocols\\\"\\u003eIs the IETF standardizing AI agent protocols?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eNot yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-10\\\" id=\\\"user-content-fnref-10-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e10\\u003c/a\\u003e\\u003c/sup\\u003e The authoritative outcome of the session is posted to the IETF Datatracker.\\u003c/p\\u003e\\n\\u003ch3 id=\\\"what-is-the-agentproto-bof-at-ietf-126\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-is-the-agentproto-bof-at-ietf-126\\\"\\u003eWhat is the agentproto BoF at IETF 126?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eAgentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-7\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-7\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch3 id=\\\"how-is-mcp-different-from-a2a\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#how-is-mcp-different-from-a2a\\\"\\u003eHow is MCP different from A2A?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eMCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-4\\\" id=\\\"user-content-fnref-4-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e5\\u003c/a\\u003e\\u003c/sup\\u003e They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-8\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch3 id=\\\"what-would-an-ietf-rfc-add-that-mcp-and-a2a-dont-cover\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-would-an-ietf-rfc-add-that-mcp-and-a2a-dont-cover\\\"\\u003eWhat would an IETF RFC add that MCP and A2A don't cover?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eThe framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-9\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\\u003c/p\\u003e\\n\\u003ch3 id=\\\"why-is-prompt-injection-worse-in-multi-agent-systems\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-is-prompt-injection-worse-in-multi-agent-systems\\\"\\u003eWhy is prompt injection worse in multi-agent systems?\\u003c/a\\u003e\\u003c/h3\\u003e\\n\\u003cp\\u003eBecause it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-10\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-8\\\" id=\\\"user-content-fnref-8-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e9\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003csection data-footnotes=\\\"\\\" class=\\\"footnotes\\\"\\u003e\\u003ch2 class=\\\"sr-only\\\" id=\\\"footnote-label\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#footnote-label\\\"\\u003eFootnotes\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003col\\u003e\\n\\u003cli id=\\\"user-content-fn-1\\\"\\u003e\\n\\u003cp\\u003e\\\"Birds of a Feather at IETF 126,\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). \\u003ca href=\\\"https://www.ietf.org/blog/ietf126-bofs/\\\"\\u003ehttps://www.ietf.org/blog/ietf126-bofs/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e3\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-4\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-4\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e4\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-5\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-5\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e5\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-6\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-6\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e6\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-1-7\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 1-7\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e7\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-2\\\"\\u003e\\n\\u003cp\\u003e\\\"Birds of a Feather (BOF),\\\" IETF process documentation, and \\\"Introduction to the IETF\\\" (rough consensus and running code). \\u003ca href=\\\"https://www.ietf.org/process/bofs/\\\"\\u003ehttps://www.ietf.org/process/bofs/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-2-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 2-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-2-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 2-3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e3\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-2-4\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 2-4\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e4\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-3\\\"\\u003e\\n\\u003cp\\u003e\\\"MCP joins the Agentic AI Foundation,\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). \\u003ca href=\\\"https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/\\\"\\u003ehttps://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-3-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 3-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-3-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 3-3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e3\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-9\\\"\\u003e\\n\\u003cp\\u003e\\\"The 2026-07-28 MCP Specification Release Candidate,\\\" Model Context Protocol Blog. \\u003ca href=\\\"https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/\\\"\\u003ehttps://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-9\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 4\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-4\\\"\\u003e\\n\\u003cp\\u003e\\\"Google Cloud donates A2A to Linux Foundation,\\\" Google Developers Blog, 23 June 2025. \\u003ca href=\\\"https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/\\\"\\u003ehttps://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-4\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 5\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-4-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 5-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-5\\\"\\u003e\\n\\u003cp\\u003e\\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\" Google Open Source Blog, 16 April 2026 (\\\"over 100 technology companies now supporting the project\\\"; A2A announced 9 April 2025, donated 23 June 2025). \\u003ca href=\\\"https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html\\\"\\u003ehttps://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-5\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 6\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-6\\\"\\u003e\\n\\u003cp\\u003e\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\"Prompt injection attacks are notoriously difficult to prevent\\\"). This individual Internet-Draft is expired and \\\"has no formal standing in the IETF standards process.\\\" Full text: \\u003ca href=\\\"https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt\\\"\\u003ehttps://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt\\u003c/a\\u003e — status: \\u003ca href=\\\"https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/\\\"\\u003ehttps://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-3\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-3\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e3\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-4\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-4\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e4\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-5\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-5\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e5\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-6\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-6\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e6\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-7\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-7\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e7\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-8\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-8\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e8\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-9\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-9\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e9\\u003c/sup\\u003e\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-6-10\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 7-10\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e10\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-7\\\"\\u003e\\n\\u003cp\\u003e\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-agentproto-usecases (the current, active revision). \\u003ca href=\\\"https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/\\\"\\u003ehttps://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-7\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 8\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-8\\\"\\u003e\\n\\u003cp\\u003e\\\"OWASP Top 10 for LLM Applications 2025,\\\" LLM01: Prompt Injection. \\u003ca href=\\\"https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf\\\"\\u003ehttps://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-8\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 9\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-8-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 9-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003cli id=\\\"user-content-fn-10\\\"\\u003e\\n\\u003cp\\u003e\\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). \\u003ca href=\\\"https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm\\\"\\u003ehttps://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-10\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 10\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003c/a\\u003e \\u003ca href=\\\"#user-content-fnref-10-2\\\" data-footnote-backref=\\\"\\\" aria-label=\\\"Back to reference 10-2\\\" class=\\\"data-footnote-backref\\\"\\u003e↩\\u003csup\\u003e2\\u003c/sup\\u003e\\u003c/a\\u003e\\u003c/p\\u003e\\n\\u003c/li\\u003e\\n\\u003c/ol\\u003e\\n\\u003c/section\\u003e\"])</script><script>self.__next_f.push([1,\"22:T3adb,\"])</script><script>self.__next_f.push([1,\"\\u003chtml\\u003e\\u003chead\\u003e\\u003c/head\\u003e\\u003cbody\\u003e\\u003cp\\u003e\\u003cstrong\\u003eIn one line:\\u003c/strong\\u003e At IETF 126 in Vienna this week, a Birds-of-a-Feather session called agentproto asked whether the internet's standards body should define how AI agents talk to each other across organizations — the gap that today's dominant protocols, MCP and A2A, leave open.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eTL;DR:\\u003c/strong\\u003e For more than a year, vendors shipped competing AI agent protocols — Anthropic's MCP, Google's A2A, and several more — and none of them cleared the one bar that makes a protocol interoperable across organizational boundaries: an IETF RFC. On Thursday, July 23, the agentproto Birds-of-a-Feather (BoF) session at IETF 126 in Vienna brought that question into the Internet Engineering Task Force, with a view toward chartering a Working Group.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e This is not a vote and not a product launch; the IETF works by rough consensus, and any resulting standard is years away.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e What is genuinely new is that agent-to-agent communication is now being treated as an internet-infrastructure problem, not just a vendor feature.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"what-youll-learn\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-youll-learn\\\"\\u003eWhat you'll learn\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cul\\u003e\\n\\u003cli\\u003eWhat happened at the agentproto BoF at IETF 126, and what a \\\"Birds-of-a-Feather\\\" session actually decides\\u003c/li\\u003e\\n\\u003cli\\u003eWhy the IETF works by rough consensus rather than a vote — and why that framing matters here\\u003c/li\\u003e\\n\\u003cli\\u003eHow MCP and A2A differ, and the interoperability gap neither one closes\\u003c/li\\u003e\\n\\u003cli\\u003eThe specific problems the underlying framework draft says still need a standard\\u003c/li\\u003e\\n\\u003cli\\u003eWhy prompt injection is the security test any agent protocol standard has to pass\\u003c/li\\u003e\\n\\u003cli\\u003eThe realistic timeline from a BoF to a published RFC, and what to watch next\\u003c/li\\u003e\\n\\u003c/ul\\u003e\\n\\u003ch2 id=\\\"what-happened-at-the-agentproto-bof\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#what-happened-at-the-agentproto-bof\\\"\\u003eWhat happened at the agentproto BoF\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe IETF 126 meeting ran 18–24 July 2026 in Vienna, and among the established Working Group sessions the organization scheduled five Birds-of-a-Feather sessions — early, community-wide discussions about work that might be ready for the IETF to take on.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e Three of the five touched AI agents directly. The one with the highest stakes for anyone building multi-agent systems was \\u003cstrong\\u003eagentproto\\u003c/strong\\u003e (Agent Communication Protocols), held Thursday, 23 July, 09:00–11:00 CEST.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThe IETF's own framing is precise: the past year produced \\\"a rush of competing, overlapping protocols for connecting AI agents to one another and to the tools they use — Model Context Protocol (MCP), Agent2Agent (A2A), the Agent Communication Protocol (ACP), the Agent Network Protocol (ANP), and more.\\\" The agentproto session, it says, \\\"brings that conversation into the IETF,\\\" building on a well-attended IETF 124 side meeting and on framework and requirements work led by Jonathan Rosenberg and Cullen Jennings, \\\"with a view toward chartering a Working Group to take that work forward.\\\"\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-1\\\" id=\\\"user-content-fnref-1-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e1\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThat phrase — \\u003cem\\u003echartering a Working Group\\u003c/em\\u003e — is the actual object of the meeting. A BoF is not where a standard gets written. It is where the community decides whether there is enough consensus, energy, and a tight enough scope to justify starting the multi-year process that eventually produces one.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch2 id=\\\"why-it-is-rough-consensus-not-a-vote\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-it-is-rough-consensus-not-a-vote\\\"\\u003eWhy it is rough consensus, not a vote\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eIt is tempting to describe Thursday's session as a vote on an IETF AI agent protocol standard. That is the wrong mental model, and the distinction is not pedantic. The IETF does not decide by counting ballots. It decides by \\\"rough consensus and running code\\\" — a working agreement in the room and on the mailing list, backed by implementations that actually run.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e A BoF that is \\\"working-group-forming,\\\" as agentproto aims to be, succeeds when it demonstrates that a coherent problem and a willing community exist; it can just as easily send the work back to the mailing list if the discussion reveals too much disagreement about scope.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-2\\\" id=\\\"user-content-fnref-2-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e2\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThis is why an IETF outcome carries weight that a vendor announcement does not. The RFCs that came out of this process define TLS, DNS, and the transport underneath modern web traffic, and they endure precisely because they were not imposed by one company. If the IETF eventually charters an agent-protocol Working Group, it is asserting that \\u003cstrong\\u003ean IETF AI agent protocol standard\\u003c/strong\\u003e belongs in the same category as those foundational specifications — an internet-layer concern rather than a product-layer one. As of this writing, the formal result of Thursday's session — whether a Working Group is chartered — follows that consensus process; session materials and minutes are posted to the IETF Datatracker as they are finalized, and that is the authoritative place to confirm the outcome rather than early press summaries.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"mcp-vs-a2a-two-layers-one-missing-piece\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#mcp-vs-a2a-two-layers-one-missing-piece\\\"\\u003eMCP vs A2A: two layers, one missing piece\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eTo see why the IETF is interested at all, you have to see what the existing protocols do and do not cover. They are not really competitors so much as neighbors solving different halves of the problem.\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eMCP (Model Context Protocol)\\u003c/strong\\u003e is a client-server protocol: an agent reaches out to a tool, database, or API and requests data or an action. Anthropic donated MCP to the Agentic AI Foundation — a directed fund under the Linux Foundation — on 9 December 2025, and by that point the protocol reported \\\"over 97 million monthly SDK downloads, 10,000 active servers,\\\" with first-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e Its next revision, the 2026-07-28 spec, is the largest since launch and, among other things, realigns authorization with OAuth 2.1; we covered that change in depth in our write-up of \\u003ca href=\\\"/mcp-stateless-protocol-enterprise-authorization\\\"\\u003eMCP's stateless 2026-07-28 spec\\u003c/a\\u003e.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-9\\\" id=\\\"user-content-fnref-9\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e4\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cstrong\\u003eA2A (Agent2Agent)\\u003c/strong\\u003e is a peer-to-peer protocol: two agents discover each other's capabilities and delegate tasks. Google donated A2A to the Linux Foundation on 23 June 2025 at Open Source Summit North America, with Amazon Web Services, Cisco, Microsoft, Salesforce, SAP, and ServiceNow among the founding members; the coalition has since grown to over 100 technology companies.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-4\\\" id=\\\"user-content-fnref-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e5\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-5\\\" id=\\\"user-content-fnref-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e6\\u003c/a\\u003e\\u003c/sup\\u003e If you want the hands-on version of how agents advertise capabilities and hand off work, our \\u003ca href=\\\"/a2a-protocol-python-tutorial\\\"\\u003eA2A protocol tutorial\\u003c/a\\u003e walks through it.\\u003c/p\\u003e\\n\\u003cdiv data-ad-placement=\\\"post-in-article-mid\\\" class=\\\"not-prose my-8\\\"\\u003e\\u003c/div\\u003e\\n\\n\\u003cp\\u003eHere is the gap. MCP standardizes the agent-to-tool link. A2A standardizes the agent-to-agent link within a broadly cooperating ecosystem. Neither one fully specifies what happens when an agent in \\u003cem\\u003eyour\\u003c/em\\u003e organization needs to prove to an agent in \\u003cem\\u003esomeone else's\\u003c/em\\u003e organization that it is authorized to act on a user's behalf — and to do so in a way both sides can verify without a prior bilateral integration. That cross-domain, no-prior-trust case is exactly the territory internet standards exist to cover.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"the-problems-the-framework-says-still-need-a-standard\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#the-problems-the-framework-says-still-need-a-standard\\\"\\u003eThe problems the framework says still need a standard\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe intellectual basis for agentproto is a framework and requirements document authored by Jonathan Rosenberg, of Five9, and Cullen Jennings, of Cisco.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e Rosenberg's involvement is a signal in itself: he is a lead author of RFC 3261, the Session Initiation Protocol that governs much of the internet's real-time voice and video. One procedural caveat worth stating plainly: an Internet-Draft is a proposal, not a standard. The datatracker attaches an explicit disclaimer that such drafts are \\\"not endorsed by the IETF\\\" and have \\\"no formal standing in the IETF standards process,\\\" and the early framework draft has already been superseded — the current document is \\u003ccode\\u003edraft-rosenberg-agentproto-usecases\\u003c/code\\u003e.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-7\\\" id=\\\"user-content-fnref-7\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e8\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eWith that caveat, the framework's argument is that today's protocols leave a short list of hard problems unsolved, and that these are the ones worth standardizing. Its requirements sections map to them directly: discovery (how agents find each other, especially across domains), authentication and authorization (how identity and credentials are federated so one organization's agent can be trusted by another's), lifecycle management (how a chain of delegated agents is managed across the life of a task), and user confirmation (how a human stays in the loop before an action such as booking a flight is committed).\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-3\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e The draft frames agent communication as a new application-layer concern — occupying the same tier of the internet stack as HTTP, SIP, and RTP do today.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-4\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003ch2 id=\\\"why-prompt-injection-is-the-security-test\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#why-prompt-injection-is-the-security-test\\\"\\u003eWhy prompt injection is the security test\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eThe most concrete technical argument for standardizing this at the protocol layer is a security one, and it centers on prompt injection.\\u003c/p\\u003e\\n\\u003cp\\u003eIn a single-agent system, prompt injection means a user crafts input that overrides the agent's instructions. OWASP ranks it as \\u003cstrong\\u003eLLM01 — the number-one risk\\u003c/strong\\u003e in its Top 10 for LLM Applications.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-8\\\" id=\\\"user-content-fnref-8\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e9\\u003c/a\\u003e\\u003c/sup\\u003e The multi-agent version is structurally worse. A malicious user can craft input for Agent A that is really aimed at Agent B, the agent that A calls next. Because A relays user content to B as part of normal operation, and because B trusts A, the injected instruction can ride the trust relationship straight past A's defenses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-5\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e The framework's position is blunt: prompt injection is notoriously difficult to prevent, so the protocol-level answer is not prevention but attribution — mechanisms for logging, diagnosis, and reconstructing which agent did what when an incident happens.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-6\\\" id=\\\"user-content-fnref-6-6\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e7\\u003c/a\\u003e\\u003c/sup\\u003e\\u003c/p\\u003e\\n\\u003cp\\u003eThat is a requirement no purely application-level defense can satisfy, because the attack crosses a boundary between two independently operated systems. It is also the clearest illustration of why \\\"just use MCP and A2A\\\" is not a complete answer: neither was designed to carry incident attribution across an inter-domain agent cascade.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"the-realistic-timeline--and-what-to-watch\\\"\\u003e\\u003ca class=\\\"anchor\\\" href=\\\"#the-realistic-timeline--and-what-to-watch\\\"\\u003eThe realistic timeline — and what to watch\\u003c/a\\u003e\\u003c/h2\\u003e\\n\\u003cp\\u003eSet expectations accordingly. The IETF process is deliberately slow: a proposal typically moves from a BoF, to a chartered Working Group, through multiple Internet-Draft revisions and reviews, to a published RFC — a path that commonly takes on the order of two to four years.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-10\\\" id=\\\"user-content-fnref-10\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e10\\u003c/a\\u003e\\u003c/sup\\u003e Nothing shipped in Vienna this week. What the meeting could produce is a decision to \\u003cem\\u003estart\\u003c/em\\u003e, and that decision then shapes what the RFC pipeline looks like in 2027 and 2028.\\u003c/p\\u003e\\n\\u003cp\\u003eThe strategic question underneath is whether an open IETF AI agent protocol standard will define inter-domain agent communication, or whether the market-dominant protocols will harden into de facto standards by deployment momentum alone. MCP's 97-million-downloads-a-month adoption is a real gravitational field, and it is entirely possible that the practical baseline gets set by what is already deployed rather than by what the IETF eventually blesses.\\u003csup\\u003e\\u003ca href=\\\"#user-content-fn-3\\\" id=\\\"user-content-fnref-3-2\\\" data-footnote-ref=\\\"\\\" aria-describedby=\\\"footnote-label\\\"\\u003e3\\u003c/a\\u003e\\u003c/sup\\u003e The tension between those two outcomes is the story worth following. It is also the same interoperability-versus-lock-in tension that regulators are pressing from a different direction, as we covered in \\u003ca href=\\\"/eu-android-ai-agent-interoperability-dma\\\"\\u003ethe EU's push for AI agent interoperability under the DMA\\u003c/a\\u003e.\\u003c/p\\u003e\\n\\u003cp\\u003eFor now, the honest status is: the conversation has arrived at the IETF, the problem statement is well-formed, and the outcome of Thursday's session is a matter of public record on the IETF Datatracker rather than of speculation.\\u003c/p\\u003e\\n\\n\\n\\n\\n\\n\\n\\n\\n\\n\\n\\n\\u003c/body\\u003e\\u003c/html\\u003e\"])</script><script>self.__next_f.push([1,\"23:Tbf3,\"])</script><script>self.__next_f.push([1,\"Because it can cascade. A user injects malicious input into Agent A that is aimed at Agent B; A relays it to B as normal operation, and B — trusting A — acts on it, bypassing A's defenses.7 OWASP already ranks prompt injection as the top risk for LLM applications; the multi-agent trust relationship adds a new path that application-level filters were not designed to catch.9 Footnotes\\n\\n\\n\\\"Birds of a Feather at IETF 126,\\\" IETF Blog, 2 July 2026 (BoF schedule, dates, and agentproto description). https://www.ietf.org/blog/ietf126-bofs/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7\\n\\n\\n\\\"Birds of a Feather (BOF),\\\" IETF process documentation, and \\\"Introduction to the IETF\\\" (rough consensus and running code). https://www.ietf.org/process/bofs/ ↩ ↩2 ↩3 ↩4\\n\\n\\n\\\"MCP joins the Agentic AI Foundation,\\\" Model Context Protocol Blog, 9 December 2025 (97 million monthly SDK downloads, 10,000 active servers, Linux Foundation donation). https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/ ↩ ↩2 ↩3\\n\\n\\n\\\"The 2026-07-28 MCP Specification Release Candidate,\\\" Model Context Protocol Blog. https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/ ↩\\n\\n\\n\\\"Google Cloud donates A2A to Linux Foundation,\\\" Google Developers Blog, 23 June 2025. https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/ ↩ ↩2\\n\\n\\n\\\"A year of open collaboration: Celebrating the anniversary of A2A,\\\" Google Open Source Blog, 16 April 2026 (\\\"over 100 technology companies now supporting the project\\\"; A2A announced 9 April 2025, donated 23 June 2025). https://opensource.googleblog.com/2026/04/a-year-of-open-collaboration-celebrating-the-anniversary-of-a2a.html ↩\\n\\n\\n\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-aiproto-framework-00, IETF (authors J. Rosenberg / Five9 and C. Jennings / Cisco; §3 requirements — Discovery, Lifecycle Management, Authentication and Authorization, User Confirmation; \\\"Prompt injection attacks are notoriously difficult to prevent\\\"). This individual Internet-Draft is expired and \\\"has no formal standing in the IETF standards process.\\\" Full text: https://www.ietf.org/archive/id/draft-rosenberg-aiproto-framework-00.txt — status: https://datatracker.ietf.org/doc/draft-rosenberg-aiproto-framework/00/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10\\n\\n\\n\\\"Framework, Use Cases and Requirements for AI Agent Protocols,\\\" draft-rosenberg-agentproto-usecases (the current, active revision). https://datatracker.ietf.org/doc/draft-rosenberg-agentproto-usecases/ ↩\\n\\n\\n\\\"OWASP Top 10 for LLM Applications 2025,\\\" LLM01: Prompt Injection. https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf ↩ ↩2\\n\\n\\n\\\"Competing AI Agent Protocols Face IETF Standards Scrutiny at Vienna Meeting,\\\" Tech Times, 18 July 2026 (BoF-to-RFC timeline framing and framework summary). https://www.techtimes.com/articles/320919/20260718/competing-ai-agent-protocols-face-ietf-standards-scrutiny-vienna-meeting.htm ↩ ↩2\"])</script><script>self.__next_f.push([1,\"25:T520e,\"])</script><script>self.__next_f.push([1,\"\\n## TL;DR\\n\\nOn April 28, 2026 Anthropic launched **Claude for Creative Work** — a coordinated release of nine creative-tool connectors, with the **Adobe for creativity** connector as the marquee partnership.[^1][^2][^3] The Adobe connector exposes **50+ pro-grade tools** across Photoshop, Lightroom, Illustrator, Firefly, Premiere, Express, InDesign, and Adobe Stock to Claude through the Model Context Protocol (MCP), letting users describe a creative outcome in chat and have Claude orchestrate the multi-step workflow across Adobe apps.[^2][^4]\\n\\nThe other eight connectors that shipped the same day cover Blender, Ableton Live, Autodesk Fusion, Splice, SketchUp, Affinity by Canva, and Resolume's Arena and Wire — turning Claude into an orchestration layer over the 2D, 3D, audio, and live-visual stacks creative pros already pay for.[^1][^5] Anthropic also launched programs with **RISD, Ringling College of Art and Design, and Goldsmiths, University of London** to put the connectors in front of art-school students and faculty.[^1][^6]\\n\\nFor Adobe, the release lands the day after the Firefly AI Assistant entered public beta on April 27, 2026 — back-to-back agentic-AI launches from Adobe in two weeks. For Anthropic, it is the most coordinated push yet to put Claude inside the daily software of professional creatives rather than asking them to come to claude.ai.[^7]\\n\\n## What You'll Learn\\n\\nBy the end of this article you will understand:\\n\\n- What the Adobe for creativity connector actually does and how it works under MCP\\n- The full list of nine creative connectors that shipped together\\n- How the connector's free, Adobe-account, and Claude-plan tiers stack\\n- How Anthropic's strategy compares with Adobe's own Firefly AI Assistant\\n- Why \\\"Claude orchestrating Photoshop\\\" is a different bet from \\\"Claude generating images\\\"\\n- What Claude Design — Anthropic's same-day Canva-exporting design product — adds to the picture\\n- What this means for image-generation incumbents like OpenAI and Midjourney\\n\\n---\\n\\n## What Adobe and Anthropic Actually Shipped\\n\\nOn April 28, 2026, Adobe and Anthropic jointly launched the **Adobe for creativity** connector inside Claude. Adobe published the announcement on its corporate blog the same day; Anthropic packaged the partnership inside a broader \\\"Claude for Creative Work\\\" launch covering nine connectors and three educational programs.[^1][^2]\\n\\nThe mechanic is straightforward. A user signs into Claude on the web, desktop, or mobile, opens the Connectors panel under Customize, finds **Adobe for creativity** in the directory, and installs it. Once enabled in a conversation, Claude can call any of the connector's exposed tools — read a Photoshop layer, generate a Firefly image, trim a Premiere clip, render an InDesign page — by emitting an [MCP tool call](/mcp-servers-explained-claudes-new-ai-backbone-for-real-automation). The user types a goal; Claude decides which Adobe tools to call, in what order, and with what parameters.[^2][^3][^4]\\n\\nThe set of exposed tools spans **eight Creative Cloud surfaces**:[^2][^3]\\n\\n| Adobe surface | Sample capability through the connector |\\n|---|---|\\n| Photoshop | Open files, read and edit layers, apply masks, run automated retouching |\\n| Illustrator | Vector edits, asset generation, format conversion |\\n| Lightroom | Photo organisation, presets, batch adjustments |\\n| Premiere | Clip operations and video formatting |\\n| Firefly | Generative image creation with Adobe's licensed-content models |\\n| Express | Quick template-driven design |\\n| InDesign | Page layout operations |\\n| Adobe Stock | Asset search and licensing |\\n\\nTotal tool count published by both vendors: **50+ pro-grade tools** behind the connector.[^2][^4] It is the same tool surface Adobe will eventually expose through its own [Firefly AI Assistant](https://blog.adobe.com/en/publish/2026/04/27/firefly-ai-assistant-public-beta), but with Claude — not Adobe's first-party agent — as the controller.\\n\\n## The Nine Connectors That Shipped Together\\n\\nAdobe got the headline, but eight other creative tools went live on April 28, 2026 alongside it. The full list:[^1][^5][^8]\\n\\n| Connector | What Claude can do with it |\\n|---|---|\\n| **Adobe for creativity** | Orchestrate 50+ Creative Cloud tools across Photoshop, Lightroom, Illustrator, Firefly, Premiere, Express, InDesign, and Stock |\\n| **Blender** | Natural-language interface to Blender's Python API; analyse scenes, batch-edit objects, add custom tools to the Blender UI |\\n| **Autodesk Fusion** | Create and modify 3D CAD models through conversation (requires a Fusion subscription) |\\n| **Ableton Live** | Grounded Q\\u0026A against the official Live and Push documentation |\\n| **Splice** | Search Splice's royalty-free sample catalogue from inside Claude |\\n| **SketchUp** | Use a chat session as the starting point for a 3D model, then open it in SketchUp for refinement |\\n| **Affinity by Canva** | Automate batch image adjustments, layer renaming, and file export across Affinity's unified Pixel, Vector, and Layout studios |\\n| **Resolume Arena** | Real-time natural-language control of live visuals for performance and AV production |\\n| **Resolume Wire** | Real-time natural-language control of Wire's node-based patches and effects, alongside Arena and Avenue |\\n\\nThat covers raster graphics (Adobe, Affinity), vector design (Adobe, Affinity), photo editing (Adobe, Affinity), 3D modelling (Blender, SketchUp, Autodesk Fusion), motion design (Adobe Premiere), audio production (Ableton, Splice), and live performance visuals (Resolume's pair) — essentially the bulk of the modern creative pro's toolchain in a single coordinated release.\\n\\nAnthropic also made a financial contribution to support continued work on Blender's Python API, which is what makes the Blender connector possible.[^1] Anthropic's contribution was initially structured as Blender Development Fund patronage, but Blender elected to receive it as a one-time donation instead — Anthropic's own announcement was updated on May 1, 2026 to reflect that change.[^1] And because the Blender integration is built on the open MCP protocol rather than as a Claude-exclusive plugin, it works with any other LLM that speaks MCP — a deliberate signal that Anthropic is prioritising ecosystem compatibility over lock-in.[^1]\\n\\n## Claude Design: The Other Product That Launched the Same Day\\n\\nLess covered, but bundled into the same April 28 announcement, is **Claude Design** — a new product from Anthropic Labs aimed at exploring ideas for software experiences. Claude Design lets users visualise options, iterate on them based on feedback, and **export the results to other tools, starting with Canva.**[^1]\\n\\nClaude Design is not a connector — it is a first-party Anthropic surface, in the same family as the Claude Code CLI. Its launch alongside the nine creative connectors makes the broader strategy clearer: Anthropic is building both an *orchestrator* over creative software (the connectors) and a *destination* for early-stage creative ideation (Claude Design), with Canva as the first export target on the destination side. That is a different bet from purely \\\"be the agent that runs Photoshop.\\\"\\n\\n## How the Free vs. Paid Tiers Actually Work\\n\\nThis is the part most coverage gets slightly wrong, because there are **two stacked subscriptions** in play — your Claude plan and your Adobe plan — and they interact in a non-obvious way.[^4][^9][^10]\\n\\n| What you have | What you get from the Adobe connector |\\n|---|---|\\n| Free Claude plan, no Adobe account (\\\"guest mode\\\") | About 40 free tools and two pre-built skills (**Retouch Portraits**, **Batch Edit Photos**) directly in chat |\\n| Free Claude plan + free Adobe ID | All six published skills, higher usage limits, work that persists across sessions |\\n| Free Claude plan + paid Creative Cloud | Same as above plus Creative Cloud storage and access to your existing assets |\\n| Paid Claude plan (Pro / Max / Team / Enterprise) + any Adobe state | Same connector behaviour as above; the Claude plan unlocks plugins generally and lifts Claude's own usage limits |\\n\\nA few things follow from that structure:\\n\\n- **The connector is genuinely usable for free.** You do not need a Creative Cloud subscription to invoke ~40 of the connector's tools and run two end-to-end skills. The free tier is more useful than the typical \\\"demo mode\\\" framing suggests.\\n- **An Adobe ID — even a free one — unlocks more.** Six skills, higher limits, persistent work. This is Adobe's hook to get Claude users into its identity stack.\\n- **A paid Creative Cloud account isn't strictly required to use the connector**, but it is required to read or write the assets in your Creative Cloud library and to use any feature that calls a paid Adobe service (e.g., generating high-resolution Firefly outputs at scale).\\n- **A paid Claude plan isn't required for connectors specifically**, but is required for Claude Plugins generally (Pro, Max, Team, or Enterprise) — and the Adobe connector itself is invoked the same way as any other directory connector.\\n\\nThe friction graph for a brand-new user: **install in 30 seconds on a free Claude account → get ~40 free Adobe tools immediately**. That is dramatically less friction than installing Photoshop on a desktop.\\n\\n## How Each Specialised Connector Differs\\n\\nThe connectors are not all identical wrappers around a backend. Three different patterns showed up in the launch documentation:[^1][^5][^8]\\n\\n- **Tool wrappers** — Adobe for creativity, Affinity by Canva, Resolume Arena, Resolume Wire. Each tool the host app exposes becomes an MCP tool Claude can call. Claude does the orchestration; the host app does the work.\\n- **API bridges** — Blender's connector exposes Blender's Python API to Claude as a natural-language layer. Claude can write and run Python in your Blender session, which is much more open-ended than a fixed tool list.\\n- **Documentation-grounded chat** — Ableton Live's connector grounds Claude's answers in official Live and Push documentation rather than letting Claude actually drive the DAW. Useful for \\\"how do I sidechain compress in Live?\\\" not for \\\"produce me a track.\\\"\\n\\nThe split matters because it tells you what each tool's parent company was willing to expose. Blender (open source, owned by the Blender Foundation) gave Claude a Python API — the maximum surface. Adobe (publicly traded, with a large licensed-content liability) gave Claude a curated set of 50+ tools and a permission gate. Ableton (privately held, smaller engineering team) shipped a documentation grounder. The technical surface is partly a strategy signal.\\n\\n## Adobe + Claude vs. Adobe Firefly AI Assistant\\n\\nAdobe's own Firefly AI Assistant entered public beta on **April 27, 2026** — exactly one day before the Claude connector launched.[^7] The two products solve overlapping problems:\\n\\n| Capability | Firefly AI Assistant | Adobe for creativity (Claude) |\\n|---|---|---|\\n| Where you live | Adobe's Firefly app and Creative Cloud surfaces | Claude (web, desktop, mobile, Cowork) |\\n| Underlying agent | Adobe's first-party \\\"creative agent\\\" | Anthropic's Claude (any model the user has access to) |\\n| Integration depth | Native — built by Adobe | MCP connector — vended by Adobe, executed by Claude |\\n| Available outside Adobe stack | No | Yes — Claude can also call your other 50+ directory connectors in the same chat |\\n| Account needed | Adobe account required | Adobe account optional (~40 free tools without one) |\\n| Public beta / GA | Public beta, April 27, 2026 | Live globally, April 28, 2026 |\\n\\nIf you live inside Creative Cloud all day, Firefly AI Assistant is the more obvious entry point — it shares Adobe's UI conventions and your asset library is already there. If you live in Claude or you need Adobe to be one tool in a longer chain (e.g., pull a transcript from Granola, summarise it, generate a thumbnail in Firefly, post it through your Slack connector), the Claude-side connector is structurally better. The two products are not direct competitors so much as the same underlying capability fronted by two different agents.\\n\\nThe interesting framing: Adobe shipped both. The same week they launched their own creative agent, they also gave Anthropic the keys. That signals Adobe sees agentic AI as the new application surface and wants to be present on every meaningful agent — including the ones it does not own.\\n\\n## What This Says About Anthropic's Strategy\\n\\nAnthropic's framing at launch was deliberate. The Anthropic page is titled *Claude for Creative Work*, and the lede is a quote that explicitly disclaims replacement: \\\"Claude can't replace taste or imagination, but it can open up new ways of working.\\\"[^1][^11]\\n\\nThe strategic move under the marketing language is more pointed. Three things are happening at once:\\n\\n1. **MCP is becoming the application layer.** Nine partner connectors ship simultaneously, all using the same protocol. That makes \\\"MCP-native\\\" a real procurement category for Adobe, Autodesk, and Ableton — not a research project.\\n2. **Connectors compose.** The same Claude conversation that runs Photoshop can also call your Slack, Notion, Gmail, and Linear connectors — and even task-routing agents like [Claude Managed Agents](/claude-managed-agents-deploy-ai-agents-faster). Adobe's own Firefly AI Assistant is locked inside Adobe; Claude's Adobe connector is composable with the rest of the user's working stack.\\n3. **The educational beachhead is real.** Putting connectors in front of RISD, Ringling, and Goldsmiths students is how you train a generation of creatives whose default reach is \\\"ask Claude to do it in Photoshop\\\" rather than \\\"open Photoshop.\\\" Anthropic is buying the muscle memory of the next cohort.[^1][^6]\\n\\nThis is not a feature drop. It is Anthropic positioning Claude as the orchestration layer over the creative software industry, with Adobe — historically the most defensive incumbent in the category — willingly contributing the most strategically valuable surface area.\\n\\n## What It Means for Image-Generation Incumbents\\n\\nThe Claude + Adobe play sits oddly on top of the consumer image-generation market. OpenAI's GPT Image 2 (now [available in Adobe Firefly](https://news.adobe.com/news/2026/04/adobe-new-creative-agent) alongside Google's Nano Banana 2, Veo 3.1, Runway's Gen-4.5, and several others), Midjourney, and Stability all live in a different shape: they generate pixels from prompts.[^7]\\n\\nThe Adobe-for-Claude connector does not replace those models. It replaces the **manual labour** of running them inside Adobe's editors:\\n\\n- The connector reads a layered Photoshop document and asks Firefly (or whatever is configured) to fill in a missing element.\\n- The connector applies a Lightroom preset to 200 photos in batch via natural language instead of clicking.\\n- The connector pulls a stock image from Adobe Stock, places it in an InDesign layout at the right size, and exports a PDF.\\n\\nThese are workflows where the value-add is **knowing which tool to use at which step**, not which generative model produces the prettiest image. That is a different ceiling. Generative model leaderboards plateau quickly; orchestration leaderboards depend on integration depth, which is exactly what 50+ Adobe tools through MCP delivers.\\n\\n## FAQ\\n\\n**Q: Do I need a paid Adobe Creative Cloud account to use the connector?**\\nA: No. Guest mode gives you about 40 free tools and two skills (Retouch Portraits, Batch Edit Photos) without any Adobe account. Signing in with a free Adobe ID unlocks all six skills and higher limits. A paid Creative Cloud subscription adds storage and access to your existing assets.[^4][^9]\\n\\n**Q: Do I need a paid Claude plan?**\\nA: Not for the connector itself — directory connectors work on the free Claude plan. A paid plan (Pro, Max, Team, Enterprise) is required for Claude Plugins generally and for higher Claude usage limits.[^10]\\n\\n**Q: How does this differ from Adobe's own Firefly AI Assistant?**\\nA: Firefly AI Assistant is Adobe's first-party creative agent, launched in public beta on April 27, 2026, and it lives inside Adobe's surfaces. The Adobe for creativity connector is the same kind of orchestration surface but executed by Claude on Anthropic's side, which means it composes with all your other Claude connectors.[^7]\\n\\n**Q: Is this built on MCP?**\\nA: Yes. Adobe for creativity is implemented as a Model Context Protocol connector that Claude can install from its Connectors directory.[^4][^9]\\n\\n**Q: What other creative tools shipped Claude connectors the same day?**\\nA: Eight more, for a total of nine: Adobe Creative Cloud, Blender, Autodesk Fusion, Ableton Live, Splice, SketchUp, Affinity by Canva, Resolume Arena, and Resolume Wire.[^1][^5][^8]\\n\\n**Q: Can the connector use my existing Photoshop documents and Creative Cloud library?**\\nA: Yes, but only if you sign in with an Adobe account that has access to those assets. Without an Adobe account you are working inside a guest sandbox.[^4][^9]\\n\\n**Q: What's Anthropic's educational angle here?**\\nA: Three programs at launch: Art and Computation at RISD, Fundamentals of AI for Creatives at Ringling, and the MA/MFA Computational Arts program at Goldsmiths. Students and faculty get access to Claude and the new connectors and feed back into product direction.[^1][^6]\\n\\n## Bottom Line\\n\\nThe Adobe for creativity connector for Claude does not generate prettier images than the existing image-gen models. What it does is much more strategically loaded: it puts the entire Adobe Creative Cloud tool surface — 50+ pro-grade operations across eight applications — behind a single Claude prompt, on the same protocol that runs your Slack, Notion, and Linear connectors. The other eight connectors that shipped the same day do the same for Blender, Ableton, Autodesk Fusion, Splice, SketchUp, Affinity, and Resolume.\\n\\nFor working creatives, the most useful tier is the most surprising: a free Claude account plus a free Adobe ID gets you all six skills and persistent work, with no Creative Cloud subscription required. For Adobe, the bet is that being present on every meaningful agent — including the ones it does not own — is more valuable than locking customers into Firefly AI Assistant. For Anthropic, this is the clearest statement yet that Claude is meant to be the orchestration layer over the working software stack, not a destination of its own.\\n\\nThe most consequential line in the whole launch is not in any spec sheet. It is the educational programs at RISD, Ringling, and Goldsmiths. The students learning to ship creative work in 2026 will reach for \\\"ask Claude to do it\\\" as a first instinct. That is a long bet, but it is the kind of bet that has actually moved the centre of gravity of software in past decades — and in this round, it lands with Adobe quietly opening the door.\\n\\n---\\n\\n[^1]: [Claude for Creative Work — Anthropic (April 28, 2026)](https://www.anthropic.com/news/claude-for-creative-work)\\n\\n[^2]: [Adobe for creativity: a new way to create with Adobe, now in Claude — Adobe Blog (April 28, 2026)](https://blog.adobe.com/en/publish/2026/04/28/adobe-for-creativity-connector)\\n\\n[^3]: [Anthropic releases 9 Claude connectors for creative tools, including Blender and Adobe — 9to5Mac](https://9to5mac.com/2026/04/28/anthropic-releases-9-new-claude-connectors-for-creative-tools-including-blender-and-adobe/)\\n\\n[^4]: [Adobe for Creativity available in Claude — Adobe Developer documentation](https://developer.adobe.com/adobe-for-creativity/)\\n\\n[^5]: [Claude Connectors for Creative Tools: All 9 Explained (2026) — Build Fast With AI](https://www.buildfastwithai.com/blogs/claude-connectors-creative-tools-2026)\\n\\n[^6]: [Anthropic unveils \\\"Claude for Creative Work,\\\" expanding AI into professional creative tools — Neowin](https://www.neowin.net/news/anthropic-unveils-claude-for-creative-work-expanding-ai-into-professional-creative-tools/)\\n\\n[^7]: [Firefly AI Assistant now available in public beta — Adobe Blog (April 27, 2026)](https://blog.adobe.com/en/publish/2026/04/27/firefly-ai-assistant-public-beta)\\n\\n[^8]: [Anthropic Claude Now Connects With Affinity, Adobe, and Other Creator Solutions — Thurrott.com](https://www.thurrott.com/a-i/anthropic/335498/anthropic-claude-now-connects-with-affinity-adobe-and-other-creator-solutions)\\n\\n[^9]: [Adobe for Creativity — Getting started — Adobe Developer documentation](https://developer.adobe.com/adobe-for-creativity/getting-started/)\\n\\n[^10]: [Use connectors to extend Claude's capabilities — Claude Help Center](https://support.claude.com/en/articles/11176164-use-connectors-to-extend-claude-s-capabilities)\\n\\n[^11]: ['Claude can't replace taste or imagination, but it can open up new ways of working': Anthropic signs up Adobe, Blender and more — TechRadar](https://www.techradar.com/pro/claude-cant-replace-taste-or-imagination-but-it-can-open-up-new-ways-of-working-anthropic-signs-up-adobe-blender-and-more-to-push-claude-into-creative-work)\\n\"])</script><script>self.__next_f.push([1,\"26:T3c03,\"])</script><script>self.__next_f.push([1,\"\\n## TL;DR\\n\\nOn April 8, 2026, Anthropic launched **Claude Managed Agents** in public beta — a hosted platform that handles sandboxing, state management, tool execution, and error recovery so developers can ship autonomous AI agents in days instead of months. Pricing follows standard Claude API token rates plus **$0.08 per active session-hour**. Early adopters include Notion, Rakuten, Asana, Sentry, and Vibecode, with Allianz deploying custom agents across insurance operations. The architecture separates sessions, harnesses, and sandboxes into independent components — a design Anthropic says cut time-to-first-token by roughly 60% at P50.[^1][^2]\\n\\n---\\n\\n## What You'll Learn\\n\\n- What Claude Managed Agents is and the problem it solves\\n- How the session–harness–sandbox architecture works under the hood\\n- Pricing breakdown and what \\\"active session-hour\\\" means\\n- Which companies are already using it and for what\\n- How Managed Agents compares to OpenAI Agents SDK, Google ADK, and open-source frameworks\\n- What features are still in research preview and when to expect them\\n\\n---\\n\\n## The Problem: Agent Infrastructure Is Expensive to Build\\n\\nBuilding a production AI agent requires more than a good model. Developers need secure sandboxing, credential management, long-running session persistence, error recovery, tool orchestration, and tracing — infrastructure that typically takes months to build and maintain.[^1]\\n\\nIndustry analysis suggests that enterprises consistently underestimate the infrastructure investment required for production agent deployments — often by 40–60% relative to the agent development cost itself. Observability, identity management, and integration layers consume more resources than the agent implementation.[^3]\\n\\nClaude Managed Agents addresses this gap directly: it is a hosted service in the Claude Platform that runs long-horizon agents on your behalf through a small set of APIs.[^1]\\n\\n---\\n\\n## How Managed Agents Works\\n\\n### Core Concepts\\n\\nThe platform is built around four primitives:[^4]\\n\\n**Agent** — the model (currently Claude models only), system prompt, tools, MCP servers, and skills that define what the agent can do.\\n\\n**Environment** — a configured container template specifying pre-installed packages (Python, Node.js, Go, and others), network access rules, and mounted files.\\n\\n**Session** — a running agent instance performing a specific task within an environment, generating outputs that persist even through disconnections.\\n\\n**Events** — messages exchanged between your application and the agent, including user turns, tool results, and status updates. Events stream back via server-sent events (SSE).[^4]\\n\\n### The Brain-and-Hands Architecture\\n\\nUnder the hood, Anthropic's engineering team decoupled the agent into three independent components inspired by operating system design — what they call \\\"virtualizing the components of an agent.\\\"[^2]\\n\\n**Session (the state)** stores an append-only event log durably, independent of the harness or sandbox. If the harness crashes, no work is lost because the session persists outside it. Developers can query the event log with positional slices — picking up from the last read point, rewinding to see the lead-up to a decision, or re-reading context before taking action.[^2]\\n\\n**Harness (the brain)** is a stateless orchestration layer. It calls Claude, routes tool results, and manages context transformations. Because it is stateless, it can be replaced instantly: a crash is caught as a tool-call error, a new harness wakes with `wake(sessionId)`, and execution resumes from the last event.[^2]\\n\\n**Sandbox (the hands)** is the execution environment where code runs, files are edited, and tools are invoked. Sandboxes are provisioned on demand via a `provision({resources})` call and are treated as disposable — replaced rather than repaired. Each tool is exposed through a uniform `execute(name, input) → string` interface, whether it is a container, an MCP server, or a custom integration.[^2]\\n\\nThis separation matters for performance. In Anthropic's original coupled design, the session, harness, and sandbox lived inside a single container. When it failed, the session was lost. After decoupling, P50 time-to-first-token dropped roughly 60%, and P95 dropped over 90% — because inference no longer waits for container startup.[^2]\\n\\n### Security Boundaries\\n\\nCredentials never reach the code-execution sandbox. Git tokens are injected during initialization but remain unavailable to generated code. OAuth tokens sit in a secure vault, accessed only through an MCP proxy that maps the session token to the right credentials. Claude never sees raw authentication material.[^2]\\n\\n---\\n\\n## Built-In Tools and MCP Support\\n\\nManaged Agents gives Claude access to several built-in tool categories:[^4]\\n\\n**Bash** — shell commands run inside the container. **File operations** — read, write, edit, glob, and grep across the container's file system. **Web search and fetch** — search the web and retrieve content from URLs. **MCP servers** — connect to any external tool provider using the Model Context Protocol.\\n\\nMCP integration is handled through a dedicated proxy. The proxy fetches authentication from the vault, calls the MCP server, and returns results — all without the agent or sandbox ever seeing raw credentials.[^2]\\n\\nThis tool-use-first design means any custom tool, any MCP server, and any Anthropic-provided tool looks identical to the harness: a name and input go in, a string comes back.[^2]\\n\\n---\\n\\n## Pricing\\n\\nClaude Managed Agents follows a consumption model:[^1]\\n\\nStandard Claude Platform token rates apply (the same rates you pay for the Messages API). On top of that, there is a **$0.08 per session-hour** charge for active runtime. \\\"Active\\\" means the session is processing work — idle sessions do not accrue charges. When agents perform web searches through the platform, Anthropic charges **$10 per 1,000 searches** on top of model usage costs.[^5]\\n\\nFor context: an agent running Claude Sonnet 4.6 for one hour of active work would cost roughly $0.08 in session fees plus whatever token costs the task generates. This compares to the alternative of provisioning, securing, and maintaining your own container infrastructure — which Anthropic argues costs orders of magnitude more when accounting for engineering time.[^1]\\n\\n---\\n\\n## Who Is Already Using It\\n\\nSeveral high-profile companies are building on Managed Agents:[^1]\\n\\n**Notion** launched Custom Agents publicly in February 2026 and is now integrating Claude Managed Agents into the platform (currently in private alpha) for code shipping and content creation workflows. **Rakuten** deploys enterprise agents across product, sales, marketing, and finance teams via Slack and Microsoft Teams. **Asana** has integrated AI Teammates — collaborative agents that work within Asana projects. **Sentry** built a debugging agent that pairs with patch-writing and PR-opening capabilities. **Vibecode** reports that Managed Agents enables customers to deploy applications ten times faster.[^1]\\n\\nBeyond these, **Allianz** — the global insurance conglomerate — signed a partnership with Anthropic in January 2026 that includes building custom AI agents for multistep workflows with a human in the loop, deploying Claude Code for all technical teams, and implementing an AI logging system for regulatory transparency.[^6]\\n\\n---\\n\\n## Research Preview Features\\n\\nTwo capabilities launched in research preview, requiring a separate access request:[^1]\\n\\n**Multi-agent coordination** — an orchestrator agent can spawn and coordinate multiple sub-agents in parallel, with Managed Agents handling communication and state sharing between them.\\n\\n**Outcomes (self-evaluation)** — developers define success criteria for a task, and Claude self-evaluates and iterates until it meets them, adding a goal-directed quality-control loop to the agent pipeline. In Anthropic's internal testing on structured file generation, Outcomes improved task success by up to 10 points over a standard prompting loop, with the largest gains on the hardest problems.[^1]\\n\\nAnthropic has not announced a timeline for graduating these features to general availability. Persistent memory tooling was not part of the April 8 launch — Anthropic added it as a separate public-beta feature on April 23, 2026, roughly two weeks later.[^9]\\n\\n---\\n\\n## How It Compares to Alternatives\\n\\nThe [agentic AI landscape](/mastering-agent-orchestration-patterns-from-theory-to-production) in 2026 offers several paths to building production agents. Here is how they differ:[^7][^8]\\n\\n**Claude Managed Agents** is a fully hosted service. Developers define an agent, point it at an environment, and start sessions. The platform handles orchestration, sandboxing, and recovery. The trade-off is model lock-in: only Claude models run in the harness. If you later want to switch models, you rebuild the orchestration layer.[^7]\\n\\n**OpenAI Agents SDK** takes an open-source, code-first approach. Its core abstraction is the handoff — agents transfer control to each other explicitly, carrying conversation context through the transition. A working multi-agent system can be defined in under twenty lines of Python. The SDK supports non-OpenAI models through custom providers, though it is optimized for OpenAI's own models.[^8]\\n\\n**Google Agent Development Kit (ADK)** provides a hierarchical agent tree with deep integration into Google Cloud (Vertex AI Agent Engine) and Google's search infrastructure. Its differentiator is grounding — agents can search Google in real time and base responses on cited information, which addresses hallucination at the infrastructure level.[^8]\\n\\n**LangGraph** leads on production maturity among open-source frameworks, with built-in checkpointing, time-travel debugging, and LangSmith integration for observability. It supports any model but requires learning its graph abstraction — expect one to two weeks before a team is productive.[^7]\\n\\n**CrewAI** offers the lowest barrier to entry with a role-based DSL and processes over 12 million executions per day as of early 2026. It has raised $18 million in funding led by Insight Partners and reports 60% Fortune 500 adoption.[^7]\\n\\nThe key distinction is hosted versus self-managed. Managed Agents eliminates infrastructure work but binds you to Claude. The SDKs and frameworks give you flexibility but require you to build and maintain the operational layer yourself.\\n\\n---\\n\\n## What This Means for Developers\\n\\nClaude Managed Agents represents Anthropic's bet that most teams building [AI agents](/ai-agents-the-next-frontier-in-software-development) do not want to be in the infrastructure business. The platform absorbs the operational complexity — sandboxing, permissions, state management, error recovery — and exposes a clean API surface.\\n\\nFor teams already building on [Claude Code](/mastering-claude-code-a-complete-hands-on-tutorial-guide) or the Claude Agent SDK, Managed Agents provides a natural upgrade path to production deployment. For teams evaluating the [MCP ecosystem](/mcp-servers-explained-claudes-new-ai-backbone-for-real-automation), the platform's first-class MCP support means existing MCP servers plug in without modification.\\n\\nThe $0.08-per-session-hour pricing is aggressive enough that many teams will find it cheaper than maintaining their own agent infrastructure, especially when factoring in engineering time for security, recovery, and scaling.\\n\\nThe open question is whether model lock-in matters. In a landscape where the performance gap between frontier models narrows with each release, betting your agent infrastructure on a single provider is a real trade-off. Anthropic is clearly betting that Claude's capabilities — extended thinking, computer use, and deep MCP integration — are compelling enough to justify it.[^8]\\n\\n---\\n\\n## Getting Started\\n\\nClaude Managed Agents is available today in public beta. To start building, you need a Claude API key and the `managed-agents-2026-04-01` beta header on all requests (the SDK sets this automatically). The service is enabled by default for all API accounts — no waitlist required for the core platform.[^4]\\n\\nMulti-agent coordination, memory, and outcomes (self-evaluation) require a separate access request through Anthropic's form.[^4]\\n\\n---\\n\\n## Frequently Asked Questions\\n\\n**What models does Claude Managed Agents support?**\\nCurrently, only Claude models run in the Managed Agents harness. This includes Claude Sonnet 4.6, Claude Opus 4.6, and Claude Haiku 4.5.[^4]\\n\\n**Can I use my existing MCP servers?**\\nYes. MCP servers connect through the platform's proxy layer, which handles authentication via a secure vault. Existing MCP servers work without modification.[^2][^4]\\n\\n**What happens if a session crashes?**\\nSessions persist independently of the harness and sandbox. If either component fails, a new instance boots and resumes from the last event in the session log. No work is lost.[^2]\\n\\n**Is there a free tier?**\\nNo dedicated free tier has been announced. Standard Claude API pricing applies, plus the $0.08 per active session-hour. Anthropic provides usage credits for new API accounts, which can be used for Managed Agents.[^4]\\n\\n**How does this relate to Claude Code?**\\nClaude Code is a CLI tool for agentic coding on your local machine. Managed Agents is a cloud-hosted platform for deploying agents at scale. They share the same underlying model capabilities but serve different use cases — local development versus production deployment.[^1]\\n\\n---\\n\\n## Bottom Line\\n\\nClaude Managed Agents is Anthropic's infrastructure play for the agentic AI era. By handling sandboxing, state management, and tool execution as a managed service, it removes the primary barrier that keeps most agent prototypes from reaching production. The brain-and-hands architecture is technically sound, the early customer list is strong, and the $0.08-per-session-hour pricing undercuts the true cost of self-hosted alternatives. The trade-off is model lock-in — a bet that Claude's capabilities justify the commitment. For teams already in the Anthropic ecosystem, this is a straightforward upgrade. For everyone else, it is a compelling argument to evaluate one.\\n\\n---\\n\\n[^1]: Anthropic, \\\"Claude Managed Agents: get to production 10x faster,\\\" claude.com/blog/claude-managed-agents, April 8, 2026.\\n[^2]: Anthropic Engineering, \\\"Scaling Managed Agents: Decoupling the brain from the hands,\\\" anthropic.com/engineering/managed-agents, April 2026.\\n[^3]: Industry analysis from LangChain's \\\"State of Agent Engineering\\\" survey and related enterprise infrastructure reports, 2026.\\n[^4]: Anthropic, \\\"Claude Managed Agents overview,\\\" platform.claude.com/docs/en/managed-agents/overview, April 2026.\\n[^5]: Anthropic pricing documentation, platform.claude.com/docs/en/about-claude/pricing, accessed April 2026.\\n[^6]: Allianz, \\\"Allianz and Anthropic forge global partnership to advance responsible AI in insurance,\\\" allianz.com, January 9, 2026.\\n[^7]: Multiple sources including Composio, Gurusup, and MorphLLM framework comparisons, April 2026.\\n[^8]: Composio, \\\"Claude Agents SDK vs. OpenAI Agents SDK vs. Google ADK,\\\" composio.dev, April 2026.\\n[^9]: Anthropic, \\\"Built-in memory for Claude Managed Agents,\\\" claude.com/blog/claude-managed-agents-memory, April 23, 2026.\\n\"])</script><script>self.__next_f.push([1,\"27:T3d8c,\"])</script><script>self.__next_f.push([1,\"\\n# Agentic Testing in 2026: What Slack's 200-Run Data Shows\\n\\n**In one line:** Agentic testing points an AI agent at a goal — \\\"reply in a thread and verify it appears\\\" — and lets it drive the UI to get there, instead of replaying a fixed script; Slack's engineering team ran more than 200 such tests and published what they actually cost and how often they fail.[^1]\\n\\n**TL;DR:** In a June 11, 2026 engineering write-up that drew broad developer-press pickup through July, Slack reported running more than 200 agent-driven end-to-end (E2E) test workflows across three execution models and two user flows.[^1][^4] The headline is not \\\"agents replace QA.\\\" It is a set of hard tradeoffs: agent-driven runs cost roughly $15-30 each and take 3-11 minutes, reliability swings from near-perfect to a ~48% failure rate depending on how the agent is wired up, and the biggest cost driver is not the model's reasoning but the conversation context re-sent on every turn.[^1] Slack's conclusion is measured — agentic testing earns a new spot at the *top* of the testing pyramid for exploration and debugging, not a replacement for the deterministic tests that guard CI.[^1] A separate Stripe benchmark from March points at the same wall from a different angle: agents generate and execute well, but validating their own work is where they still break.[^2]\\n\\n## What you'll learn\\n\\n- What agentic testing is, and how \\\"verify a goal\\\" differs from \\\"replay a journey\\\"\\n- How Slack structured its 200+-run experiment, and which models and tools it used\\n- What the reliability numbers show across Playwright MCP, Playwright CLI, and generated tests\\n- Why an agent-driven test run costs $15-30, and where that money actually goes\\n- The adaptability tradeoff: only about one run in five takes the same path\\n- Where agentic testing fits in the testing pyramid — and where it does not\\n- The bigger 2026 pattern: agents that build well but validate poorly\\n- What to do if you are adding agents to your own test stack\\n\\n## What agentic testing actually is\\n\\nA traditional end-to-end test encodes a journey: click this, type that, assert the result. It is deterministic and cheap, and it breaks the moment the UI shifts underneath it — a renamed button or a reordered menu fails the test even when nothing functionally regressed. That brittleness is the maintenance tax every large web app pays.\\n\\nAgentic testing swaps the journey for a goal. You describe an outcome in natural language — \\\"send a thread message,\\\" \\\"run a search and confirm the result appears in All Threads\\\" — and an AI agent observes the interface, decides what to click, and checks whether the goal state was reached. Slack's own one-line summary is the cleanest definition going: **\\\"Tests enforce journeys. Agents verify goals.\\\"**[^1] The vendor QA market has spent 2026 selling this idea hard — BrowserStack, Mabl, UiPath, and a dozen others publish near-identical \\\"autonomous, self-healing, replaces manual QA\\\" pitches — but almost none of them show what it costs or how often it works. Slack's contribution is that it ran the experiment and published the numbers.\\n\\n## Inside Slack's experiment\\n\\nSlack's DevXP team ran more than 200 agentic E2E workflows — 20 runs each across five configurations and two user flows — in test workspaces using non-production data.[^1] It compared three execution models:\\n\\n- **Agent + Playwright MCP.** The agent drives the browser through Microsoft's open-source [Playwright MCP](https://github.com/microsoft/playwright-mcp) server, which exposes browser actions as tools and returns accessibility-tree snapshots as structured state.[^1][^3]\\n- **Agent + Playwright CLI.** The agent shells out to Playwright CLI commands one step at a time, deciding the next action from the updated UI.[^1]\\n- **Generated Playwright tests.** The agent writes deterministic Playwright code from a natural-language description, runs it, and refines it until it passes — after which it executes like any normal scripted test.[^1]\\n\\nThe agent models were Claude Sonnet 4.5 for the MCP and CLI runs and Claude Opus 4.6 for generating the deterministic tests, all executed through non-interactive Claude Code (`claude -p`), with a token-usage side experiment that also included Claude Haiku 4.5.[^1] The two flows were a simple \\\"Thread Reply\\\" (roughly 15-20 steps) and a medium-complexity \\\"Search Discovery\\\" (roughly 25-30 steps), each fed to the agent as both free-form natural language and structured YAML.[^1] Those are the exact model and tool choices Slack used in mid-2026; the point is the shape of the results, which is unlikely to change with a newer model.\\n\\n## What the reliability data shows\\n\\nThe reliability story is really a story about *how* the agent is wired up, not which model sits behind it. Slack's summary numbers:\\n\\n| Approach | Failure (simple flow) | Failure (medium flow) | Avg runtime |\\n| --- | --- | --- | --- |\\n| Agent + Playwright MCP | 0% | ~12% | ~5-8 min |\\n| Agent + Playwright CLI | ~12% | ~20% | ~9-11 min |\\n| Generated Playwright tests | ~8% | ~48% | ~3 min |\\n\\nTwo patterns stand out. First, the reliability gap *widens* with complexity, and the MCP-based agent stays most stable as flows get harder — near-zero failures on the simple flow and within 0-12% on the complex one.[^1] Slack attributes this to state handling: the MCP keeps a live, stable view of the app and appears to reuse successful interactions from earlier in the same run, while the CLI rebuilds state from snapshots at each step, letting small timing and interpretation errors accumulate.[^1] Most CLI failures, notably, came from authentication, navigation timing, and session instability — the execution layer — rather than the model reasoning wrong.[^1]\\n\\nSecond, generated tests are a trap on complex flows. They looked fine on the simple flow (~8% failure) but failed roughly 48% of the time on the medium one, typically after progressing through 70-80% of the flow before breaking on a final interaction or assertion.[^1] Generated from loosely specified natural language and reusing existing page-object abstractions, they stumbled on exactly the precise element targeting that a longer flow demands. The lesson is not that generation is bad — it is that \\\"have an agent write a script once\\\" and \\\"have an agent drive the browser live every time\\\" are different tools with different failure surfaces.\\n\\n## Why an agent-driven run costs $15-30\\n\\nThe number that makes engineers wince is cost. Slack pegs agent-driven runs at roughly **$15-30 per execution**, against pennies for a traditional scripted test.[^1] The instinctive explanation — \\\"big model, so it's expensive\\\" — is wrong, and Slack's teardown of where the money goes is the most useful part of the write-up.\\n\\nMeasuring the same Search Discovery flow, token usage ran from about 3.5M tokens (MCP with Sonnet 4.5) to about 7M (generated tests with Opus 4.6), with the CLI approach around 6M and, interestingly, Haiku burning *more* tokens (~5.7M) than the larger models on MCP.[^1] How the agent was executed mattered more than which model powered it. The reason is turn count: the CLI averaged about 85 turns to complete the flow, versus roughly 40-60 for MCP, because every browser interaction was split across separate action, wait, snapshot, read, and lookup commands, while MCP folded interaction and state return into one round trip.[^1]\\n\\nAnd each turn is expensive because the underlying API is stateless. As Slack explains it, Claude Code re-sends the full system prompt plus the entire conversation history on every turn, so cost is driven by how fast context accumulates and how many turns the run takes — not by the model's output, which is negligible.[^1] The bulk of the payload is browser accessibility-tree snapshots piling up in the context window turn after turn; the majority of the spend, in Slack's analysis, is simply retransmitting content the model has already seen. If you have followed the [token cost of a single agent task](/ai-agent-token-cost-per-task), this is the same accounting, just measured against a browser instead of a chatbot: the levers Slack names to bring it down — prompt caching, context compaction, and cutting snapshot frequency — are all about shrinking what gets re-sent, not about picking a cheaper model. It is also a reminder that the [stateless request model behind agent tooling protocols like MCP](/mcp-stateless-protocol-enterprise-authorization) has a direct line to your bill.\\n\\n## The adaptability tradeoff\\n\\nHere is the property that makes agentic testing genuinely different, and genuinely awkward: it is non-deterministic by design. Across Slack's runs, only about 20% followed the exact same sequence of actions; in most runs the agent found a different valid path to the same goal — opening menus in a different order, selecting different elements, using alternate navigation.[^1] Slack measured this by comparing normalized \\\"action signatures,\\\" collapsing away waits and equivalent tool variants so only meaningful differences counted.[^1]\\n\\nThat flexibility is the whole point — it is why an agent survives a UI change that would break a scripted test. But it is also why you cannot drop agentic tests into a CI gate the way you drop in a unit test. A check that takes a different route every run, costs $15-30, and fails ~12% of the time on a medium flow is not a regression gate. It is something else.\\n\\n## Where agentic testing fits\\n\\nSlack's answer is refreshingly un-hyped: agentic testing is a new *fourth layer* on top of the classic testing pyramid — unit, integration, E2E, and now agentic — not a replacement for anything below it.[^1] Deterministic tests, whether hand-written or agent-generated, stay the fast, cheap, repeatable foundation of CI. The agentic layer is where you send an agent to do the things scripts are bad at: exploring complex or unfamiliar UI behavior, debugging flaky workflows, and reproducing production bugs whose repro steps you cannot fully specify in advance.[^1] Slack is explicit that, at current prices, agent-driven testing suits \\\"targeted debugging or exploratory testing\\\" far better than \\\"high-frequency CI execution.\\\"[^1]\\n\\nThat framing is the direct rebuttal to the vendor pitch. Agentic testing in 2026 is not autonomous QA that fires your test engineers; it is a power tool for the ambiguous cases, priced accordingly, that complements the deterministic tests you already run.\\n\\n## The bigger 2026 pattern\\n\\nZoom out and Slack's experiment rhymes with the other serious piece of agentic-engineering data this year. In a March 2, 2026 benchmark it later open-sourced, Stripe built 11 production-realistic environments and had agents attempt full Stripe integrations through a goose-based harness and an MCP server.[^2][^5] The models were strong: Claude Opus 4.5 averaged 92% on full-stack API integration tasks and OpenAI's GPT-5.2 averaged 73% on Stripe's harder \\\"gym\\\" problem sets, with the best runs sustaining an average of 63 turns of productive work.[^2] Stripe declined to publish a single aggregate score, and for a telling reason — the failures clustered not in writing code but in *validating* it.[^2]\\n\\nStripe's most instructive failure mode: on SDK-upgrade tasks, some agents fed nonexistent data to an endpoint, saw the expected HTTP 400 error, and concluded the integration worked — \\\"the endpoint is working, it's returning a proper Stripe error\\\" — when in fact they had verified nothing.[^2] Others got a browser checkout into a bad focus state and gave up on a task that a single page refresh would have recovered.[^2] Slack saw the mirror image: agents that could not always recover from a browser glitch, and a reliability/cost profile that gates production use.\\n\\nRead together — and this is the author's synthesis across two independent studies, not a claim either company makes jointly — the 2026 picture is consistent: modern agents generate and execute confidently, but self-verification under a real correctness bar is the wall. That is the same gap showing up elsewhere as agents ship code faster than teams can govern it, a tension we covered in [the AI coding governance gap](/ai-coding-governance-gap), and it is why [tracing and evaluating agent runs](/opentelemetry-claude-agent-tracing-typescript-tutorial) is becoming as important as the agent itself.\\n\\n## What this means if you're adding agents to your test stack\\n\\nA few practical takeaways fall out of the data. Prefer a structured browser tool (an MCP-style server) over shelling out to a CLI if reliability matters — Slack's cleanest results came from the tighter integration, and its worst flakiness came from the execution layer, not the model.[^1] Budget honestly: at $15-30 and several minutes per run, agentic tests belong on high-value, hard-to-script scenarios, not on every pull request. Watch turn count and context growth, not model choice, as your primary cost lever, and reach for prompt caching and context compaction before you reach for a smaller model. And keep your deterministic suite — the point of the agentic layer is to reach the cases that suite cannot, including generating new scripted tests you then run cheaply forever. As with deciding [how many tools an agent can realistically juggle](/how-many-tools-can-an-ai-agent-handle), the win in 2026 comes from wiring the agent up well, not from waiting for a better model.\\n\\n## FAQ\\n\\n**Is agentic testing reliable enough to replace traditional automated tests?** No, and Slack does not claim it is. Its own data shows failure rates from 0% up to ~48% depending on configuration and flow complexity, and it positions agentic testing as a new top-of-pyramid layer that complements — not replaces — deterministic CI tests.[^1]\\n\\n**How much does an agentic test run cost?** In Slack's experiment, roughly $15-30 per agent-driven execution, versus pennies for a traditional scripted test, with runtimes of about 3-11 minutes.[^1]\\n\\n**Why is it so expensive if the model output is small?** Because the underlying API is stateless: every turn re-sends the full system prompt and the entire accumulated conversation history, which for browser agents is dominated by accessibility-tree snapshots. Cost tracks turn count and context growth, not reasoning output.[^1]\\n\\n**What is Playwright MCP?** Microsoft's open-source Model Context Protocol server that exposes browser automation as agent tools and returns structured accessibility-tree snapshots; in Slack's runs it was both the most reliable and the most token-efficient execution model.[^1][^3]\\n\\n*This is an analysis of a sensitive-to-recency topic: model capabilities, tooling, and prices move fast. All figures are dated to their primary sources — Slack's June 11, 2026 study and Stripe's March 2, 2026 benchmark — and should be re-checked against those pages before you quote them.*\\n\\n[^1]: Sergii Gorbachov, \\\"Agentic Testing: Where Agents Fit in the E2E Testing Stack,\\\" Engineering at Slack, June 11, 2026. https://slack.engineering/agentic-testing-where-agents-fit-in-the-e2e-testing-stack/\\n[^2]: Carol Liang and Kevin Ho, \\\"Can AI agents build real Stripe integrations? We built a benchmark to find out,\\\" Stripe Blog, March 2, 2026. https://stripe.com/blog/can-ai-agents-build-real-stripe-integrations\\n[^3]: \\\"Playwright MCP\\\" (Model Context Protocol server for browser automation), Microsoft, GitHub. https://github.com/microsoft/playwright-mcp\\n[^4]: Leela Kumili, \\\"Slack Introduces Agent Driven End-to-End Testing to Improve Resilience in UI Test Automation,\\\" InfoQ, July 2026. https://www.infoq.com/news/2026/07/slack-agentic-e2e-testing-ui/\\n[^5]: Stripe integration benchmark (open-source), stripe/ai, GitHub. https://github.com/stripe/ai/tree/main/benchmarks\\n\"])</script><script>self.__next_f.push([1,\"28:T5134,\"])</script><script>self.__next_f.push([1,\"\\n# Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\\n\\n**In one line:** Pinecone Nexus is a \\\"knowledge engine\\\" for AI agents that compiles an enterprise's scattered data into structured, pre-built artifacts agents query in one step — moving reasoning and token spend out of the per-query retrieval loop that defines RAG and into a one-time curation stage.[^1][^3]\\n\\n**TL;DR:** On July 1, 2026, Pinecone — the vector-database company that, by its own account, \\\"defined RAG as a standard pattern\\\" — moved Pinecone Nexus into public preview, nearly two months after opening early access.[^1][^3] Nexus reframes the problem: rather than letting an agent search, retrieve, and reassemble context on every task, it compiles a company's knowledge into typed artifacts ahead of time and serves them through a declarative query language called KnowQL.[^1][^2] Benchmarks published by Pinecone and by customers evaluating it during early access show large accuracy and token-cost gains over agentic RAG on bounded document corpora.[^2][^3] The framing in the trade press — that \\\"the RAG era is ending\\\" — is louder than the evidence: Nexus targets bounded corpora, none of the numbers have been independently reproduced, and the more defensible reading is that retrieval is bifurcating, not dying.[^5][^6][^7]\\n\\n## What you'll learn\\n\\n- What Pinecone actually announced across May and July 2026, and what \\\"public preview\\\" does and does not mean\\n- What a \\\"knowledge engine\\\" is, and how it differs from RAG and from a vector database\\n- How Nexus is put together — Connectors, Workspaces, Contexts, Manifests, and KnowQL\\n- The specific numbers Pinecone is pointing to, including the ones it leads with, and why the \\\"vendor benchmark\\\" label matters\\n- Whether RAG is actually \\\"dead\\\" — the evenhanded version, with the counterarguments\\n- What this means if you are building agents right now\\n\\n## What Pinecone actually announced\\n\\nNexus arrived on May 4, 2026 in a pair of same-day posts: a company-level launch announcement from Ash Ashutosh and Edo Liberty introducing Nexus and its query language KnowQL, and an engineering deep dive from Jeff Zhu and Siva Ragavan bluntly titled \\\"Better Models Won't Save Your Agent.\\\"[^1][^2] At that point it was early access only, open to a limited set of design partners.[^2] On July 1, 2026, Pinecone opened Nexus to public preview, telling anyone with a business use case they could request access.[^3] Public preview is not general availability: access is still request-gated, and the production deployment path is a separate request.[^3]\\n\\nThe pitch behind the product is a diagnosis, and Pinecone states it aggressively. Frontier models, the company argues, are rarely the limiting factor; the reasoning step is usually fine. What breaks is everything before it. An agent gets a task, searches, retrieves, evaluates, decides it needs more, searches again, and loops — and by the time it can answer, most of the token and latency budget is gone.[^2] Pinecone puts a number on it, claiming that \\\"roughly 85% of an agent's effort is spent on knowledge retrieval,\\\" with task completion rates \\\"stuck at 50–60%,\\\" and it dismisses retrieval-at-inference as \\\"the 'ten blue links' era of agentic retrieval.\\\"[^1] That last line is the one the trade press seized on.[^5]\\n\\nThe discipline Pinecone is invoking has a name: *context engineering*, which it describes as shaping data into knowledge the model can use, instead of asking the agent to reassemble it from raw data at query time.[^2][^8] Nexus is Pinecone's bet on productizing it.\\n\\n## What a \\\"knowledge engine\\\" is\\n\\nIn Pinecone's framing, a knowledge engine \\\"compiles an enterprise's distributed knowledge into a structured layer agents can query directly, shifting token spend out of the per-query retrieval loop and into a one-time curation step.\\\"[^3] The contrast it is drawing is with retrieval-augmented generation. Classic RAG solves a specific problem well: give a language model access to external knowledge at inference time by retrieving relevant document chunks. That worked because early use cases were request-response — a user asks, the system retrieves, the model answers.[^2]\\n\\nAgent workloads break that assumption. A single agent task can touch dozens of documents across years and departments, and standard chunk-and-retrieve either misses facts that are not co-located or burns the budget looping to reassemble them.[^2][^3] A knowledge engine moves that assembly work upstream. Instead of handing the agent chunks and asking it to stitch an answer together, Nexus pre-shapes source data into *artifacts* — typed, governed pieces of information built for a specific task — so the agent reads a mostly-finished answer rather than reconstructing one.[^2]\\n\\nPinecone's own formulation is that Nexus is \\\"a knowledge engine, not a retrieval system,\\\" and the distinction it wants is with inference-time retrieval, not with vector search as such.[^1] It is not retiring its vector index: the company says plainly that \\\"the Pinecone vector database is the foundation; vector primitives and their management remain essential,\\\" and Nexus runs on the retrieval substrate Pinecone has spent years building.[^1][^2] The layer sits above search, aimed at a third kind of knowledge that neither model weights nor vector search captures well — business context, \\\"what a three-year employee knows without searching,\\\" scattered across contracts, wikis, HR docs, meeting notes, support tickets, and financial records.[^3]\\n\\nIs any of this new? Pinecone answers both ways in the same week. The engineering post concedes that \\\"knowledge graphs, entity catalogs, and semantic layers have existed for decades\\\" and that the hard part was never the concept but operationalizing it per domain — while its own section heading insists this is \\\"a new category, not a better pipeline,\\\" and the launch post claims a knowledge engine that moves reasoning from retrieval to curation \\\"did not exist until today.\\\"[^1][^2] The honest read is that the instinct is old and the packaging is new.\\n\\n## Inside Nexus: Manifests, Contexts, and KnowQL\\n\\nIn the public-preview build, the moving parts are organized like this.[^3] **Connectors** handle ingestion; local file upload, Box, and Microsoft OneLake are live, with Google Drive, Slack, GitHub, Notion, Confluence, and S3 described as close behind.[^3][^4] A **Workspace** is the top-level container, one per team or business unit that owns its own data sources and access controls. Inside a Workspace, data is organized into **Contexts** — one per dataset or knowledge domain.[^3]\\n\\nThe most interesting design choice is the **Manifest**. A Manifest is a blueprint that tells Nexus how to turn raw documents into structured knowledge artifacts tuned to a domain, and it is meant to be authored by a subject-matter expert rather than a retrieval engineer.[^3] The patent attorney who knows how patent standards are organized, or the M\\u0026A analyst who knows which document categories to cross-reference, designs the artifact types and relationships before any query runs. The agent then inherits that understanding instead of rediscovering the corpus structure on every call.[^3] This is a real shift in emphasis from May: the launch materials led with an autonomous \\\"context compiler\\\" — a coding agent that iterates on curation and query code against an eval set — whereas the public-preview messaging centers the human-in-the-loop Manifest, with re-curation as the answer to what Pinecone calls knowledge drift.[^1][^2][^3]\\n\\nWork runs as **Tasks** — import, curate, and search — inside isolated sandboxes, and everything is queried through **KnowQL** (Knowledge Query Language), the single interface agents talk to.[^2][^3] The declarative design is the point: like SQL, the agent states what answer it needs, in what shape, and with what constraints, and the engine decides which contexts to search and which artifacts to compose.[^1][^2] Pinecone's two May posts describe its surface slightly differently — the engineering post organizes a query into four categories (intent, filter, provenance, and a control budget), while the launch post advertises six core primitives, adding output shape and confidence.[^1][^2] Either way the ambition is explicit: Pinecone wants KnowQL to be a shared interface rather than a private one, and it has LangChain and Teradata publicly signed up to help advance it.[^1] That ambition has an obvious hurdle, as The New Stack put it: \\\"KnowQL has to clear the standardization bar SQL cleared, and standards do not get declared into existence by a single vendor.\\\"[^5]\\n\\nFor production, Pinecone points to a bring-your-own-cloud deployment where the cluster runs in the customer's own VPC and, the company says, documents never leave the customer's infrastructure. That deployment is request-gated, and as of the May launch Pinecone described BYOC support for Nexus specifically as coming \\\"very soon.\\\"[^1][^3]\\n\\n## The numbers Pinecone is pointing to\\n\\nPinecone leads with headline figures: task completion rates above 90%, \\\"30x faster time-to-completion,\\\" and up to 90% less token spend.[^1] The trade press repeated them, though not uncritically. Reviewing the completion-rate and token-spend claims, The New Stack wrote: \\\"Take this claim with a grain of salt until production teams confirm\\\" — while arguing that Pinecone's structural case \\\"does not need the numbers to hold.\\\"[^5] Everything below is either Pinecone's own benchmark or a customer evaluation conducted during early access. None of it has been independently reproduced.\\n\\nPinecone's named internal benchmark, KRAFTBench, pits Nexus against an agentic-RAG pipeline and a sandboxed coding agent on 493 free-form 10-K filings (about 245MB) from S\\u0026P 500 companies, asking 150 hard financial questions with a 120-second, one-million-token budget each.[^2] Pinecone reports Nexus completing every question at 22.7 seconds average latency and about 6,700 tokens per task, versus 37.9 seconds and roughly 49,000 tokens for agentic RAG, and 84.1 seconds and about 528,000 tokens for the coding agent, which finished only 63% of the questions.[^2] That is roughly 7× fewer tokens than RAG and about 80× fewer than the coding agent. The accuracy column is more sobering than the headline claims suggest: Nexus scores 0.680, against 0.413 for agentic RAG and 0.585 for the coding agent.[^2] Nexus wins the comparison clearly, but 68% on the vendor's own harness is not a solved problem.\\n\\nThe public-preview post adds three customer-facing evaluations, all on small question sets. Q2, a digital-banking infrastructure provider, ran its own benchmark without Pinecone in the loop and reported a 95% F1 score across a 20-question eval set; its chief data scientist, Jesse Barbour, said his team could \\\"easily stand up a vector database and run RAG\\\" over its corpus, and that \\\"the hard part is getting an agent to reliably and efficiently assemble the right knowledge for genuinely difficult questions.\\\"[^3] A second benchmark, which Pinecone says it ran with a legal-research AI company over 30,000 documents of EU case law and legislation, pitted Nexus against agentic RAG and a coding agent across 35 questions: Pinecone reports 100% completion at 87% accuracy for Nexus versus 66% completion at 45% accuracy for RAG and 6% completion at 4% accuracy for the coding agent, with token use roughly 9–15× lower.[^3][^4] A third, run with a data-protection vendor across 598 municipal-meeting documents, reports 90% accuracy against a 65% RAG baseline on a 100-question set, with a one-time curation cost of $2.31 to compile the corpus into twelve artifact types in 34 minutes.[^3]\\n\\nThe direction is consistent across all four: compile once, and the per-query cost collapses. The evidentiary weight is thinner than it first appears. Only the KRAFTBench and legal benchmarks report a full head-to-head against RAG on completion, accuracy, and tokens together; Q2 published no RAG baseline or token comparison beyond its executive's assertion, and the municipal benchmark reports cost per query rather than a token comparison. The corpora are large; the question sets are 20, 35, 100, and 150 items.\\n\\n## Is RAG actually \\\"dead\\\"?\\n\\nHeadlines raced ahead of the product back in May, when Nexus was still early access. VentureBeat framed it as \\\"the RAG era is ending for agentic AI\\\" on the day of the announcement, and The New Stack ran \\\"the company that made RAG mainstream is now betting against it\\\" two days later.[^5][^6] That is a good story, and an incomplete one.\\n\\nStart with scope. Pinecone says Nexus is \\\"built for bounded corpora where agents need to reason across documents,\\\" at its best where a single question touches dozens of files and standard retrieval starts falling apart.[^3] That is a real and common shape — financial filings, case law, support archives, government records — but it is a shape, not the whole space. A knowledge base that changes hourly, an open-ended web search, or a lookup that only ever needs one chunk are not obviously improved by paying an upfront compilation cost. Pinecone scopes Nexus to bounded corpora but does not extend that caution to the cases above; its launch materials illustrate Nexus working over fast-moving operational estates that include Slack, Gong, and Jira (as example data sources rather than shipped connectors), and it launched a marketplace of more than 90 knowledge applications spanning sales, HR, and support.[^1] Exactly where the limits fall is a reading of the evidence, not a line the vendor draws.\\n\\nThe counterargument that holds up best is that retrieval is not disappearing so much as being re-drawn. In January 2026 — months before Nexus existed publicly — Algolia published a rebuttal to a viral essay titled \\\"The RAG Obituary,\\\" arguing that the case against RAG is really a case against \\\"naive, slow, passive implementations,\\\" and that once hybrid keyword-and-vector retrieval is \\\"fast, structured, predictable, and directly callable by the model, the distinction of RAG vs agents becomes obsolete.\\\"[^7] Algolia sells retrieval, so read it with the same skepticism as Pinecone's benchmarks; but the continuum argument is the one that survives contact with real systems. Compiling knowledge upfront and retrieving it at query time are points on a spectrum, and where a given workload lands depends on how bounded and how stable its corpus is. Pinecone is also not alone in the compilation direction — InfoQ points to comparable efforts from Cognite, RelationalAI, and LlamaIndex, among others.[^4]\\n\\nWhere boosters and skeptics agree is the underlying insight, and it is worth taking seriously even if you never touch Nexus: for agents working a fixed corpus, making the model rediscover the same structure on every task is waste. That is the same lesson showing up in adjacent work on [agent memory systems](/microsoft-memora-huawei-jiuwenmemory-agent-memory) and on [how many tools an agent can realistically juggle](/how-many-tools-can-an-ai-agent-handle) — the bottleneck in 2026 is less often the model and more often the context you hand it.\\n\\n## Why it matters if you are building agents\\n\\nThe practical takeaway is not \\\"rip out your RAG pipeline.\\\" It is a question worth asking about any agent you are shipping: how much of its token bill and latency is spent re-deriving structure it could have been handed? If an agent repeatedly loops over the same bounded set of documents to answer variations of the same question, the compilation-first model is a genuinely different cost curve, because the reasoning-about-the-corpus work is amortized once instead of paid per query.[^2][^3]\\n\\nThere are trade-offs the benchmarks do not foreground. Compilation adds an upstream step — someone has to author the Manifest and re-curate when the corpus drifts — which shifts effort rather than erasing it, and it fits corpora stable enough to be worth compiling.[^3] It also concentrates a great deal in one vendor's curation layer and query surface; the LangChain and Teradata collaborations suggest Pinecone knows a single-vendor interface is a hard sell, and the bring-your-own-cloud option and field-level provenance are the answers it offers to the governance version of the same worry.[^1][^3] For teams already thinking in terms of [context engineering rather than prompt engineering](/claude-memory-tool-context-editing-typescript-tutorial), and for anyone weighing how much agent behavior should be pinned down at build time versus discovered at run time (the same tension underneath [agent tooling protocols like MCP](/mcp-stateless-protocol-enterprise-authorization)), Nexus is a clear, well-argued data point — provided you read its benchmarks as the vendor's case rather than a settled result.\\n\\n## FAQ\\n\\n**What is Pinecone Nexus?** It is a \\\"knowledge engine\\\" for AI agents, announced May 4, 2026 and in public preview since July 1, 2026. It compiles an enterprise's scattered documents into structured, task-specific artifacts ahead of time, so agents query a pre-built knowledge layer through the KnowQL query language instead of retrieving and reassembling raw chunks on every request.[^1][^3]\\n\\n**Is RAG dead in 2026?** No — but standard \\\"retrieve-then-generate\\\" RAG is being narrowed. For bounded, slow-changing corpora, compilation-first approaches can beat agentic RAG on accuracy and token cost; for fast-changing or open-ended data, retrieval remains the right tool. The realistic framing is a spectrum, not a death.[^5][^7]\\n\\n**How is a knowledge engine different from a vector database?** A vector database finds relevant chunks at query time. A knowledge engine sits above search and pre-compiles those sources into typed, governed artifacts, so the agent reads a mostly-finished answer instead of assembling one. Pinecone describes Nexus as \\\"a knowledge engine, not a retrieval system,\\\" and says its vector database remains the foundation underneath.[^1][^2]\\n\\n**What is KnowQL?** KnowQL — Knowledge Query Language — is Pinecone's declarative query language and the single interface agents use to talk to Nexus. Like SQL, the agent declares the answer it needs, the shape it wants, and its constraints, and the engine plans how to compose it, returning typed responses with field-level citations.[^2] LangChain and Teradata have said they are working with Pinecone to advance it.[^1]\\n\\n**Are the performance numbers independent?** No. They come from Pinecone's own KRAFTBench harness and from early customers evaluating on Pinecone's preview environment — one of whom, Q2, ran its evaluation without Pinecone involved, though still on Pinecone's platform. The eval sets range from 20 to 150 questions. Treat them as the vendor's case until third parties reproduce them.[^2][^3][^5]\\n\\n**Can I run it without sending Pinecone my data?** Pinecone points to a bring-your-own-cloud deployment where the cluster runs inside your own VPC, which the company says means your documents never leave your infrastructure. It is request-gated for production workloads, and Pinecone described BYOC coverage for Nexus as arriving \\\"very soon\\\" as of its May launch. The hosted preview playground is the lower-commitment way to try it.[^1][^3]\\n\\n[^1]: Pinecone, \\\"Pinecone Nexus: The Knowledge Engine for Agents\\\" (launch announcement; Ash Ashutosh and Edo Liberty, May 4, 2026). https://www.pinecone.io/blog/knowledge-infrastructure-for-agents/\\n[^2]: Pinecone, \\\"Better Models Won't Save Your Agent\\\" (engineering deep dive and KRAFTBench results; Jeff Zhu and Siva Ragavan, May 4, 2026). https://www.pinecone.io/blog/introducing-nexus-knowledge-engine/\\n[^3]: Pinecone, \\\"Pinecone Nexus Is Now in Public Preview\\\" (Jasmeet Singh Gujral and Lea Wang-Tomic, July 1, 2026). https://www.pinecone.io/blog/pinecone-nexus-public-preview/\\n[^4]: Sergio De Simone, \\\"Pinecone Introduces Nexus Engine for Compiling Business Context into Structured Data for AI Agents,\\\" InfoQ, July 18, 2026. https://www.infoq.com/news/2026/07/pinecon-nexus-knowledge-engine/\\n[^5]: Janakiram MSV, \\\"The company that made RAG mainstream is now betting against it,\\\" The New Stack, May 6, 2026. https://thenewstack.io/pinecone-nexus-rag-obsolete/\\n[^6]: \\\"The RAG era is ending for agentic AI — a new compilation-stage knowledge layer is what comes next,\\\" VentureBeat, May 4, 2026. https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next\\n[^7]: Alex Webb, \\\"No, RAG is not dead,\\\" Algolia, January 15, 2026 — a response to the viral essay \\\"The RAG Obituary: Killed By Agents, Buried By Context Windows.\\\" https://www.algolia.com/blog/ai/rag-is-not-dead\\n[^8]: Pinecone, \\\"What is Context Engineering?\\\" https://www.pinecone.io/learn/context-engineering/\\n\"])</script><script>self.__next_f.push([1,\"9:[[\\\"$\\\",\\\"script\\\",null,{\\\"type\\\":\\\"application/ld+json\\\",\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"$1e\\\"}}],[\\\"$\\\",\\\"$L1f\\\",null,{\\\"post\\\":{\\\"slug\\\":\\\"ietf-ai-agent-protocol-standard-agentproto\\\",\\\"content\\\":\\\"$20\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\",\\\"title\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"keywords\\\":[\\\"IETF AI agent protocol standard\\\",\\\"agentproto BoF\\\",\\\"MCP vs A2A\\\",\\\"AI agent protocol interoperability\\\",\\\"IETF 126 Vienna AI agents\\\",\\\"will the IETF standardize AI agent protocols\\\",\\\"cross-domain agent identity federation\\\"],\\\"tags\\\":[\\\"IETF\\\",\\\"AI agent protocol\\\",\\\"agentproto\\\",\\\"MCP\\\",\\\"A2A\\\",\\\"agent interoperability\\\",\\\"agentic ai\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\\\",\\\"date\\\":\\\"2026-07-24T00:00:00.000Z\\\"}},\\\"translatedContent\\\":{\\\"title\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\",\\\"description\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\",\\\"body\\\":\\\"$21\\\",\\\"prevTitle\\\":\\\"AI Agents in Go: Microsoft Joins Google's Bet in 2026\\\",\\\"nextTitle\\\":\\\"Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\\\",\\\"tocHeader\\\":\\\"Table of contents\\\",\\\"tocAriaLabel\\\":\\\"Table of contents\\\"},\\\"toc\\\":[{\\\"id\\\":\\\"what-youll-learn\\\",\\\"text\\\":\\\"What you'll learn\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"what-happened-at-the-agentproto-bof\\\",\\\"text\\\":\\\"What happened at the agentproto BoF\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"why-it-is-rough-consensus-not-a-vote\\\",\\\"text\\\":\\\"Why it is rough consensus, not a vote\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"mcp-vs-a2a-two-layers-one-missing-piece\\\",\\\"text\\\":\\\"MCP vs A2A: two layers, one missing piece\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"the-problems-the-framework-says-still-need-a-standard\\\",\\\"text\\\":\\\"The problems the framework says still need a standard\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"why-prompt-injection-is-the-security-test\\\",\\\"text\\\":\\\"Why prompt injection is the security test\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"the-realistic-timeline--and-what-to-watch\\\",\\\"text\\\":\\\"The realistic timeline — and what to watch\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"faq\\\",\\\"text\\\":\\\"FAQ\\\",\\\"depth\\\":2},{\\\"id\\\":\\\"is-the-ietf-standardizing-ai-agent-protocols\\\",\\\"text\\\":\\\"Is the IETF standardizing AI agent protocols?\\\",\\\"depth\\\":3},{\\\"id\\\":\\\"what-is-the-agentproto-bof-at-ietf-126\\\",\\\"text\\\":\\\"What is the agentproto BoF at IETF 126?\\\",\\\"depth\\\":3},{\\\"id\\\":\\\"how-is-mcp-different-from-a2a\\\",\\\"text\\\":\\\"How is MCP different from A2A?\\\",\\\"depth\\\":3},{\\\"id\\\":\\\"what-would-an-ietf-rfc-add-that-mcp-and-a2a-dont-cover\\\",\\\"text\\\":\\\"What would an IETF RFC add that MCP and A2A don't cover?\\\",\\\"depth\\\":3},{\\\"id\\\":\\\"why-is-prompt-injection-worse-in-multi-agent-systems\\\",\\\"text\\\":\\\"Why is prompt injection worse in multi-agent systems?\\\",\\\"depth\\\":3}],\\\"prevSlug\\\":\\\"microsoft-agent-framework-go-google-adk\\\",\\\"nextSlug\\\":\\\"pinecone-nexus-knowledge-engine-rag-agents\\\",\\\"prevTitle\\\":\\\"AI Agents in Go: Microsoft Joins Google's Bet in 2026\\\",\\\"nextTitle\\\":\\\"Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\\\",\\\"shareUrl\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\",\\\"prevHref\\\":\\\"/microsoft-agent-framework-go-google-adk\\\",\\\"nextHref\\\":\\\"/pinecone-nexus-knowledge-engine-rag-agents\\\",\\\"lang\\\":\\\"en\\\",\\\"tocHeader\\\":\\\"Table of contents\\\",\\\"tocAriaLabel\\\":\\\"Table of contents\\\",\\\"updatedLabel\\\":\\\"Updated\\\",\\\"bodyWithoutFAQ\\\":\\\"$22\\\",\\\"faqItems\\\":[{\\\"question\\\":\\\"Is the IETF standardizing AI agent protocols?\\\",\\\"answer\\\":\\\"Not yet. At IETF 126 in Vienna, the agentproto Birds-of-a-Feather session opened the question of whether the IETF should charter a Working Group to standardize agent-to-agent communication.1 A BoF is an exploratory step, not a standard; even if a Working Group is chartered, a published RFC is typically two to four years out.10 The authoritative outcome of the session is posted to the IETF Datatracker.\\\"},{\\\"question\\\":\\\"What is the agentproto BoF at IETF 126?\\\",\\\"answer\\\":\\\"Agentproto (Agent Communication Protocols) was a working-group-forming Birds-of-a-Feather session held Thursday, 23 July 2026, at IETF 126 in Vienna. It brought the fragmented landscape of agent protocols — MCP, A2A, ACP, ANP, and others — into the IETF to identify which building blocks genuinely need a standard, building on requirements work by Jonathan Rosenberg and Cullen Jennings.17\\\"},{\\\"question\\\":\\\"How is MCP different from A2A?\\\",\\\"answer\\\":\\\"MCP is a client-server protocol connecting one agent to tools, data, and APIs; A2A is a peer-to-peer protocol letting agents discover each other's capabilities and delegate tasks.35 They are complementary rather than competing. What neither fully specifies is cross-domain identity federation and incident attribution when agents from different organizations interact without prior trust.7\\\"},{\\\"question\\\":\\\"What would an IETF RFC add that MCP and A2A don't cover?\\\",\\\"answer\\\":\\\"The framework behind agentproto argues that a standard is needed for cross-domain agent discovery and identity federation, lifecycle management of multi-hop delegation chains, human confirmation before irreversible actions, and protocol-level attribution for security incidents such as multi-agent prompt injection.7 These are inter-organizational guarantees that a single vendor's protocol is not positioned to define on its own.\\\"},{\\\"question\\\":\\\"Why is prompt injection worse in multi-agent systems?\\\",\\\"answer\\\":\\\"$23\\\"}],\\\"faqHeadingId\\\":\\\"faq\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mx-auto max-w-3xl px-4\\\",\\\"children\\\":[\\\"$\\\",\\\"$L24\\\",null,{\\\"posts\\\":[{\\\"slug\\\":\\\"claude-adobe-creativity-connector-50-creative-cloud-tools\\\",\\\"content\\\":\\\"$25\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"Adobe and Anthropic launched the Adobe for creativity connector for Claude on April 28, 2026, exposing 50+ Photoshop, Premiere, and Firefly tools via MCP.\\\",\\\"title\\\":\\\"Adobe + Claude: 50+ Creative Tools From One Prompt\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"tags\\\":[\\\"claude\\\",\\\"adobe\\\",\\\"adobe-creative-cloud\\\",\\\"mcp\\\",\\\"claude-connectors\\\",\\\"anthropic\\\",\\\"creative-ai\\\",\\\"agentic-ai\\\",\\\"photoshop\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/placeholders/cover-general.svg\\\",\\\"date\\\":\\\"2026-05-01T00:00:00.000Z\\\"}},{\\\"slug\\\":\\\"claude-managed-agents-deploy-ai-agents-faster\\\",\\\"content\\\":\\\"$26\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"Claude Managed Agents (public beta, April 2026): hosted sandboxing, state, tool execution, and error recovery — production agents in days instead of weeks.\\\",\\\"title\\\":\\\"Claude Managed Agents: Build Production AI Agents in Days\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"tags\\\":[\\\"anthropic\\\",\\\"claude\\\",\\\"ai-agents\\\",\\\"managed-agents\\\",\\\"mcp\\\",\\\"enterprise-ai\\\",\\\"agentic-ai\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/placeholders/cover-general.svg\\\",\\\"date\\\":\\\"2026-04-13T00:00:00.000Z\\\"}},{\\\"slug\\\":\\\"agentic-testing-slack-200-run-data\\\",\\\"content\\\":\\\"$27\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"Slack ran 200+ agentic E2E tests. The data on cost ($15-30/run), reliability, and where agentic testing fits versus traditional automated tests in 2026.\\\",\\\"title\\\":\\\"Agentic Testing in 2026: What Slack's 200-Run Data Shows\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"keywords\\\":[\\\"agentic testing\\\",\\\"agentic e2e testing\\\",\\\"AI agent test automation\\\",\\\"agentic testing cost\\\",\\\"Playwright MCP vs Playwright CLI\\\",\\\"agentic testing reliability\\\",\\\"does agentic testing replace traditional tests\\\",\\\"where agentic testing fits testing pyramid\\\"],\\\"tags\\\":[\\\"agentic testing\\\",\\\"AI agents\\\",\\\"end-to-end testing\\\",\\\"Playwright MCP\\\",\\\"test automation\\\",\\\"agentic ai\\\",\\\"QA automation\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/covers/agentic-testing-slack-200-run-data.jpg\\\",\\\"date\\\":\\\"2026-07-26T00:00:00.000Z\\\"}},{\\\"slug\\\":\\\"pinecone-nexus-knowledge-engine-rag-agents\\\",\\\"content\\\":\\\"$28\\\",\\\"frontmatter\\\":{\\\"description\\\":\\\"Pinecone Nexus, a knowledge engine for AI agents, compiles enterprise data upfront to cut the RAG retrieval loop. What changes in 2026 — and if RAG is dead.\\\",\\\"title\\\":\\\"Pinecone Nexus: Is RAG Ending for AI Agents? (2026)\\\",\\\"category\\\":\\\"ai-ml\\\",\\\"keywords\\\":[\\\"Pinecone Nexus\\\",\\\"knowledge engine for AI agents\\\",\\\"is RAG dead 2026\\\",\\\"knowledge compilation vs RAG\\\",\\\"context engineering for AI agents\\\",\\\"KnowQL declarative query language\\\",\\\"what is Pinecone Nexus\\\",\\\"reduce agent token cost retrieval\\\"],\\\"tags\\\":[\\\"Pinecone Nexus\\\",\\\"knowledge engine\\\",\\\"RAG\\\",\\\"context engineering\\\",\\\"KnowQL\\\",\\\"AI agents\\\",\\\"agentic ai\\\"],\\\"featured\\\":true,\\\"coverImage\\\":\\\"/images/covers/pinecone-nexus-knowledge-engine-rag-agents.jpg\\\",\\\"date\\\":\\\"2026-07-25T00:00:00.000Z\\\"}}],\\\"lang\\\":\\\"en\\\",\\\"translatedTitles\\\":\\\"$undefined\\\"}]}]]\\n\"])</script><script>self.__next_f.push([1,\"10:[[\\\"$\\\",\\\"meta\\\",\\\"0\\\",{\\\"name\\\":\\\"viewport\\\",\\\"content\\\":\\\"width=device-width, initial-scale=1, viewport-fit=cover\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"1\\\",{\\\"charSet\\\":\\\"utf-8\\\"}],[\\\"$\\\",\\\"title\\\",\\\"2\\\",{\\\"children\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026 | Nerd Level Tech\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"3\\\",{\\\"name\\\":\\\"description\\\",\\\"content\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\"}],[\\\"$\\\",\\\"link\\\",\\\"4\\\",{\\\"rel\\\":\\\"canonical\\\",\\\"href\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"}],[\\\"$\\\",\\\"link\\\",\\\"5\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"en-US\\\",\\\"href\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"}],[\\\"$\\\",\\\"link\\\",\\\"6\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"ar-EG\\\",\\\"href\\\":\\\"https://nerdleveltech.com/ar/ietf-ai-agent-protocol-standard-agentproto\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"7\\\",{\\\"property\\\":\\\"og:title\\\",\\\"content\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"8\\\",{\\\"property\\\":\\\"og:description\\\",\\\"content\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"9\\\",{\\\"property\\\":\\\"og:url\\\",\\\"content\\\":\\\"https://nerdleveltech.com/ietf-ai-agent-protocol-standard-agentproto\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"10\\\",{\\\"property\\\":\\\"og:image\\\",\\\"content\\\":\\\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"11\\\",{\\\"property\\\":\\\"og:image:width\\\",\\\"content\\\":\\\"1200\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"12\\\",{\\\"property\\\":\\\"og:image:height\\\",\\\"content\\\":\\\"630\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"13\\\",{\\\"property\\\":\\\"og:image:alt\\\",\\\"content\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"14\\\",{\\\"property\\\":\\\"og:type\\\",\\\"content\\\":\\\"article\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"15\\\",{\\\"property\\\":\\\"article:published_time\\\",\\\"content\\\":\\\"2026-07-24T00:00:00.000Z\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"16\\\",{\\\"name\\\":\\\"twitter:card\\\",\\\"content\\\":\\\"summary_large_image\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"17\\\",{\\\"name\\\":\\\"twitter:title\\\",\\\"content\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"18\\\",{\\\"name\\\":\\\"twitter:description\\\",\\\"content\\\":\\\"At IETF 126 in Vienna, the agentproto BoF put AI agent protocols like MCP and A2A under standards-body scrutiny. Here is what an IETF RFC would actually change.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"19\\\",{\\\"name\\\":\\\"twitter:image\\\",\\\"content\\\":\\\"https://nerdleveltech.com/images/covers/ietf-ai-agent-protocol-standard-agentproto.jpg\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"20\\\",{\\\"name\\\":\\\"twitter:image:width\\\",\\\"content\\\":\\\"1200\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"21\\\",{\\\"name\\\":\\\"twitter:image:height\\\",\\\"content\\\":\\\"630\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"22\\\",{\\\"name\\\":\\\"twitter:image:alt\\\",\\\"content\\\":\\\"IETF Weighs an AI Agent Protocol Standard in 2026\\\"}],[\\\"$\\\",\\\"link\\\",\\\"23\\\",{\\\"rel\\\":\\\"icon\\\",\\\"href\\\":\\\"/favicon.svg\\\",\\\"type\\\":\\\"image/svg+xml\\\"}],[\\\"$\\\",\\\"link\\\",\\\"24\\\",{\\\"rel\\\":\\\"icon\\\",\\\"href\\\":\\\"/icon.svg\\\",\\\"type\\\":\\\"image/svg+xml\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"25\\\",{\\\"name\\\":\\\"next-size-adjust\\\"}]]\\n\"])</script><script>self.__next_f.push([1,\"8:null\\n\"])</script><script>self.__next_f.push([1,\"2a:I[81025,[\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3185\\\",\\\"static/chunks/app/layout-4e6ae73d356025e1.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n2b:I[68259,[\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"3185\\\",\\\"static/chunks/app/layout-4e6ae73d356025e1.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n29:T403,(function(){\\n  if (window.fbq) return;\\n  var n = window.fbq = function(){ n.callMethod ? n.callMethod.apply(n, arguments) : n.queue.push(arguments); };\\n  if (!window._fbq) window._fbq = n;\\n  n.push = n; n.loaded = true; n.version = '2.0'; n.queue = [];\\n  fbq('init', '1937494190493436');\\n  fbq('track', 'PageView');\\n  var loaded = false;\\n  function loadPixel() {\\n    if (loaded) return;\\n    loaded = true;\\n    var s = document.createElement('script');\\n    s.async = true;\\n    s.src = 'https://connect.facebook.net/en_US/fbevents.js';\\n    document.head.appendChild(s);\\n    ['scroll','click','mousemove','touchstart'].forEach(function(e){\\n      document.removeEventListener(e, loadPixel);\\n    });\\n  }\\n  if (document.readyState === 'complete') {\\n    setTimeout(loadPixel, 3000);\\n  } else {\\n    window.addEventListener('load', function() { setTimeout(loadPixel, 3000); });\\n  }\\n  ['scroll','click','mousemove','touchstart'].forEach(function(e){\\n    document.addEventListener(e, loadPixel, { once: true, passive: true });\\n  });\\n})();\"])</script><script>self.__next_f.push([1,\"f:[\\\"$\\\",\\\"html\\\",null,{\\\"lang\\\":\\\"en\\\",\\\"dir\\\":\\\"ltr\\\",\\\"className\\\":\\\"__variable_bbcc58 __variable_948ce5 __variable_9ded40 __variable_3f4575 __variable_16cd69\\\",\\\"suppressHydrationWarning\\\":true,\\\"children\\\":[[\\\"$\\\",\\\"head\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"(() =\\u003e {\\\\n var t = localStorage.getItem('theme');\\\\n var d = document.documentElement;\\\\n if (t === 'dark' || (!t || t === 'system') \\u0026\\u0026 window.matchMedia('(prefers-color-scheme: dark)').matches) {\\\\n d.classList.add('dark');\\\\n } else {\\\\n d.classList.remove('dark');\\\\n }\\\\n try {\\\\n var consent = localStorage.getItem('nlt-cookie-consent');\\\\n if (consent) d.setAttribute('data-nlt-consent', consent);\\\\n } catch (e) {}\\\\n})();\\\"}}],[\\\"$\\\",\\\"meta\\\",null,{\\\"name\\\":\\\"msvalidate.01\\\",\\\"content\\\":\\\"63B94FDFC56A65B5E9E316E474AB9D0D\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/rss+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Articles\\\",\\\"href\\\":\\\"/rss.xml\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/atom+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Articles\\\",\\\"href\\\":\\\"/atom.xml\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/rss+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Podcast\\\",\\\"href\\\":\\\"/podcast.xml\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/rss+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Courses\\\",\\\"href\\\":\\\"/courses-rss.xml\\\"}],[\\\"$\\\",\\\"link\\\",null,{\\\"rel\\\":\\\"alternate\\\",\\\"type\\\":\\\"application/rss+xml\\\",\\\"title\\\":\\\"NerdLevelTech — Remote Tech Jobs\\\",\\\"href\\\":\\\"/jobs-rss.xml\\\"}],[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"(function(){\\\\n  window.clarity = window.clarity || function(){ (window.clarity.q = window.clarity.q || []).push(arguments); };\\\\n  var loaded = false;\\\\n  function loadClarity() {\\\\n    if (loaded) return;\\\\n    loaded = true;\\\\n    var s = document.createElement('script');\\\\n    s.async = true;\\\\n    s.src = 'https://www.clarity.ms/tag/uiskr3p74z';\\\\n    document.head.appendChild(s);\\\\n    ['scroll','click','mousemove','touchstart'].forEach(function(e){\\\\n      document.removeEventListener(e, loadClarity);\\\\n    });\\\\n  }\\\\n  if (document.readyState === 'complete') {\\\\n    setTimeout(loadClarity, 3000);\\\\n  } else {\\\\n    window.addEventListener('load', function() { setTimeout(loadClarity, 3000); });\\\\n  }\\\\n  ['scroll','click','mousemove','touchstart'].forEach(function(e){\\\\n    document.addEventListener(e, loadClarity, { once: true, passive: true });\\\\n  });\\\\n})();\\\"}}],[\\\"$\\\",\\\"script\\\",null,{\\\"async\\\":true,\\\"src\\\":\\\"https://www.googletagmanager.com/gtag/js?id=G-7LWRNQMJYQ\\\"}],[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"\\\\n window.dataLayer = window.dataLayer || [];\\\\n function gtag(){dataLayer.push(arguments);}\\\\n\\\\n // Default consent to 'denied' for GDPR compliance (EU/EEA users)\\\\n gtag('consent', 'default', {\\\\n 'ad_storage': 'denied',\\\\n 'ad_user_data': 'denied',\\\\n 'ad_personalization': 'denied',\\\\n 'analytics_storage': 'denied'\\\\n });\\\\n\\\\n gtag('js', new Date());\\\\n // Skip the initial config + pageview for admin routes. SPA navigations\\\\n // away from /admin still work — AnalyticsListeners fires page_view on\\\\n // route change for any non-admin path it sees next.\\\\n if (!/^\\\\\\\\/admin(\\\\\\\\/|$)/.test(window.location.pathname)) {\\\\n gtag('config', 'G-7LWRNQMJYQ');\\\\n }\\\\n\\\\n // Check if user already consented and update consent accordingly\\\\n try {\\\\n var consent = localStorage.getItem('nlt-cookie-consent');\\\\n if (consent === 'accepted') {\\\\n gtag('consent', 'update', {\\\\n 'ad_storage': 'granted',\\\\n 'ad_user_data': 'granted',\\\\n 'ad_personalization': 'granted',\\\\n 'analytics_storage': 'granted'\\\\n });\\\\n }\\\\n } catch(e) {}\\\\n\\\"}}],[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"(function(){\\\\n var loaded = false;\\\\n function loadBrevo() {\\\\n if (loaded) return;\\\\n loaded = true;\\\\n var s = document.createElement('script');\\\\n s.src = 'https://cdn.brevo.com/js/sdk-loader.js';\\\\n s.async = true;\\\\n s.onload = function() {\\\\n window.Brevo = window.Brevo || [];\\\\n Brevo.push([\\\\\\\"init\\\\\\\", { client_key:\\\\\\\"07ps0c5debu6rk7jhbq1fkyj\\\\\\\" }]);\\\\n };\\\\n document.head.appendChild(s);\\\\n ['scroll','click','mousemove','touchstart'].forEach(function(e){\\\\n document.removeEventListener(e, loadBrevo);\\\\n });\\\\n }\\\\n if (document.readyState === 'complete') {\\\\n setTimeout(loadBrevo, 3000);\\\\n } else {\\\\n window.addEventListener('load', function() { setTimeout(loadBrevo, 3000); });\\\\n }\\\\n ['scroll','click','mousemove','touchstart'].forEach(function(e){\\\\n document.addEventListener(e, loadBrevo, { once: true, passive: true });\\\\n });\\\\n})();\\\"}}],[[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"$29\\\"}}],[\\\"$\\\",\\\"noscript\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"img\\\",null,{\\\"height\\\":\\\"1\\\",\\\"width\\\":\\\"1\\\",\\\"style\\\":{\\\"display\\\":\\\"none\\\"},\\\"src\\\":\\\"https://www.facebook.com/tr?id=1937494190493436\\u0026ev=PageView\\u0026noscript=1\\\",\\\"alt\\\":\\\"\\\"}]}]]]}],[\\\"$\\\",\\\"body\\\",null,{\\\"className\\\":\\\"nlt-newlook\\\",\\\"children\\\":[[\\\"$\\\",\\\"script\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"(() =\\u003e {\\\\n var RTL_LANGS = ['ar', 'he', 'fa', 'ur'];\\\\n var pathname = window.location.pathname;\\\\n var langMatch = pathname.match(/^\\\\\\\\/([a-z]{2})(\\\\\\\\/|$)/);\\\\n var lang = langMatch ? langMatch[1] : 'en';\\\\n var isRTL = RTL_LANGS.indexOf(lang) !== -1;\\\\n document.documentElement.dir = isRTL ? 'rtl' : 'ltr';\\\\n document.documentElement.lang = lang;\\\\n})();\\\"}}],[\\\"$\\\",\\\"$L2a\\\",null,{}],[\\\"$\\\",\\\"$L2b\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$La\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"segmentPath\\\":[\\\"children\\\"],\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$Ld\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$L2c\\\",\\\"notFoundStyles\\\":[]}]}]]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"2d:I[86654,[\\\"2972\\\",\\\"static/chunks/2972-dd97b5f59023ad3e.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"8975\\\",\\\"static/chunks/8975-adfc9b974456bd76.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\",\\\"9160\\\",\\\"static/chunks/app/not-found-c019844bdcd8d240.js?dpl=dpl_Cp3Yg3kZGg6j9yZRCzY4yFzwCoQ9\\\"],\\\"default\\\"]\\n\"])</script><script>self.__next_f.push([1,\"2c:[\\\"$\\\",\\\"$L2d\\\",null,{\\\"lang\\\":\\\"en\\\",\\\"recentPosts\\\":[{\\\"slug\\\":\\\"ai-agent-kill-switch-containment\\\",\\\"title\\\":\\\"AI Agent Kill Switches: Can You Actually Stop One in 2026?\\\",\\\"description\\\":\\\"OpenAI's models breached Hugging Face on their own — yet only 5% of teams say they could contain a rogue AI agent. What real agent kill switches look like.\\\",\\\"date\\\":\\\"2026-07-28T00:00:00.000Z\\\",\\\"category\\\":\\\"security\\\",\\\"tags\\\":[\\\"AI agents\\\",\\\"agent security\\\"]},{\\\"slug\\\":\\\"openai-presence-enterprise-agent-platform\\\",\\\"title\\\":\\\"OpenAI Presence: Enterprise Agent Platform in 2026\\\",\\\"description\\\":\\\"OpenAI Presence is a managed platform for deploying governed voice and chat AI agents. What it does, how it differs from build-it SDKs, and why it matters.\\\",\\\"date\\\":\\\"2026-07-28T00:00:00.000Z\\\",\\\"category\\\":\\\"news\\\",\\\"tags\\\":[\\\"AI agents\\\",\\\"OpenAI\\\"]},{\\\"slug\\\":\\\"ai-agent-payments-x402-standards\\\",\\\"title\\\":\\\"AI Agent Payments: The x402 Standards Race in 2026\\\",\\\"description\\\":\\\"The Linux Foundation launched the x402 Foundation with 40 members in July 2026. Here is how AI agents pay now: x402, Google's AP2, and the card giants.\\\",\\\"date\\\":\\\"2026-07-27T00:00:00.000Z\\\",\\\"category\\\":\\\"news\\\",\\\"tags\\\":[\\\"AI agents\\\",\\\"agentic payments\\\"]}],\\\"guides\\\":[{\\\"slug\\\":\\\"n8n-rag-chat-webpage\\\",\\\"title\\\":{\\\"en\\\":\\\"Build a RAG Chatbot That Answers From Any Webpage in n8n (7 Nodes)\\\",\\\"ar\\\":\\\"ابنِ روبوت RAG يُجيب من أي صفحة ويب في n8n (7 عقد)\\\"},\\\"description\\\":{\\\"en\\\":\\\"Wire a chat trigger to an AI agent with windowed memory and retrieval from a live URL. The workflow fetches the page on every question, chunks it, ranks chunks by query relevance, and grounds gpt-5-mini's answer with source citations — no vector DB, no embeddings bill.\\\",\\\"ar\\\":\\\"وصل مُشغِّل دردشة بوكيل AI مع ذاكرة نافذة واسترجاع من رابط مباشر. السير يجلب الصفحة مع كل سؤال، يُقسمها إلى chunks، يُرتبها بالصلة بالاستعلام، ويُؤصل إجابة gpt-5-mini بمراجع مصدر — بدون قاعدة بيانات متجهية، بدون فاتورة embeddings.\\\"},\\\"category\\\":\\\"tooling\\\",\\\"estimatedReadingMinutes\\\":17,\\\"isFeatured\\\":true},{\\\"slug\\\":\\\"n8n-ai-workflows\\\",\\\"title\\\":{\\\"en\\\":\\\"Build an AI Research Digest with n8n — No Code, Real Output in 6 Steps\\\",\\\"ar\\\":\\\"بناء ملخص بحثي بالذكاء الاصطناعي مع n8n — بلا كود، نتائج حقيقية في 6 خطوات\\\"},\\\"description\\\":{\\\"en\\\":\\\"Build a fully automated AI newsletter that fetches the top 10 Hacker News stories daily, summarizes each with GPT, and formats a polished digest email — all in n8n's visual canvas. Every node was wired and executed live on n8n cloud. No code required beyond one simple JavaScript snippet.\\\",\\\"ar\\\":\\\"ابنِ نشرة إخبارية AI مؤتمتة بالكامل تجلب أهم 10 قصص من Hacker News يومياً وتلخصها بـ GPT وتُنسّق بريداً إلكترونياً أنيقاً — كل ذلك في لوحة n8n البصرية. كل عقدة وُصِّلت ونُفِّذت مباشرةً على n8n cloud. لا حاجة لكود سوى مقطع JavaScript بسيط.\\\"},\\\"category\\\":\\\"tooling\\\",\\\"estimatedReadingMinutes\\\":25,\\\"isFeatured\\\":true},{\\\"slug\\\":\\\"dify-rag-chatbot\\\",\\\"title\\\":{\\\"en\\\":\\\"Build a RAG Chatbot with Dify — No Code, Real Output in 5 Steps\\\",\\\"ar\\\":\\\"بناء شات بوت RAG مع Dify — بلا كود، نتائج حقيقية في 5 خطوات\\\"},\\\"description\\\":{\\\"en\\\":\\\"Build a fully working RAG chatbot in Dify's visual builder — no code required. Every step was executed live on cloud.dify.ai and produces real output. Covers model setup, Knowledge Base creation with hybrid search, Chatflow wiring, live testing, and API integration.\\\",\\\"ar\\\":\\\"ابنِ شات بوت RAG كامل الوظائف في Dify — بدون كود. كل خطوة نُفِّذت مباشرةً على cloud.dify.ai وتنتج نتائج حقيقية. يغطي إعداد النماذج وقاعدة المعرفة والبحث الهجين واختبار التطبيق الحي وتكامل API.\\\"},\\\"category\\\":\\\"llm-integration\\\",\\\"estimatedReadingMinutes\\\":20,\\\"isFeatured\\\":true}],\\\"recentCourses\\\":[{\\\"slug\\\":\\\"prompt-engineering-path-code\\\",\\\"title\\\":{\\\"en\\\":\\\"Prompts for Code \\u0026 Engineering — The Prompt Engineering Path\\\",\\\"ar\\\":\\\"أوامر للكود والهندسة — مسار هندسة الأوامر\\\"},\\\"description\\\":{\\\"en\\\":\\\"The expansion course for engineers. Master code-generation prompts, debugging prompts, refactor locks, structured code-review prompts, and the prompt patterns that make Cursor, Claude Code, Aider, and Copilot productive. Every example is a real, verified Claude output you can re-run.\\\",\\\"ar\\\":\\\"دورة التوسع للمهندسين. أتقن أوامر توليد الكود، أوامر تصحيح الأخطاء، أقفال إعادة الهيكلة، أوامر مراجعة الكود المنظمة، وأنماط الأوامر التي تجعل Cursor و Claude Code و Aider و Copilot منتجة. كل مثال هو مخرج حقيقي موثق من Claude يمكنك إعادة تشغيله.\\\"},\\\"difficultyLevel\\\":\\\"intermediate\\\",\\\"category\\\":\\\"ai\\\",\\\"lessonCount\\\":26},{\\\"slug\\\":\\\"prompt-engineering-path-cross-model\\\",\\\"title\\\":{\\\"en\\\":\\\"Cross-Model Mastery — The Prompt Engineering Path\\\",\\\"ar\\\":\\\"إتقان النماذج المتعددة — مسار هندسة الأوامر\\\"},\\\"description\\\":{\\\"en\\\":\\\"The same prompt sent to Claude, GPT, and Gemini lands three different responses. Learn the dialects: tone, instruction-following, structured output, refusal shape, system-prompt loyalty. Every comparison in this course was captured live from the three frontier APIs — not from training data, not from screenshots.\\\",\\\"ar\\\":\\\"نفس الأمر المُرسَل إلى Claude و GPT و Gemini يحصل على ثلاث ردود مختلفة. تعلم اللهجات: النبرة، اتباع التعليمات، المخرج المنظم، شكل الرفض، الولاء لأمر النظام. كل مقارنة في هذه الدورة تم التقاطها مباشرةً من الـAPIs الثلاثة الرائدة — ليست من بيانات التدريب، ولا من لقطات الشاشة.\\\"},\\\"difficultyLevel\\\":\\\"intermediate\\\",\\\"category\\\":\\\"ai\\\",\\\"lessonCount\\\":24},{\\\"slug\\\":\\\"prompt-engineering-path-foundations\\\",\\\"title\\\":{\\\"en\\\":\\\"The Prompt Engineering Path — Foundations\\\",\\\"ar\\\":\\\"مسار هندسة الأوامر — الأساسيات\\\"},\\\"description\\\":{\\\"en\\\":\\\"Learn the craft of prompting — from your first ChatGPT message to a tight production-grade system prompt. Real, verified outputs from Claude, GPT, and Gemini. Day-to-day scenarios, no fluff. The gateway to the full Prompt Engineering learning path.\\\",\\\"ar\\\":\\\"تعلم حرفة كتابة الأوامر — من أول رسالة في ChatGPT إلى أمر نظام محكم بمستوى الإنتاج. أمثلة حقيقية موثقة من Claude و GPT و Gemini. سيناريوهات يومية بدون حشو. البوابة لكامل مسار هندسة الأوامر.\\\"},\\\"difficultyLevel\\\":\\\"beginner\\\",\\\"category\\\":\\\"ai\\\",\\\"lessonCount\\\":42}],\\\"tools\\\":[{\\\"name\\\":\\\"API Response Mocker\\\",\\\"nameAr\\\":\\\"محاكي استجابة API\\\",\\\"description\\\":\\\"Generate realistic mock API responses with dynamic data using Faker.js. 18 pre-built templates for testing and development.\\\",\\\"descriptionAr\\\":\\\"أنشئ استجابات API وهمية واقعية مع بيانات ديناميكية باستخدام Faker.js. 18 قالباً جاهزاً للاختبار والتطوير.\\\",\\\"href\\\":\\\"/tools/api-response-mocker\\\"},{\\\"name\\\":\\\"Tech Pulse\\\",\\\"nameAr\\\":\\\"نبض التقنية\\\",\\\"description\\\":\\\"AI-curated tech news feed for developers. Get the latest AI, Cloud, DevOps, and Security updates in one place.\\\",\\\"descriptionAr\\\":\\\"موجز أخبار تقنية منتقى بالذكاء الاصطناعي للمطورين. احصل على آخر تحديثات الذكاء الاصطناعي والسحابة وDevOps والأمان في مكان واحد.\\\",\\\"href\\\":\\\"/tools/tech-pulse\\\"},{\\\"name\\\":\\\"Resume Optimizer\\\",\\\"nameAr\\\":\\\"محسّن السيرة الذاتية\\\",\\\"description\\\":\\\"Transform your resume for ATS compliance with AI-powered optimization. Upload and download improved DOCX/PDF versions.\\\",\\\"descriptionAr\\\":\\\"حوّل سيرتك الذاتية لتتوافق مع أنظمة ATS بتحسين مدعوم بالذكاء الاصطناعي. ارفع وحمّل نسخ DOCX/PDF محسّنة.\\\",\\\"href\\\":\\\"/tools/resume-optimizer\\\"},{\\\"name\\\":\\\"IP Checker + Browser Info\\\",\\\"nameAr\\\":\\\"فاحص IP + معلومات المتصفح\\\",\\\"description\\\":\\\"Discover your IP address, location, ISP details, and comprehensive browser information.\\\",\\\"descriptionAr\\\":\\\"اكتشف عنوان IP الخاص بك وموقعك وتفاصيل مزود الخدمة ومعلومات المتصفح الشاملة.\\\",\\\"href\\\":\\\"/tools/ip-checker\\\"}],\\\"nerdoModes\\\":[{\\\"id\\\":\\\"fast\\\",\\\"name\\\":\\\"nerdo.modes.fast.name\\\",\\\"description\\\":\\\"nerdo.modes.fast.description\\\",\\\"icon\\\":\\\"zap\\\"},{\\\"id\\\":\\\"learning\\\",\\\"name\\\":\\\"nerdo.modes.learning.name\\\",\\\"description\\\":\\\"nerdo.modes.learning.description\\\",\\\"icon\\\":\\\"graduation-cap\\\"},{\\\"id\\\":\\\"create-content\\\",\\\"name\\\":\\\"nerdo.modes.createContent.name\\\",\\\"description\\\":\\\"nerdo.modes.createContent.description\\\",\\\"icon\\\":\\\"pen-tool\\\"}],\\\"categories\\\":[{\\\"slug\\\":\\\"ai-ml\\\",\\\"name\\\":\\\"AI \\u0026 Machine Learning\\\",\\\"color\\\":\\\"text-purple-500 dark:text-purple-400\\\"},{\\\"slug\\\":\\\"llm-integration\\\",\\\"name\\\":\\\"LLM \\u0026 Integration\\\",\\\"color\\\":\\\"text-indigo-500 dark:text-indigo-400\\\"},{\\\"slug\\\":\\\"cloud-devops\\\",\\\"name\\\":\\\"Cloud \\u0026 DevOps\\\",\\\"color\\\":\\\"text-sky-500 dark:text-sky-400\\\"},{\\\"slug\\\":\\\"frontend\\\",\\\"name\\\":\\\"Frontend Development\\\",\\\"color\\\":\\\"text-blue-500 dark:text-blue-400\\\"},{\\\"slug\\\":\\\"backend\\\",\\\"name\\\":\\\"Backend Development\\\",\\\"color\\\":\\\"text-green-500 dark:text-green-400\\\"},{\\\"slug\\\":\\\"tooling\\\",\\\"name\\\":\\\"Tooling \\u0026 Productivity\\\",\\\"color\\\":\\\"text-orange-500 dark:text-orange-400\\\"},{\\\"slug\\\":\\\"architecture\\\",\\\"name\\\":\\\"Architecture \\u0026 Design\\\",\\\"color\\\":\\\"text-pink-500 dark:text-pink-400\\\"},{\\\"slug\\\":\\\"performance\\\",\\\"name\\\":\\\"Performance \\u0026 Optimization\\\",\\\"color\\\":\\\"text-yellow-500 dark:text-yellow-400\\\"},{\\\"slug\\\":\\\"security\\\",\\\"name\\\":\\\"Security \\u0026 Privacy\\\",\\\"color\\\":\\\"text-red-500 dark:text-red-400\\\"},{\\\"slug\\\":\\\"news\\\",\\\"name\\\":\\\"News\\\",\\\"color\\\":\\\"text-gray-500 dark:text-gray-400\\\"},{\\\"slug\\\":\\\"career\\\",\\\"name\\\":\\\"Career \\u0026 Growth\\\",\\\"color\\\":\\\"text-purple-500 dark:text-purple-400\\\"}]}]\\n\"])</script></body></html>","snapshot_chars":266244,"live_check":"matches"},{"url":"https://hackernoon.com/the-identity-layer-for-ai-agents-is-finally-being-built","committed_hash":"sha256:a9a2c03a0cfcdf307d0984cb94b7b8acdd5cc1618cb47f83adc3f5d3586dd915","committed_hash_short":"sha256:a9a2c03a…586dd915","mime_type":"text/html","committed_at":"2026-07-28T18:00:26.157562+00:00","content_snapshot":"<!DOCTYPE html><html lang=\"en\"><head><meta charSet=\"utf-8\" data-next-head=\"\"/><meta name=\"viewport\" content=\"width=device-width\" data-next-head=\"\"/><script async=\"\" src=\"https://www.googletagmanager.com/gtag/js?id=G-ECJJ2Q2SJQ\"></script><title data-next-head=\"\"></title><link rel=\"preconnect\" href=\"https://bridge.hackernoon.com\" data-next-head=\"\"/><link rel=\"preconnect\" href=\"https://cdn.hackernoon.com\" data-next-head=\"\"/><link rel=\"preconnect\" href=\"https://hackernoon.imgix.net\" data-next-head=\"\"/><link rel=\"dns-prefetch\" href=\"https://cdn.hackernoon.com\" data-next-head=\"\"/><meta name=\"description\" content=\"The identity layer for AI agents is finally being built. What MCP, A2A and new research delivered since March, and what&#x27;s still missing.\" data-next-head=\"\"/><meta property=\"og:title\" content=\"The Identity Layer for AI Agents Is Finally Being Built | HackerNoon\" data-next-head=\"\"/><meta property=\"og:description\" content=\"The identity layer for AI agents is finally being built. What MCP, A2A and new research delivered since March, and what&#x27;s still missing.\" data-next-head=\"\"/><meta name=\"image\" property=\"og:image\" content=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png\" data-next-head=\"\"/><meta property=\"twitter:title\" content=\"The Identity Layer for AI Agents Is Finally Being Built | HackerNoon\" data-next-head=\"\"/><meta property=\"twitter:description\" content=\"The identity layer for AI agents is finally being built. What MCP, A2A and new research delivered since March, and what&#x27;s still missing.\" data-next-head=\"\"/><meta property=\"twitter:image\" content=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png\" data-next-head=\"\"/><meta name=\"twitter:card\" content=\"summary_large_image\" data-next-head=\"\"/><meta name=\"twitter:site\" content=\"@hackernoon\" data-next-head=\"\"/><link rel=\"canonical\" href=\"https://hackernoon.com/the-identity-layer-for-ai-agents-is-finally-being-built\" data-next-head=\"\"/><link rel=\"alternate\" href=\"https://hackernoon.com/ru/the-identity-layer-for-ai-agents-is-finally-being-built\" hrefLang=\"ru\" data-next-head=\"\"/><link rel=\"preload\" as=\"font\" href=\"/fonts/HackerNoonFont/hackernoonv1-regular-webfont.woff2\" type=\"font/woff2\" crossorigin=\"anonymous\"/><link rel=\"preconnect\" href=\"https://fonts.googleapis.com\"/><link rel=\"preconnect\" href=\"https://fonts.gstatic.com\" crossorigin=\"anonymous\"/><link data-next-font=\"\" rel=\"preconnect\" href=\"/\" crossorigin=\"anonymous\"/><link rel=\"preload\" href=\"/_next/static/css/7830fe1600a03696.css\" as=\"style\"/><link rel=\"preload\" href=\"/_next/static/css/6d530d6069fd563f.css\" as=\"style\"/><link rel=\"preload\" as=\"image\" imageSrcSet=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=640 640w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=750 750w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=828 828w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=1080 1080w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=1200 1200w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=1920 1920w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=2048 2048w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=3840 3840w\" imageSizes=\"(max-width: 768px) 100vw, 900px\" data-next-head=\"\"/><script type=\"application/ld+json\" data-next-head=\"\">{\"@context\":\"http://schema.org\",\"@type\":\"Article\",\"name\":\"The Identity Layer for AI Agents Is Finally Being Built\",\"headline\":\"The Identity Layer for AI Agents Is Finally Being Built\",\"author\":{\"@type\":\"Person\",\"name\":\"Gus Aragón\"},\"datePublished\":\"2026-07-11\",\"image\":\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png\",\"articleSection\":\"ai-agents\",\"articleBody\":\"In March I published a piece arguing that AI agents don&apos;t have identities and that this was already a security crisis. The claim was operational. We were deploying systems that read files, call APIs and chain tools together, while the answer to the most basic security question, who exactly is acting right now, was still a shared account, a reused API key and permissions far broader than any single task required. Four months later the diagnosis holds. Agent identity is not solved end to end. What changed is that the problem became explicit. Between March and July 2026 it showed up in protocol releases, enterprise features and papers with measured results. The identity layer for AI agents is finally being built. It just isn&apos;t finished. A2A grew up first The first milestone landed almost on top of my original article. On March 12, the A2A project shipped v1.0.0, its first stable specification. The release touches security directly: it removes the legacy OAuth implicit and password flows, adds Device Code (RFC 8628) and PKCE support, introduces native multi-tenancy, adds mTLS to the security schemes and formalizes Agent Card signature verification using JWS and JSON Canonicalization. The signed Agent Cards are the piece I care about most. In v0.x, an Agent Card was self-declared metadata. Any agent could claim to be anything. With v1.0, clients can cryptographically verify agent identity and metadata before trusting an interaction across organizational boundaries. The spec also formalizes in-task authorization through the TASK_STATE_AUTH_REQUIRED state, which gives agents a standard fallback when an operation needs human or client approval mid-flight. The limitation is that Agent Cards remain a declarative layer. The signature proves who published the card. It says nothing about what a specific running instance of that agent is doing right now, or under whose delegated authority. Identity per instance, portable across heterogeneous stacks, still doesn&apos;t exist in the spec. MCP put authorization at the center MCP moved on a different front. On March 9, the maintainers published their 2026 roadmap, acknowledging that the protocol had outgrown its &quot;connect local tools&quot; phase and was now production infrastructure with governance to match. In April the project expanded its maintainer team, citing the move to the Agentic AI Foundation and a growing volume of Specification Enhancement Proposals. When a protocol starts adding lead maintainers to handle SEP throughput, it has stopped being an experiment. On May 21, the maintainers published the release candidate for MCP 2026-07-28 and described it as the largest revision since launch. It brings a stateless core, Tasks and MCP Apps as extensions, a formal deprecation policy and six SEPs hardening authorization to align with how OAuth 2.0 and OpenID Connect actually get deployed in production, including issuer validation per RFC 9207. The most tangible piece landed on June 18, when Enterprise-Managed Authorization went stable. EMA lets organizations control MCP server access centrally through their identity provider. Users log in once and inherit access to every approved server, with no per-app OAuth consent screens. Okta is the first supported IdP through Cross App Access. Anthropic implemented it across Claude, Claude Code and Cowork, Microsoft shipped it in VS Code, and MCP servers from Asana, Atlassian, Figma, Linear and Supabase support it at launch. EMA fixes something real. Before it, the typical enterprise pattern was a shared service account with a long-lived token in a .env file. No audit trail, no role scoping, no revocation path. EMA replaces that with IdP-governed access: group membership, conditional access rules, deprovisioning on offboarding. For anyone running agents in an enterprise, this is the most important practical improvement since my original article. What EMA answers is which humans in this org may connect to which servers. What it doesn&apos;t answer is which agent instance received which delegated authority to perform which specific action inside a chain of tools. Provisioning and governance improved dramatically. Per-action, per-instance identity did not. Research went where the protocols don&apos;t reach While the protocols hardened their edges, academic work attacked the middle. Two papers stand out. PAuth (arXiv 2603.17170, March 17) goes straight at overprivilege. Its argument: OAuth scopes are bound to operators, not operations. If your agent needs to transfer $100 to Bob, OAuth forces you to grant a blanket TRANSFER permission that covers any amount to any recipient. PAuth proposes task-scoped implicit authorization instead. Submitting a natural-language task authorizes only the concrete operations required to execute it faithfully. In the AgentDojo evaluation, all benign tasks complete without extra permissions and all injected attack operations trigger warnings, with zero false positives and zero false negatives. This is the operation-level policy layer I sketched in March, now with a working prototype. AIP (arXiv 2603.24775, March 25) is the most direct confirmation of the original thesis. The paper states that neither MCP nor A2A natively verifies agent identity, and cites a Knostic scan of roughly 2,000 internet-exposed MCP servers in which every single one lacked authentication. Its answer is Invocation-Bound Capability Tokens: an append-only chain that fuses identity, attenuated authorization and provenance into one cryptographic artifact, with bindings for MCP, A2A and plain HTTP. The measured overhead is 2.35ms in a real multi-agent deployment, 0.086% of end-to-end latency, with a 100% rejection rate across 600 adversarial attempts. AIP is now also an IETF Internet-Draft, which tells you where this conversation is heading. Around these two, a broader research cluster is forming: decentralized identity approaches built on DIDs and verifiable credentials, IETF drafts on attenuating authorization tokens for delegation chains, and work reframing the problem from &quot;who are you&quot; to &quot;what portable authority can you prove&quot;. None of it is deployed at scale. All of it targets the layers the protocols still leave open. Scoring my March claims The original article made five claims. This is how they held up. Agents don&apos;t fit the identity models for humans, services or bots. Confirmed. Every serious paper published since starts from this exact insufficiency and proposes agent-specific frameworks. Agents don&apos;t fit the identity models for humans, services or bots. Agents don&apos;t fit the identity models for humans, services or bots. Delegation on behalf of a user is badly modeled*.* Confirmed, with nuance. MCP&apos;s authorization is still built on standard OAuth 2.1 flows. EMA improves the enterprise operation of those flows enormously without introducing universal agentic identity. Better plumbing, same conceptual gap. Delegation on behalf of a user is badly modeled Delegation on behalf of a user is badly modeled Multi-tool composition creates emergent privileges nobody approved. Confirmed and expanded. MCP elevated tool annotations as a risk vocabulary, threat modeling work flagged tool poisoning as a critical client-side vulnerability, and A2A added in-task authorization. The ecosystem now agrees this is where attacks live. Multi-tool composition creates emergent privileges nobody approved. Multi-tool composition creates emergent privileges nobody approved. You can&apos;t reliably audit who did what*.* Partially mitigated. Signed Agent Cards and AIP-style completion records add provenance. There is still no dominant standard for per-instance audit across stacks. You can&apos;t reliably audit who did what You can&apos;t reliably audit who did what The fix is a layered stack, not a single patch. Confirmed. MCP is building the authorization layer. A2A is building declarative identity and inter-agent trust. Research is building task scoping, verifiable delegation and portable authority. Nobody is shipping one magic fix, because there isn&apos;t one. The fix is a layered stack, not a single patch. The fix is a layered stack, not a single patch. The right question for July 2026 The question is no longer whether agents have an identity crisis. They do, and now everyone from protocol maintainers to IETF draft authors says so in writing. The right question is which parts of the stack finally exist and which parts remain aspirational. My answer today: enterprise authorization for MCP exists and works. A serious foundation for inter-agent trust exists in A2A v1.0. Measured proposals exist for task scoping and verifiable delegation. What still doesn&apos;t exist is the layer that binds them into an interoperable default: identity per running instance, authority that attenuates correctly across multi-hop delegation and provenance you can audit end to end without trusting every intermediary. In March I wrote that the best time to close this gap was before deployment, and the second best time was now. That line deserves an update. We&apos;re no longer starting from zero. We&apos;re starting from an ecosystem that finally admits, in specs and in code, that an agent can&apos;t keep being treated as a weird user or as just another service. An agent needs verifiable identity, bounded authority and auditable provenance. Until that&apos;s the default behavior in production, the crisis hasn&apos;t ended. It has started to professionalize. References Original article: AI Agents Don&apos;t Have Identities, and That&apos;s a Security Crisis (HackerNoon, March 2026)\\nThe 2026 MCP Roadmap (MCP Blog, March 9, 2026)\\nA2A Protocol v1.0 announcement and What&apos;s New in v1.0\\nPAuth: Precise Task-Scoped Authorization For Agents (arXiv, March 17, 2026)\\nAIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A (arXiv, March 25, 2026) and IETF draft-prakash-aip\\nThe 2026-07-28 MCP Specification Release Candidate (MCP Blog, May 21, 2026)\\nEnterprise-Managed Authorization: Zero-touch OAuth for MCP (MCP Blog, June 18, 2026) Original article: AI Agents Don&apos;t Have Identities, and That&apos;s a Security Crisis (HackerNoon, March 2026) AI Agents Don&apos;t Have Identities, and That&apos;s a Security Crisis The 2026 MCP Roadmap (MCP Blog, March 9, 2026) The 2026 MCP Roadmap A2A Protocol v1.0 announcement and What&apos;s New in v1.0 A2A Protocol v1.0 announcement What&apos;s New in v1.0 PAuth: Precise Task-Scoped Authorization For Agents (arXiv, March 17, 2026) PAuth: Precise Task-Scoped Authorization For Agents AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A (arXiv, March 25, 2026) and IETF draft-prakash-aip AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A IETF draft-prakash-aip The 2026-07-28 MCP Specification Release Candidate (MCP Blog, May 21, 2026) The 2026-07-28 MCP Specification Release Candidate Enterprise-Managed Authorization: Zero-touch OAuth for MCP (MCP Blog, June 18, 2026) Enterprise-Managed Authorization: Zero-touch OAuth for MCP\"}</script><link href=\"https://fonts.googleapis.com/css2?family=IBM+Plex+Mono:wght@400;700&amp;family=IBM+Plex+Sans:wght@400;700&amp;family=Inter:wght@400;600;900&amp;family=Source+Code+Pro:wght@400;500;600;700&amp;display=swap\" rel=\"stylesheet\" media=\"print\"/><noscript><link href=\"https://fonts.googleapis.com/css2?family=IBM+Plex+Mono:wght@400;700&amp;family=IBM+Plex+Sans:wght@400;700&amp;family=Inter:wght@400;600;900&amp;family=Source+Code+Pro:wght@400;500;600;700&amp;display=swap\" rel=\"stylesheet\"/></noscript> <!-- --><script id=\"ga4-init\">\n                window.dataLayer = window.dataLayer || [];\n                function gtag(){dataLayer.push(arguments);}\n\n                // Consent Mode: default to denied\n                gtag('consent', 'default', {\n                  'ad_storage': 'denied',\n                  'analytics_storage': 'denied',\n                  'ad_user_data': 'denied',\n                  'ad_personalization': 'denied'\n                });\n\n                gtag('js', new Date());\n                gtag('config', 'G-ECJJ2Q2SJQ');\n              </script><script id=\"iubenda-init\">\n                function initIubenda() {\n                  (async function () {\n                    try {\n                      const res = await fetch(\"https://geolocation-db.com/json/\");\n                      const data = await res.json();\n                      const country = data && data.country_code;\n\n                      const GDPR_COUNTRIES = [\n                        \"AT\",\"BE\",\"BG\",\"HR\",\"CY\",\"CZ\",\"DK\",\"EE\",\"FI\",\"FR\",\"DE\",\"GR\",\"HU\",\n                        \"IE\",\"IT\",\"LV\",\"LT\",\"LU\",\"MT\",\"NL\",\"PL\",\"PT\",\"RO\",\"SK\",\"SI\",\"ES\",\n                        \"SE\",\"IS\",\"LI\",\"NO\",\"UK\",\"GB\"\n                      ];\n                      var isGdpr = GDPR_COUNTRIES.indexOf(country) > -1;\n\n                      window._iub = window._iub || [];\n                      window._iub.csConfiguration = {\n                        siteId: 1848357,\n                        cookiePolicyId: 18778700,\n                        lang: \"en\",\n                        enableTcf: false,\n                        googleAdditionalConsentMode: true,\n                        banner: {\n                          position: \"bottom\",\n                          rejectButtonDisplay: true,\n                          explicitWithdrawal: true,\n                          customizeButtonDisplay: true,\n                          acceptButtonDisplay: true,\n                          showTotalNumberOfProviders: false,\n                          display: isGdpr\n                        }\n                      };\n\n                      var iubScript = document.createElement(\"script\");\n                      iubScript.src = \"https://cdn.iubenda.com/cs/iubenda_cs.js\";\n                      iubScript.async = true;\n                      document.head.appendChild(iubScript);\n\n                      if (!isGdpr) {\n                        gtag('consent', 'update', {\n                          'ad_storage': 'granted',\n                          'analytics_storage': 'granted',\n                          'ad_user_data': 'granted',\n                          'ad_personalization': 'granted'\n                        });\n                      }\n                    } catch (e) {\n                      console.error(\"Iubenda geolocation failed\", e);\n                    }\n                  })();\n                }\n\n                // Defer until browser is idle — never blocks initial render\n                if (typeof requestIdleCallback !== 'undefined') {\n                  requestIdleCallback(initIubenda, { timeout: 3000 });\n                } else {\n                  setTimeout(initIubenda, 1000);\n                }\n              </script><script id=\"iubenda-consent-bridge\">\n                window.addEventListener(\"iubenda_consent_given\", function () {\n                  gtag('consent', 'update', {\n                    'ad_storage': 'granted',\n                    'analytics_storage': 'granted',\n                    'ad_user_data': 'granted',\n                    'ad_personalization': 'granted'\n                  });\n\n                  gtag('event', 'page_view', {\n                    page_title: document.title,\n                    page_location: location.href,\n                    page_path: location.pathname + location.search\n                  });\n                });\n              </script><link rel=\"stylesheet\" href=\"/_next/static/css/7830fe1600a03696.css\" data-n-g=\"\"/><link rel=\"stylesheet\" href=\"/_next/static/css/6d530d6069fd563f.css\" data-n-p=\"\"/><noscript data-n-css=\"\"></noscript><script defer=\"\" noModule=\"\" src=\"/_next/static/chunks/polyfills-42372ed130431b0a.js\"></script><script src=\"https://accounts.google.com/gsi/client\" defer=\"\" data-nscript=\"beforeInteractive\"></script><script defer=\"\" src=\"/_next/static/chunks/7618.5fb36eb1ea44922b.js\"></script><script defer=\"\" src=\"/_next/static/chunks/3213.16a90dca5589ecdb.js\"></script><script defer=\"\" src=\"/_next/static/chunks/7127.9c425c4d3409a6ac.js\"></script><script defer=\"\" src=\"/_next/static/chunks/3304.7c3523eee5ba4042.js\"></script><script defer=\"\" src=\"/_next/static/chunks/1826.1ab3736f712279dc.js\"></script><script defer=\"\" src=\"/_next/static/chunks/b6790ad6-21a72b711b29c9a6.js\"></script><script defer=\"\" src=\"/_next/static/chunks/4829-32ed3fa27f9fba8a.js\"></script><script defer=\"\" src=\"/_next/static/chunks/8145-56bb137bc815feca.js\"></script><script defer=\"\" src=\"/_next/static/chunks/7878-038a9b85114cf28d.js\"></script><script defer=\"\" src=\"/_next/static/chunks/9407-02afcd7299ecf2e9.js\"></script><script defer=\"\" src=\"/_next/static/chunks/7655-0d56fc045e3c1152.js\"></script><script defer=\"\" src=\"/_next/static/chunks/997.043403d1cfb4d583.js\"></script><script defer=\"\" src=\"/_next/static/chunks/5002.9a46a38e3395b49b.js\"></script><script defer=\"\" src=\"/_next/static/chunks/9752.24e18fe088b9acb7.js\"></script><script defer=\"\" src=\"/_next/static/chunks/1486.6875746f7e7b3bd6.js\"></script><script defer=\"\" src=\"/_next/static/chunks/2348.6ff1c8ab2b7f714e.js\"></script><script src=\"/_next/static/chunks/webpack-90065ae3dc1ee893.js\" defer=\"\"></script><script src=\"/_next/static/chunks/framework-594babcea68f40f6.js\" defer=\"\"></script><script src=\"/_next/static/chunks/main-f4c6b80eccf8d9c3.js\" defer=\"\"></script><script src=\"/_next/static/chunks/pages/_app-20fc6ac6544e0ced.js\" defer=\"\"></script><script src=\"/_next/static/chunks/4004-46cbf9060446c734.js\" defer=\"\"></script><script src=\"/_next/static/chunks/3363-3997af8403818196.js\" defer=\"\"></script><script src=\"/_next/static/chunks/8230-f743aded49f5ec53.js\" defer=\"\"></script><script src=\"/_next/static/chunks/5594-72de39eaed860f55.js\" defer=\"\"></script><script src=\"/_next/static/chunks/7871-2033514d4a1687fa.js\" defer=\"\"></script><script src=\"/_next/static/chunks/3261-28f7d7d5ddf137c8.js\" defer=\"\"></script><script src=\"/_next/static/chunks/1902-922299f711a16f76.js\" defer=\"\"></script><script src=\"/_next/static/chunks/8581-1c63d69fe79360dc.js\" defer=\"\"></script><script src=\"/_next/static/chunks/4680-044548c650fd83e7.js\" defer=\"\"></script><script src=\"/_next/static/chunks/2562-5aa3cd1aa6e464a5.js\" defer=\"\"></script><script src=\"/_next/static/chunks/8373-1c61bad6a8e1fdcb.js\" defer=\"\"></script><script src=\"/_next/static/chunks/7701-92913481d8f90585.js\" defer=\"\"></script><script src=\"/_next/static/chunks/7225-9872d2a57af3718c.js\" defer=\"\"></script><script src=\"/_next/static/chunks/pages/%5Bslug%5D-09b2527556e14fc2.js\" defer=\"\"></script><script src=\"/_next/static/Xk2r7uR-ZJNVqZdnbVuTv/_buildManifest.js\" defer=\"\"></script><script src=\"/_next/static/Xk2r7uR-ZJNVqZdnbVuTv/_ssgManifest.js\" defer=\"\"></script></head><body><link rel=\"preload\" as=\"image\" imageSrcSet=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=640 640w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=750 750w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=828 828w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=1080 1080w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=1200 1200w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=1920 1920w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=2048 2048w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=3840 3840w\" imageSizes=\"(max-width: 768px) 100vw, 1200px\" fetchPriority=\"high\"/><link rel=\"preload\" as=\"image\" href=\"https://hackernoon.imgix.net/avatars/robot-b5.png\"/><link rel=\"preload\" as=\"image\" href=\"https://hackernoon.imgix.net/avatars/robot-b6.png\"/><div id=\"__next\"><div class=\"bg-light text-lightText font-[ibm-plex-mono]\"><main><header class=\"font-[ibm-plex-sans] fixed top-0 left-0 w-full z-50 transition-all duration-500 ease-in-out translate-y-0\"><div class=\"flex items-center justify-between bg-primary  lg:navbar h-[50px] sm:min-h-[75px] transition-all duration-100 shadow-md  w-full\"><div class=\"hidden lg:flex navbar-start h-full items-center ml-1\"><button class=\"flex items-center hover:scale-[1.01]  justify-center rounded-lg text-base px-4 font-bold py-2 border-none  bg-primary-content text-primaryContentText\">Discover Anything<i class=\"hn hn-search text-lg ml-4 text-primaryContentText \"></i></button></div><div class=\"nav-start lg:navbar-center ml-2 lg:ml-0 min-w-0 flex-shrink\"><a href=\"/\" class=\"relative z-10 flex items-center space-x-2 hover:scale-[1.02]\" aria-label=\"HackerNoon Homepage\"><svg class=\"w-[180px] xs:w-[200px] sm:w-[240px] lg:w-[260px] h-auto\" viewBox=\"0 0 2150 260\" fill=\"none\" xmlns=\"http://www.w3.org/2000/svg\" preserveAspectRatio=\"xMidYMid meet\" style=\"transition:fill 150ms ease\"><g style=\"transition:fill 150ms ease\"><path d=\"M269.997 20.0005V0H130V20.0005V40.0011V60.0016H150H169.995V40.0011H189.995H229.996V60.0016H249.997H269.997V40.0011V20.0005Z\" fill=\"transparent\"></path><path d=\"M130.006 80.003V60.0024H110.006V80.003V100.004H130.006V80.003Z\" fill=\"transparent\"></path><path d=\"M110 119.998V100.003H90V119.998V139.998V159.999H110V139.998V119.998Z\" fill=\"transparent\"></path><path d=\"M270 100.004H290V80.003V60.0024H270V80.003V100.004Z\" fill=\"transparent\"></path><path d=\"M310 119.997V100.002H290V119.997V139.998V159.998H310V139.998H330.001V119.997H310Z\" fill=\"transparent\"></path><path d=\"M130 159.998H110V179.998V199.999H130V179.998V159.998Z\" fill=\"transparent\"></path><path d=\"M270 179.998V199.999H290V179.998V159.998H270V179.998Z\" fill=\"transparent\"></path><path d=\"M130 260V240V219.999V199.999H150H169.995V219.999H189.995H209.996H229.996V199.999H249.997H269.997V219.999V240V260H130Z\" fill=\"transparent\"></path><path d=\"M210.415 39.74V59.7405V79.7411V99.7416V119.736V139.737H190.415V119.736V99.7416V79.7411V59.7405V39.74H210.415Z\" fill=\"transparent\"></path><path d=\"M390 200V60H417.801V116.676H501.206V60H530V200H501.206V144.517H417.801V200H390Z\" fill=\"transparent\"></path><path d=\"M672.199 116.676V88.8352H588.794V116.676H672.199ZM560 200V60H700V200H672.199V144.517H588.794V200H560Z\" fill=\"transparent\"></path><path d=\"M730 200V60H870V88.8352H758.794V172.159H870V200H730Z\" fill=\"transparent\"></path><path d=\"M900 200V60H928.794V116.276H984.397V143.724H928.794V200H900ZM1012.2 171.368H984.397V143.724H1012.2V171.368ZM1012.2 171.368H1040V199.013H1012.2V171.368ZM1012.2 88.6319V116.276H984.397V88.6319H1012.2ZM1012.2 88.6319V60H1040V88.6319H1012.2Z\" fill=\"transparent\"></path><path d=\"M1070 200V60H1210V88.8352H1098.79V116.676H1154.4V144.517H1098.79V172.159H1210V200H1070Z\" fill=\"transparent\"></path><path d=\"M1351.24 116.519V88.7589H1267.76V116.519H1351.24ZM1240 200V60H1380V144.479H1351.24V172.24H1380V200H1351.24V172.24H1323.48V144.479H1267.76V200H1240Z\" fill=\"transparent\"></path><path d=\"M1410 200V60H1550V200H1522.24V88.7589H1438.76V200H1410Z\" fill=\"transparent\"></path><path d=\"M1692.24 172.24V88.7589H1608.76V172.24H1692.24ZM1580 200V60H1720V200H1580Z\" fill=\"transparent\"></path><path d=\"M1862.04 172.24V88.7589H1778.97V172.24H1862.04ZM1750 200V60H1890V200H1750Z\" fill=\"transparent\"></path><path d=\"M1920 200V60H2060V200H2032.24V88.7589H1948.76V200H1920Z\" fill=\"transparent\"></path></g></svg></a></div><div class=\"navbar-end h-full flex items-center min-w-[100px] lg:min-w-[200px] space-x-4 mr-2\"><div class=\" h-[40px] flex items-center justify-center\"></div><div class=\"hidden sm:flex space-x-4   \"><button class=\"px-4 font-bold text-base py-1 sm:py-2 bg-primary-content text-primaryContentText rounded-md transition-all duration-300\">Signup</button><a href=\"/new\" class=\"px-4 hover:scale-105 font-bold text-base py-2  bg-primary-content text-primaryContentText rounded-md \">Write</a></div><button class=\"btn border-none p-0 m-0 lg:hidden bg-transparent hover:bg-transparent text-primary-content hover:scale-110\"><i class=\"hn hn-search text-xl mr-2 \"></i></button><button class=\"lg:flex hidden items-center hover:scale-110 text-primary-content\" aria-label=\"Notifications\"><i width=\"20\" class=\"hn hn-bell text-2xl w-4 h-4 sm:w-6 sm:h-6\"></i></button><button class=\"flex items-center hover:scale-110 text-primary-content\" aria-label=\"Menu\"><i class=\"hn hn-bars text-2xl text-primary-content\"></i></button></div></div><div class=\"z-20 hidden lg:block h-[52px] transition-all duration-500 ease-in-out\"><nav class=\"h-[52px] bg-secondary animate-pulse\"></nav></div><div class=\"flex items-center \"><div class=\"bg-accent text-accent-content flex items-center h-[62px] sm:min-h-[80px]  font-[ibm-plex-sans] w-full  relative z-10 opacity-100\"><div class=\"h-[62px] sm:h-[80px] bg-[transparent] animate-pulse\"></div></div></div></header><div class=\"transition-all duration-200 pt-[112px] sm:pt-[155px] lg:pt-[207px]\"><div data-rht-toaster=\"\" style=\"position:fixed;z-index:9999;top:16px;left:16px;right:16px;bottom:16px;pointer-events:none\"></div><div class=\"\"><div class=\"bg-light text-lightText  h-auto xl:mx-2 \"><div class=\"col-span-12\"><div class=\"max-w-[1200px] mx-auto px-2 xs:px-4  xl: xl:px-0 mt-10\"><div class=\"\"><div><div class=\"text-xs\"><div class=\"mb-4 flex gap-2\"><span class=\"bg-lightAlt p-2 rounded-lg inline-flex gap-2 items-center justify-start\"><i class=\"hn hn-star-solid\"></i> <!-- -->2,419<!-- --> <!-- -->reads</span></div><h1 class=\"font-bold line-clamp-4 leading-snug text-lightTextStrong \n              text-xl sm:text-2xl xl:text-3xl 3xl:text-4xl tracking-wide\n\n                \">The Identity Layer for AI Agents Is Finally Being Built</h1><div class=\"flex flex-wrap border-y border-lightBorder my-4 sm:my-2 sm:border-t-0 py-2 items-center justify-between text-lightTextLight text-sm sm:text-base xl:text-xl \"><div class=\"flex flex-wrap justify-between w-full xs:w-auto  items-center gap-2\"><span class=\"flex items-center  flex-wrap gap-2 mr-10 sm:mr-0 \">by<div class=\"dropdown dropdown-hover \"><label tabindex=\"0\"><a aria-label=\"View profile of Gus Aragón\" href=\"/u/garagon\"><strong class=\"...\">Gus Aragón</strong></a></label><div class=\"dropdown-content z-[1] pt-2 sm:pt-1 left-[-40px] w-[280px] xs:w-[320px] sm:w-[400px] bg-transparent menu rounded \"><div class=\"w-full   \"><div class=\" p-4 border border-lightBorder bg-light rounded-lg\"><a href=\"/u/garagon\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"flex items-start text-sm rounded-lg group gap-2\"><div class=\"\"><img alt=\"Gus Aragón\" loading=\"lazy\" width=\"40\" height=\"40\" decoding=\"async\" data-nimg=\"1\" class=\"w-10 h-9 border-solid border border-lightBorder rounded-full object-contain\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=48 1x, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=96 2x\" src=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=96\"/></div><span class=\"flex flex-col min-w-0 w-full justify-center\"><span class=\"flex items-center gap-1 text-ellipsis overflow-hidden whitespace-nowrap\"><span class=\"font-bold group-hover:underline text-sm truncate\"><span class=\"text-xs font-light mr-1\">by</span>Gus Aragón</span><span class=\"text-xs font-light opacity-50\">|</span><span class=\"text-sm false text-ellipsis overflow-hidden whitespace-nowrap\" title=\"@garagon\">@<!-- -->garagon</span></span><span class=\"text-xs text-ellipsis overflow-hidden whitespace-nowrap mt-0.5\" title=\"Founder at Oktsec.com\">Founder<!-- --> at <!-- -->Oktsec.com</span></span></a><p class=\"text-sm overflow-x-auto mt-2 text-bodyTxtLight\">Founder @ Oktsec | Security for AI agent work | AAIF Ambassador | Cybersecurity | Open Source</p><div class=\"mt-4\"><div class=\"w-full flex justify-start\"><div class=\"w-full\"><form class=\"w-full flex flex-col items-start gap-2 \"><div class=\"flex w-full\"><input class=\"p-2 flex-grow  border rounded-l-md text-lightText bg-light focus:outline-none focus:ring-0 focus:ring-transparent border-lightBorder w-full text-base px-2} \n                  }\" placeholder=\"name@company.com\" type=\"email\" required=\"\" name=\"email\" value=\"\"/><button type=\"submit\" class=\"text-base} \n                bg-lightAlt border border-l-0 border-lightBorder hover:bg-green-700 text-lightText hover:bg-dark hover:text-darkText  px-2 py-1 rounded-r-md  font-bold\">Subscribe</button></div></form></div></div></div></div></div></div></div></span><div class=\"flex gap-2 items-center cursor-pointer\"><span class=\"hidden sm:block w-1 h-1 bg-lightTextLight mx-4 rounded-full\"></span><a href=\"/archives/2026/07/11\"><span class=\"text-xs xs:text-sm lg:text-base\">July 11th, 2026</span></a></div></div><div class=\"hidden xl:block\"><div class=\" flex items-center gap-4 \"><span class=\"tooltip tooltip-left tooltip-left  w-7 h-7 flex items-center justify-center  cursor-pointer\" data-tip=\"Terminal Reader\"><img alt=\"Read on Terminal Reader\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/computer.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/computer.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/computer.png?auto=format%2Ccompress&amp;w=48\"/></span><span class=\"tooltip tooltip-left tooltip-left  w-7 h-7 flex items-center justify-center  cursor-pointer\" data-tip=\"Print this story\"><img alt=\"Print this story\" data-tip=\"true\" data-for=\"print-page\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/Print%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/Print%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/Print%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=48\"/></span><span class=\"tooltip tooltip-left tooltip-left   w-7 h-7 flex items-center justify-center cursor-pointer\" data-tip=\"Read this story w/o Javascript\"><img alt=\"Read this story w/o Javascript\" data-tip=\"true\" data-for=\"arweave-backup\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/Lite%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/Lite%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/Lite%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=48\"/></span></div></div></div></div><div class=\"mb-2 \"><div class=\"flex justify-between  \"><button class=\"flex m-1 px-2 xl:px-4 h-[40px] items-center font-[hackernoon2] bg-dark text-darkText  text-xs sm:text-sm rounded-lg border border-lightBorder\">TLDR <i class=\"hn hn-angle-right text-base ml-1 \"></i></button><div class=\"flex items-center gap-2\"><div class=\"hidden sm:block xl:hidden\"><div class=\" flex items-center gap-4 \"><span class=\"tooltip tooltip-left undefined  w-7 h-7 flex items-center justify-center  cursor-pointer\" data-tip=\"Terminal Reader\"><img alt=\"Read on Terminal Reader\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/computer.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/computer.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/computer.png?auto=format%2Ccompress&amp;w=48\"/></span><span class=\"tooltip tooltip-left undefined  w-7 h-7 flex items-center justify-center  cursor-pointer\" data-tip=\"Print this story\"><img alt=\"Print this story\" data-tip=\"true\" data-for=\"print-page\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/Print%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/Print%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/Print%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=48\"/></span><span class=\"tooltip tooltip-left undefined   w-7 h-7 flex items-center justify-center cursor-pointer\" data-tip=\"Read this story w/o Javascript\"><img alt=\"Read this story w/o Javascript\" data-tip=\"true\" data-for=\"arweave-backup\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/Lite%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/Lite%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/Lite%20Icon%20%4025px.png?auto=format%2Ccompress&amp;w=48\"/></span></div></div><div class=\"dropdown dropdown-bottom dropdown-hover dropdown-end xl:hidden\"><label tabindex=\"0\" class=\"border border-lightBorder p-2 rounded m-1 flex items-center gap-2 cursor-pointer text-xs\">Translations <i class=\"hn hn-translate text-xl\"></i></label><div tabindex=\"0\" class=\"dropdown-content z-20 bg-light border border-lightBorder shadow rounded w-32 max-h-[300px] overflow-y-auto overscroll-contain\"><ul class=\"menu menu-compact p-1\"><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"English\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-lightAccent text-lightAccentText\" href=\"/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"en-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/usa_flag.webp?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/usa_flag.webp?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/usa_flag.webp?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">EN</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Russian\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/ru/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"ru-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/russian_uchb3r98.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/russian_uchb3r98.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/russian_uchb3r98.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">RU</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Korean\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/ko/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"ko-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/korean_rceor8o8.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/korean_rceor8o8.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/korean_rceor8o8.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">KO</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Spanish\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/es/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"es-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/spain_flag.webp?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/spain_flag.webp?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/spain_flag.webp?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">ES</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Chinese\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/zh/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"zh-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/chinese_vri67rp8.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/chinese_vri67rp8.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/chinese_vri67rp8.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">ZH</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"French\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/fr/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"fr-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/fr_flag.webp?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/fr_flag.webp?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/fr_flag.webp?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">FR</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Japanese\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/ja/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"ja-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/japanese_20jtajj.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/japanese_20jtajj.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/japanese_20jtajj.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">JA</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Croatian\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/hr/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"hr-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/croatian_bmb27tbg.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/croatian_bmb27tbg.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/croatian_bmb27tbg.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">HR</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Pashto\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/ps/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"ps-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/afghanistan.jpg?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/afghanistan.jpg?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/afghanistan.jpg?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">PS</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Greek\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/el/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"el-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/greek_696idl18.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/greek_696idl18.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/greek_696idl18.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">EL</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Catalan\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/ca/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"ca-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/catalan_vidt0k2g.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/catalan_vidt0k2g.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/catalan_vidt0k2g.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">CA</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Belarusian\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/be/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"be-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/belarusian_68crd5o8.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/belarusian_68crd5o8.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/belarusian_68crd5o8.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">BE</span></a></li><li class=\"mx-1 tooltip tooltip-left\" data-tip=\"Lao\"><a class=\"lang border border-transparent hover:text-lightTextStrong\n                                                          bg-light\" href=\"/lang/lo/the-identity-layer-for-ai-agents-is-finally-being-built\"><img alt=\"lo-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/lao_plfjm3t.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/lao_plfjm3t.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/lao_plfjm3t.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"ml-1 text-sm\">LO</span></a></li></ul></div></div><div class=\"xl:hidden\"></div></div><div class=\"hidden xl:flex items-center flex-wrap gap-2\"><a href=\"/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-lightAlt border-lightText\" data-tip=\"English\"><img alt=\"en-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/usa_flag.webp?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/usa_flag.webp?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/usa_flag.webp?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">EN</span></a><a href=\"/lang/ru/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Russian\"><img alt=\"ru-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/russian_uchb3r98.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/russian_uchb3r98.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/russian_uchb3r98.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">RU</span></a><a href=\"/lang/ko/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Korean\"><img alt=\"ko-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/korean_rceor8o8.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/korean_rceor8o8.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/korean_rceor8o8.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">KO</span></a><a href=\"/lang/es/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Spanish\"><img alt=\"es-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/spain_flag.webp?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/spain_flag.webp?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/spain_flag.webp?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">ES</span></a><a href=\"/lang/zh/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Chinese\"><img alt=\"zh-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/chinese_vri67rp8.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/chinese_vri67rp8.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/chinese_vri67rp8.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">ZH</span></a><a href=\"/lang/fr/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"French\"><img alt=\"fr-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/fr_flag.webp?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/fr_flag.webp?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/fr_flag.webp?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">FR</span></a><a href=\"/lang/ja/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Japanese\"><img alt=\"ja-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/japanese_20jtajj.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/japanese_20jtajj.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/japanese_20jtajj.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">JA</span></a><a href=\"/lang/hr/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Croatian\"><img alt=\"hr-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/croatian_bmb27tbg.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/croatian_bmb27tbg.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/croatian_bmb27tbg.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">HR</span></a><a href=\"/lang/ps/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Pashto\"><img alt=\"ps-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/afghanistan.jpg?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/images/afghanistan.jpg?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/images/afghanistan.jpg?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">PS</span></a><a href=\"/lang/el/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Greek\"><img alt=\"el-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/greek_696idl18.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/greek_696idl18.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/greek_696idl18.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">EL</span></a><a href=\"/lang/ca/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Catalan\"><img alt=\"ca-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/catalan_vidt0k2g.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/catalan_vidt0k2g.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/catalan_vidt0k2g.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">CA</span></a><a href=\"/lang/be/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip  \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Belarusian\"><img alt=\"be-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/belarusian_68crd5o8.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/belarusian_68crd5o8.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/belarusian_68crd5o8.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">BE</span></a><a href=\"/lang/lo/the-identity-layer-for-ai-agents-is-finally-being-built\" class=\"flex gap-2 tooltip tip-r-10 \n                                                     px-2 py-1 rounded h-[30px] border items-center \n                                                     bg-light hover:bg-lightAlt border-lightBorder\" data-tip=\"Lao\"><img alt=\"lo-flag\" loading=\"lazy\" width=\"20\" height=\"20\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-full\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/flags/lao_plfjm3t.png?auto=format%2Ccompress&amp;w=32 1x, https://hackernoon.imgix.net/flags/lao_plfjm3t.png?auto=format%2Ccompress&amp;w=48 2x\" src=\"https://hackernoon.imgix.net/flags/lao_plfjm3t.png?auto=format%2Ccompress&amp;w=48\"/><span class=\"text-sm\">LO</span></a></div></div></div></div></div></div><div class=\"max-w-[1200px] mx-auto\"><div class=\"flex items-center justify-center w-full h-full\"><div class=\"relative group cursor-zoom-in transition-transform hover:scale-[1.01] max-w-full mx-auto px-[14px] md:px-0 w-full\"><button class=\"absolute top-2 right-5 z-10 w-6 h-6 rounded  flex items-center justify-center opacity-0 group-hover:opacity-100 transition-opacity\"><i class=\"hn hn-download text-darkText bg-dark p-2 rounded-xl text-base\"></i></button><img alt=\"featured image - The Identity Layer for AI Agents Is Finally Being Built\" fetchPriority=\"high\" loading=\"eager\" width=\"1672\" height=\"941\" decoding=\"async\" data-nimg=\"1\" class=\"w-full h-auto object-contain rounded-lg shadow-lg my-0\" style=\"color:transparent;background-size:cover;background-position:50% 50%;background-repeat:no-repeat;background-image:url(&quot;data:image/svg+xml;charset=utf-8,%3Csvg xmlns=&#x27;http://www.w3.org/2000/svg&#x27; viewBox=&#x27;0 0 1672 941&#x27;%3E%3Cfilter id=&#x27;b&#x27; color-interpolation-filters=&#x27;sRGB&#x27;%3E%3CfeGaussianBlur stdDeviation=&#x27;20&#x27;/%3E%3CfeColorMatrix values=&#x27;1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 100 -1&#x27; result=&#x27;s&#x27;/%3E%3CfeFlood x=&#x27;0&#x27; y=&#x27;0&#x27; width=&#x27;100%25&#x27; height=&#x27;100%25&#x27;/%3E%3CfeComposite operator=&#x27;out&#x27; in=&#x27;s&#x27;/%3E%3CfeComposite in2=&#x27;SourceGraphic&#x27;/%3E%3CfeGaussianBlur stdDeviation=&#x27;20&#x27;/%3E%3C/filter%3E%3Cimage width=&#x27;100%25&#x27; height=&#x27;100%25&#x27; x=&#x27;0&#x27; y=&#x27;0&#x27; preserveAspectRatio=&#x27;none&#x27; style=&#x27;filter: url(%23b);&#x27; href=&#x27;data:image/svg+xml;base64,CiAgICA8c3ZnIHdpZHRoPSIxNjcyIiBoZWlnaHQ9Ijk0MSIgdmVyc2lvbj0iMS4xIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIj4KICAgICAgPGRlZnM+CiAgICAgICAgPGxpbmVhckdyYWRpZW50IGlkPSJnIj4KICAgICAgICAgIDxzdG9wIHN0b3AtY29sb3I9IiMyMjIiIG9mZnNldD0iMjAlIiAvPgogICAgICAgICAgPHN0b3Agc3RvcC1jb2xvcj0iIzBmMCIgb2Zmc2V0PSI1MCUiIC8+CiAgICAgICAgICA8c3RvcCBzdG9wLWNvbG9yPSIjMjIyIiBvZmZzZXQ9IjgwJSIgLz4KICAgICAgICA8L2xpbmVhckdyYWRpZW50PgogICAgICA8L2RlZnM+CiAgICAgIDxyZWN0IHdpZHRoPSIxNjcyIiBoZWlnaHQ9Ijk0MSIgZmlsbD0iIzIyMiIgLz4KICAgICAgPHJlY3QgaWQ9InIiIHdpZHRoPSIxNjcyIiBoZWlnaHQ9Ijk0MSIgZmlsbD0idXJsKCNnKSIgLz4KICAgICAgPGFuaW1hdGUgeGxpbms6aHJlZj0iI3IiIGF0dHJpYnV0ZU5hbWU9IngiIGZyb209Ii0xNjcyIiB0bz0iMTY3MiIgZHVyPSIxcyIgcmVwZWF0Q291bnQ9ImluZGVmaW5pdGUiICAvPgogICAgPC9zdmc+&#x27;/%3E%3C/svg%3E&quot;)\" sizes=\"(max-width: 768px) 100vw, 1200px\" srcSet=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=640 640w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=750 750w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=828 828w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=1080 1080w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=1200 1200w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=1920 1920w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=2048 2048w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=3840 3840w\" src=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png?auto=format%2Ccompress&amp;w=3840\"/></div></div></div><div class=\"px-2 xs:px-4 3xl:px-0 my-4 sm:mt-4 sm:mb-6 max-w-[1200px] 6xl:max-w-[1200px] mx-auto \"><div class=\"w-full flex flex-col justify-center rounded-lg\"><audio src=\"https://storage.googleapis.com/hackernoon/audios/6a45bd39acdf1c8e2e7d18d3-en-US-Wavenet-I-MALE--3d47727880fa8.mp3\" preload=\"metadata\">Your browser does not support the <code>audio</code> element.</audio><div class=\"hidden sm:flex justify-between items-center \"><span></span></div><div class=\"flex gap-2 items-center\"><div class=\"flex items-center  justify-center mx-auto gap-2 xs:gap-4 lg:gap-6 flex-1\"><button aria-label=\"play/pause\" class=\"text-darkAccent max-w-[40px] max-h-[40px] sm:min-w-[48px] sm:min-h-[48px] border order-1 border-darkBorder bg-dark p-2 rounded-full flex items-center justify-center\" title=\"Play/Pause\"><i class=\"hn hn-play-solid text-base xs:text-lg sm:text-2xl \"></i></button><div class=\"dropdown order-2  dropdown-hover\"><label tabindex=\"0\" class=\"flex items-center hn hn-playlist-solid text-base xs:text-lg sm:text-xl lg:text-2xl rounded-lg  \" title=\"Speed &amp; Voice\"></label><ul tabindex=\"0\" class=\"dropdown-content border z-40 menu p-4 shadow bg-light rounded-box w-60\"><div class=\"text-lightText flex bg-light p-2 rounded w-full mb-2 items-center justify-between\"><span class=\"text-xs font-bold\">Speed</span><button class=\"bg-lightAlt ml-2 px-4 py-2 rounded-full text-sm font-bold min-w-[100px]\">1x</button></div><div class=\"text-lightText flex flex-col bg-light p-2 rounded w-full\"><span class=\"text-xs font-bold mb-2\">Voice</span><div class=\"flex flex-col gap-2 max-h-60 overflow-auto pr-1\"><button class=\"bg-lightAlt px-3 py-2 rounded-lg text-sm font-bold text-left flex items-center justify-between ring-2 ring-green-600\"><span class=\"truncate mr-2\">Dr. One </span><img src=\"https://hackernoon.imgix.net/avatars/robot-b5.png\" alt=\"Dr. One (en-US)\" class=\"w-6 h-6 rounded-full\"/></button><button class=\"bg-lightAlt px-3 py-2 rounded-lg text-sm font-bold text-left flex items-center justify-between \"><span class=\"truncate mr-2\">Ms. Hacker </span><img src=\"https://hackernoon.imgix.net/avatars/robot-b6.png\" alt=\"Ms. Hacker (en-US)\" class=\"w-6 h-6 rounded-full\"/></button></div></div></ul></div><div class=\"flex gap-2 order-3 sm:items-center sm:flex-row w-full\"><div class=\"rounded-lg flex-1 bg-lightAccentTextAlt relative\"><div class=\"hidden lg:block\"><div class=\"relative max-w-[1000px] h-full flex items-center cursor-pointer rounded-lg \"><canvas class=\"bg-transparent absolute top-0 left-0 w-full h-full rounded-lg   \"></canvas><div></div><div class=\"  top-0 left-0 h-full overflow-hidden bg-lightAccentAlt border rounded-l-lg\" style=\"width:0px\"><canvas class=\"bg-transparent w-full h-full text-green-500\"></canvas></div></div></div><div class=\"hidden sm:block lg:hidden\"><div class=\"relative max-w-[1000px] h-full flex items-center cursor-pointer rounded-lg \"><canvas class=\"bg-transparent absolute top-0 left-0 w-full h-full rounded-lg   \"></canvas><div></div><div class=\"  top-0 left-0 h-full overflow-hidden bg-lightAccentAlt border rounded-l-lg\" style=\"width:0px\"><canvas class=\"bg-transparent w-full h-full text-green-500\"></canvas></div></div></div><div class=\"w-full sm:hidden\"><div class=\"relative max-w-[1000px] h-full flex items-center cursor-pointer rounded-lg \"><canvas class=\"bg-transparent absolute top-0 left-0 w-full h-full rounded-lg   \"></canvas><div></div><div class=\"  top-0 left-0 h-full overflow-hidden bg-lightAccentAlt border rounded-l-lg\" style=\"width:0px\"><canvas class=\"bg-transparent w-full h-full text-green-500\"></canvas></div></div></div></div><div class=\"hidden lg:ml-2 sm:block\"></div><div class=\" flex items-center sm:hidden\"></div></div></div></div></div></div><div class=\" flex xl:hidden bg-light z-10 mx-auto  gap-4 items-center border-y sticky top-[62px] sm:top-[80px]  py-2 sm:py-0 \"><div class=\"w-full max-w-[1200px] mx-auto px-4 flex justify-between items-center\"><div class=\"6xl:hidden dropdown dropdown-bottom dropdown-hover\"><div tabindex=\"0\" role=\"button\" class=\"flex text-sm rounded-lg py-2\"><div class=\"mr-2 flex -space-x-2 items-center \"><div class=\"\"><img alt=\"Gus Aragón\" loading=\"lazy\" width=\"48\" height=\"48\" decoding=\"async\" data-nimg=\"1\" class=\"w-10 h-10 sm:w-12 sm:h-12 bg-light relative border border-lightBorder rounded-full object-contain\" style=\"color:transparent;z-index:1\" srcSet=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=48 1x, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=96 2x\" src=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=96\"/></div></div><div class=\"flex-col hidden sm:flex flex-wrap\"><span class=\"font-bold mx-2 text-sm\"><span class=\"text-xs font-light mr-1\">by</span>Gus Aragón</span><span class=\"text-sm ml-2\">@<!-- -->garagon</span></div></div><ul tabindex=\"0\" class=\"dropdown-content menu w-[300px] py-1 left-[-20px] bg-light px-1  ml-4  rounded-b-lg 3xl:border-none rounded-boxabsolute z-50\"><div class=\"flex w-full flex-col gap-4\"><div><div class=\"w-full   \"><div class=\" p-4 border border-lightBorder bg-light rounded-lg\"><a href=\"/u/garagon\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"flex items-start text-sm rounded-lg group gap-2\"><div class=\"\"><img alt=\"Gus Aragón\" loading=\"lazy\" width=\"40\" height=\"40\" decoding=\"async\" data-nimg=\"1\" class=\"w-10 h-9 border-solid border border-lightBorder rounded-full object-contain\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=48 1x, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=96 2x\" src=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=96\"/></div><span class=\"flex flex-col min-w-0 w-full justify-center\"><span class=\"flex items-center gap-1 text-ellipsis overflow-hidden whitespace-nowrap\"><span class=\"font-bold group-hover:underline text-sm truncate\"><span class=\"text-xs font-light mr-1\">by</span>Gus Aragón</span><span class=\"text-xs font-light opacity-50\">|</span><span class=\"text-sm false text-ellipsis overflow-hidden whitespace-nowrap\" title=\"@garagon\">@<!-- -->garagon</span></span><span class=\"text-xs text-ellipsis overflow-hidden whitespace-nowrap mt-0.5\" title=\"Founder at Oktsec.com\">Founder<!-- --> at <!-- -->Oktsec.com</span></span></a><p class=\"text-sm overflow-x-auto mt-2 text-bodyTxtLight\">Founder @ Oktsec | Security for AI agent work | AAIF Ambassador | Cybersecurity | Open Source</p><div class=\"mt-4\"><div class=\"w-full flex justify-start\"><div class=\"w-full\"><form class=\"w-full flex flex-col items-start gap-2 \"><div class=\"flex w-full\"><input class=\"p-2 flex-grow  border rounded-l-md text-lightText bg-light focus:outline-none focus:ring-0 focus:ring-transparent border-lightBorder w-full text-base px-2} \n                  }\" placeholder=\"name@company.com\" type=\"email\" required=\"\" name=\"email\" value=\"\"/><button type=\"submit\" class=\"text-base} \n                bg-lightAlt border border-l-0 border-lightBorder hover:bg-green-700 text-lightText hover:bg-dark hover:text-darkText  px-2 py-1 rounded-r-md  font-bold\">Subscribe</button></div></form></div></div></div></div></div></div><div class=\"xl:hidden\"><div class=\"group transition-all duration-300\"><div class=\"p-2 border border-lightBorder bg-light rounded-lg transition-all duration-300 pb-0\"><span class=\"font-bold mx-2 text-sm text-lightTextLight\">Story&#x27;s Credibility</span><div class=\"\n                        mt-2 flex gap-2 flex-wrap m-2 transition-all duration-300 ease-in-out\n                        flex-row\n                    \"><div class=\"flex items-start gap-2 text-sm rounded-lg max-w-[250px] \n                                           transition-all duration-300 ease-in-out p-1\n                                           \n                                           \n                                           cursor-default\"><img alt=\"Original Reporting\" loading=\"lazy\" width=\"16\" height=\"16\" decoding=\"async\" data-nimg=\"1\" class=\"w-4 h-4 rounded-full transition-transform duration-300 group-hover:scale-105 cursor-pointer\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/img-oi03r0q.png?auto=format%2Ccompress&amp;w=32 1x\" src=\"https://hackernoon.imgix.net/images/img-oi03r0q.png?auto=format%2Ccompress&amp;w=32\"/></div><div class=\"flex items-start gap-2 text-sm rounded-lg max-w-[250px] \n                                           transition-all duration-300 ease-in-out p-1\n                                           \n                                           \n                                           cursor-default\"><img alt=\"AI-assisted \" loading=\"lazy\" width=\"16\" height=\"16\" decoding=\"async\" data-nimg=\"1\" class=\"w-4 h-4 rounded-full transition-transform duration-300 group-hover:scale-105 cursor-pointer\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/img-w003rvs.png?auto=format%2Ccompress&amp;w=32 1x\" src=\"https://hackernoon.imgix.net/images/img-w003rvs.png?auto=format%2Ccompress&amp;w=32\"/></div></div></div></div></div></div></ul></div><div class=\"w-[200px] 6xl:hidden\"><div class=\" flex flex-row  flex-row-reverse  items-start gap-4 \"><span class=\"tooltip tooltip-left cursor-pointer\" data-tip=\"Bookmark\"><button class=\"3xl:hover:bg-lightAlt hover:bg-light p-1 md:p-2 rounded h-[40px] w-[40px] flex items-center justify-center border border-lightBorder\"><i class=\"hn hn-bookmark text-lightText text-2xl\"></i></button></span><span class=\"tooltip tooltip-left   cursor-pointer\" data-tip=\"Comment\"><button class=\"3xl:hover:bg-lightAlt hover:bg-light p-1 md:p-2 rounded h-[40px] w-[40px] flex items-center justify-center border border-lightBorder\"><i class=\"hn hn-comment text-lightText text-2xl\"></i></button></span><div class=\"dropdown  dropdown-bottom dropdown-hover group  \"><label tabindex=\"0\" class=\"flex items-center  cursor-pointer justify-center border border-lightBorder  3xl:group-hover:bg-lightAlt group-hover:bg-light h-[40px] w-[40px] p-2 rounded \"><i class=\"hn hn-share text-2xl\"></i></label><ul tabindex=\"0\" class=\"dropdown-content bg-light z-[1] py-4 px-4 3xl:px-0  3xl:py-2 border 3xl:border-none flex flex-col items-center justify-center gap-2 \"><button class=\"border p-2 rounded hover:bg-lightAlt\"><i class=\" hn hn-copy text-lightText  text-2xl \"></i></button><button class=\"border p-2 rounded hover:bg-lightAlt\"><i class=\"hn hn-facebook-round text-lightText text-2xl\"></i></button><button class=\"border p-2 rounded hover:bg-lightAlt\"><i class=\"hn hn-x text-lightText text-2xl\"></i></button><button class=\"border p-2 rounded hover:bg-lightAlt\"><i class=\"hn hn-linkedin text-lightText text-2xl\"></i></button><a href=\"mailto:?subject=I&#x27;d like to share a link with you &amp;body=\" class=\"border p-2 rounded inline-block hover:bg-lightAlt\"><i class=\"hn hn-envelope text-lightText text-2xl\"></i></a></ul></div></div></div></div></div><div class=\"flex max-w-[1100px] 2xl:max-w-[1200px] mx-auto justify-center flex-row gap-4 items-start mt-10 px-4 xl:px-0\"><div class=\"hidden xl:flex xl:flex-col self-stretch\"><div class=\"sticky top-[99px] z-40\"><div class=\"dropdown z-25  dropdown-right dropdown-hover\"><div class=\"mr-2 flex  gap-2 flex-col justify-center flex-wrap  items-center \"><div class=\"relative h-12 w-12 bg-black rounded-full overflow-hidden flex-shrink-0\"><img alt=\"Gus Aragón\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"rounded-full object-contain \" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent;z-index:1\" sizes=\"100vw\" srcSet=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=640 640w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=750 750w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=828 828w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=1080 1080w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=1200 1200w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=1920 1920w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=2048 2048w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=3840 3840w\" src=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=3840\"/></div></div><ul tabindex=\"0\" class=\"dropdown-content w-[280px] xs:w-[320px] sm:w-[400px] rounded-lg z-[100] bg-light flex flex-col items-center justify-center gap-2\"><div class=\"flex w-full flex-col gap-4\"><div><div class=\"w-full   \"><div class=\" p-4 border border-lightBorder bg-light rounded-lg\"><a href=\"/u/garagon\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"flex items-start text-sm rounded-lg group gap-2\"><div class=\"\"><img alt=\"Gus Aragón\" loading=\"lazy\" width=\"40\" height=\"40\" decoding=\"async\" data-nimg=\"1\" class=\"w-10 h-9 border-solid border border-lightBorder rounded-full object-contain\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=48 1x, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=96 2x\" src=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=96\"/></div><span class=\"flex flex-col min-w-0 w-full justify-center\"><span class=\"flex items-center gap-1 text-ellipsis overflow-hidden whitespace-nowrap\"><span class=\"font-bold group-hover:underline text-sm truncate\"><span class=\"text-xs font-light mr-1\">by</span>Gus Aragón</span><span class=\"text-xs font-light opacity-50\">|</span><span class=\"text-sm false text-ellipsis overflow-hidden whitespace-nowrap\" title=\"@garagon\">@<!-- -->garagon</span></span><span class=\"text-xs text-ellipsis overflow-hidden whitespace-nowrap mt-0.5\" title=\"Founder at Oktsec.com\">Founder<!-- --> at <!-- -->Oktsec.com</span></span></a><p class=\"text-sm overflow-x-auto mt-2 text-bodyTxtLight\">Founder @ Oktsec | Security for AI agent work | AAIF Ambassador | Cybersecurity | Open Source</p><div class=\"mt-4\"><div class=\"w-full flex justify-start\"><div class=\"w-full\"><form class=\"w-full flex flex-col items-start gap-2 \"><div class=\"flex w-full\"><input class=\"p-2 flex-grow  border rounded-l-md text-lightText bg-light focus:outline-none focus:ring-0 focus:ring-transparent border-lightBorder w-full text-base px-2} \n                  }\" placeholder=\"name@company.com\" type=\"email\" required=\"\" name=\"email\" value=\"\"/><button type=\"submit\" class=\"text-base} \n                bg-lightAlt border border-l-0 border-lightBorder hover:bg-green-700 text-lightText hover:bg-dark hover:text-darkText  px-2 py-1 rounded-r-md  font-bold\">Subscribe</button></div></form></div></div></div></div></div></div><div class=\"xl:hidden\"><div class=\"group transition-all duration-300\"><div class=\"p-2 border border-lightBorder bg-light rounded-lg transition-all duration-300 pb-0\"><span class=\"font-bold mx-2 text-sm text-lightTextLight\">Story&#x27;s Credibility</span><div class=\"\n                        mt-2 flex gap-2 flex-wrap m-2 transition-all duration-300 ease-in-out\n                        flex-row\n                    \"><div class=\"flex items-start gap-2 text-sm rounded-lg max-w-[250px] \n                                           transition-all duration-300 ease-in-out p-1\n                                           \n                                           \n                                           cursor-default\"><img alt=\"Original Reporting\" loading=\"lazy\" width=\"16\" height=\"16\" decoding=\"async\" data-nimg=\"1\" class=\"w-4 h-4 rounded-full transition-transform duration-300 group-hover:scale-105 cursor-pointer\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/img-oi03r0q.png?auto=format%2Ccompress&amp;w=32 1x\" src=\"https://hackernoon.imgix.net/images/img-oi03r0q.png?auto=format%2Ccompress&amp;w=32\"/></div><div class=\"flex items-start gap-2 text-sm rounded-lg max-w-[250px] \n                                           transition-all duration-300 ease-in-out p-1\n                                           \n                                           \n                                           cursor-default\"><img alt=\"AI-assisted \" loading=\"lazy\" width=\"16\" height=\"16\" decoding=\"async\" data-nimg=\"1\" class=\"w-4 h-4 rounded-full transition-transform duration-300 group-hover:scale-105 cursor-pointer\" style=\"color:transparent\" srcSet=\"https://hackernoon.imgix.net/images/img-w003rvs.png?auto=format%2Ccompress&amp;w=32 1x\" src=\"https://hackernoon.imgix.net/images/img-w003rvs.png?auto=format%2Ccompress&amp;w=32\"/></div></div></div></div></div></div></ul></div></div></div><div class=\"flex-1 flex flex-col justify-center \"><div class=\"\"><div class=\" story-body font-sans flex items-center  justify-center  \"><div class=\"prose  max-w-[1020px] min-w-[150px] xs:p-0  lg:px-0 prose-a:break-words prose-table:block prose-div:bg-transparent  prose-table:max-w-[900px]  xs:prose-table:mx-auto prose-table:overflow-x-auto prose-th:whitespace-wrap prose-td:whitespace-wrap  leading-relaxed tracking-wide  prose-p:text-lightTextLight prose-strong:text-lightTextStrong prose-strong:font-bold prose-small:text-lightTextLight prose-small:font-light prose-a:text-lightTextLight prose-p:mx-0 prose-p:my-2 prose [&amp;_.line-space]:my-0 prose-p:my-2 prose-p:text-base  sm:prose-p:text-lg  prose-blockquote:my-0 prose-blockquote:border-l-[5px] prose-blockquote:border-lightTextAccent prose-blockquote:pl-4 prose-blockquote:leading-relaxed prose-blockquote:text-lightText prose-h2:text-lightTextStrong prose-li:marker:text-lightText prose-h2:text-xl sm:prose-h2:text-3xl prose-h2:font-bold prose-h2:my-6 prose-h3:text-lightTextStrong prose-hr:m-2 prose-h3:text-xl sm:prose-h3:text-2xl prose-h3:font-bold prose-h3:my-5 prose-h4:text-xl prose-h4:font-bold prose-h4:my-4 prose-td:text-lightTextLight prose-td:border prose-td:border-lightBorder prose-td:px-2 prose-th:text-lightTextLight prose-th:border prose-th:border-lightBorder prose-th:px-2 prose-li:text-lg prose-li:text-lightTextLight prose-li:px-0 prose-li:mb-3 prose-li:ml-3 prose-li:leading-relaxed prose-ul:pl-2 prose-ul:sm:pl-8 prose-ol:pl-2 prose-ol:sm:pl-8  hover:prose-a:text-lightTextAccent prose-a:rounded prose-code:text-lightTextLight prose-code:break-all prose-pre:rounded-lg prose-pre:text-sm prose-pre:my-4 prose-pre:p-3 prose-pre:overflow-x-scroll prose-pre:whitespace-pre-wrap prose-pre:break-words \"><div class=\"w-full flex items-center justify-center \"><p class=\"line-space\"> <br/> </p><p>In March I published a piece arguing that AI agents don&#x27;t have identities and that this was already a security crisis. The claim was operational. We were deploying systems that read files, call APIs and chain tools together, while the answer to the most basic security question, who exactly is acting right now, was still a shared account, a reused API key and permissions far broader than any single task required.</p><p>Four months later the diagnosis holds. Agent identity is not solved end to end. What changed is that the problem became explicit. Between March and July 2026 it showed up in protocol releases, enterprise features and papers with measured results. The identity layer for AI agents is finally being built. It just isn&#x27;t finished.</p>\n<h2 id=\"h-a-2-a-grew-up-first\">A2A grew up first</h2>\n<p>The first milestone landed almost on top of my original article. On March 12, the A2A project shipped v1.0.0, its first stable specification. The release touches security directly: it removes the legacy OAuth implicit and password flows, adds Device Code (RFC 8628) and PKCE support, introduces native multi-tenancy, adds mTLS to the security schemes and formalizes Agent Card signature verification using JWS and JSON Canonicalization.</p>\n<p>The signed Agent Cards are the piece I care about most. In v0.x, an Agent Card was self-declared metadata. Any agent could claim to be anything. With v1.0, clients can cryptographically verify agent identity and metadata before trusting an interaction across organizational boundaries. The spec also formalizes in-task authorization through the TASK_STATE_AUTH_REQUIRED state, which gives agents a standard fallback when an operation needs human or client approval mid-flight.</p>\n<p>The limitation is that Agent Cards remain a declarative layer. The signature proves who published the card. It says nothing about what a specific running instance of that agent is doing right now, or under whose delegated authority. Identity per instance, portable across heterogeneous stacks, still doesn&#x27;t exist in the spec.</p>\n<h2 id=\"h-mcp-put-authorization-at-the-center\">MCP put authorization at the center</h2>\n<p>MCP moved on a different front. On March 9, the maintainers published their 2026 roadmap, acknowledging that the protocol had outgrown its &quot;connect local tools&quot; phase and was now production infrastructure with governance to match. In April the project expanded its maintainer team, citing the move to the Agentic AI Foundation and a growing volume of Specification Enhancement Proposals. When a protocol starts adding lead maintainers to handle SEP throughput, it has stopped being an experiment.</p>\n<p>On May 21, the maintainers published the release candidate for MCP 2026-07-28 and described it as the largest revision since launch. It brings a stateless core, Tasks and MCP Apps as extensions, a formal deprecation policy and six SEPs hardening authorization to align with how OAuth 2.0 and OpenID Connect actually get deployed in production, including issuer validation per RFC 9207.</p>\n<p>The most tangible piece landed on June 18, when Enterprise-Managed Authorization went stable. EMA lets organizations control MCP server access centrally through their identity provider. Users log in once and inherit access to every approved server, with no per-app OAuth consent screens. Okta is the first supported IdP through Cross App Access. Anthropic implemented it across Claude, Claude Code and Cowork, Microsoft shipped it in VS Code, and MCP servers from Asana, Atlassian, Figma, Linear and Supabase support it at launch.</p>\n<p>EMA fixes something real. Before it, the typical enterprise pattern was a shared service account with a long-lived token in a .env file. No audit trail, no role scoping, no revocation path. EMA replaces that with IdP-governed access: group membership, conditional access rules, deprovisioning on offboarding. For anyone running agents in an enterprise, this is the most important practical improvement since my original article.</p>\n<p>What EMA answers is which humans in this org may connect to which servers. What it doesn&#x27;t answer is which agent instance received which delegated authority to perform which specific action inside a chain of tools. Provisioning and governance improved dramatically. Per-action, per-instance identity did not.</p>\n<h2 id=\"h-research-went-where-the-protocols-dont-reach\">Research went where the protocols don&#x27;t reach</h2>\n<p>While the protocols hardened their edges, academic work attacked the middle. Two papers stand out.</p>\n<p>PAuth (arXiv 2603.17170, March 17) goes straight at overprivilege. Its argument: OAuth scopes are bound to operators, not operations. If your agent needs to transfer $100 to Bob, OAuth forces you to grant a blanket TRANSFER permission that covers any amount to any recipient. PAuth proposes task-scoped implicit authorization instead. Submitting a natural-language task authorizes only the concrete operations required to execute it faithfully. In the AgentDojo evaluation, all benign tasks complete without extra permissions and all injected attack operations trigger warnings, with zero false positives and zero false negatives. This is the operation-level policy layer I sketched in March, now with a working prototype.</p>\n<p>AIP (arXiv 2603.24775, March 25) is the most direct confirmation of the original thesis. The paper states that neither MCP nor A2A natively verifies agent identity, and cites a Knostic scan of roughly 2,000 internet-exposed MCP servers in which every single one lacked authentication. Its answer is Invocation-Bound Capability Tokens: an append-only chain that fuses identity, attenuated authorization and provenance into one cryptographic artifact, with bindings for MCP, A2A and plain HTTP. The measured overhead is 2.35ms in a real multi-agent deployment, 0.086% of end-to-end latency, with a 100% rejection rate across 600 adversarial attempts. AIP is now also an IETF Internet-Draft, which tells you where this conversation is heading.</p>\n<p>Around these two, a broader research cluster is forming: decentralized identity approaches built on DIDs and verifiable credentials, IETF drafts on attenuating authorization tokens for delegation chains, and work reframing the problem from &quot;who are you&quot; to &quot;what portable authority can you prove&quot;. None of it is deployed at scale. All of it targets the layers the protocols still leave open.</p>\n<h2 id=\"h-scoring-my-march-claims\">Scoring my March claims</h2>\n<p>The original article made five claims. This is how they held up.</p>\n<p><em><strong>Agents don&#x27;t fit the identity models for humans, services or bots.</strong></em> Confirmed. Every serious paper published since starts from this exact insufficiency and proposes agent-specific frameworks.</p>\n<p><em><strong>Delegation on behalf of a user is badly modeled</strong></em>*.* Confirmed, with nuance. MCP&#x27;s authorization is still built on standard OAuth 2.1 flows. EMA improves the enterprise operation of those flows enormously without introducing universal agentic identity. Better plumbing, same conceptual gap.</p>\n<p><em><strong>Multi-tool composition creates emergent privileges nobody approved.</strong></em> Confirmed and expanded. MCP elevated tool annotations as a risk vocabulary, threat modeling work flagged tool poisoning as a critical client-side vulnerability, and A2A added in-task authorization. The ecosystem now agrees this is where attacks live.</p>\n<p><em><strong>You can&#x27;t reliably audit who did what</strong></em>*.* Partially mitigated. Signed Agent Cards and AIP-style completion records add provenance. There is still no dominant standard for per-instance audit across stacks.</p>\n<p><em><strong>The fix is a layered stack, not a single patch.</strong></em> Confirmed. MCP is building the authorization layer. A2A is building declarative identity and inter-agent trust. Research is building task scoping, verifiable delegation and portable authority. Nobody is shipping one magic fix, because there isn&#x27;t one.</p>\n<h2 id=\"h-the-right-question-for-july-2026\">The right question for July 2026</h2>\n<p>The question is no longer whether agents have an identity crisis. They do, and now everyone from protocol maintainers to IETF draft authors says so in writing. The right question is which parts of the stack finally exist and which parts remain aspirational.</p>\n<p>My answer today: enterprise authorization for MCP exists and works. A serious foundation for inter-agent trust exists in A2A v1.0. Measured proposals exist for task scoping and verifiable delegation. What still doesn&#x27;t exist is the layer that binds them into an interoperable default: identity per running instance, authority that attenuates correctly across multi-hop delegation and provenance you can audit end to end without trusting every intermediary.</p>\n<p>In March I wrote that the best time to close this gap was before deployment, and the second best time was now. That line deserves an update. We&#x27;re no longer starting from zero. We&#x27;re starting from an ecosystem that finally admits, in specs and in code, that an agent can&#x27;t keep being treated as a weird user or as just another service. An agent needs verifiable identity, bounded authority and auditable provenance. Until that&#x27;s the default behavior in production, the crisis hasn&#x27;t ended. It has started to professionalize.</p>\n<hr/>\n<h2 id=\"h-references\">References</h2>\n<ul>\n<li>Original article: <a href=\"https://hackernoon.com/ai-agents-dont-have-identities-and-thats-a-security-crisis?ref=hackernoon.com\" target=\"_blank\" rel=\"noopener noreferrer ugc\">AI Agents Don&#x27;t Have Identities, and That&#x27;s a Security Crisis</a> (HackerNoon, March 2026)</li>\n<li><a href=\"https://blog.modelcontextprotocol.io/?ref=hackernoon.com\" target=\"_blank\" rel=\"noopener noreferrer ugc\">The 2026 MCP Roadmap</a> (MCP Blog, March 9, 2026)</li>\n<li><a href=\"https://a2a-protocol.org/latest/announcing-1.0/?ref=hackernoon.com\" target=\"_blank\" rel=\"noopener noreferrer ugc\">A2A Protocol v1.0 announcement</a> and <a href=\"https://a2a-protocol.org/latest/whats-new-v1/?ref=hackernoon.com\" target=\"_blank\" rel=\"noopener noreferrer ugc\">What&#x27;s New in v1.0</a></li>\n<li><a href=\"https://arxiv.org/abs/2603.17170?ref=hackernoon.com\" target=\"_blank\" rel=\"noopener noreferrer ugc\">PAuth: Precise Task-Scoped Authorization For Agents</a> (arXiv, March 17, 2026)</li>\n<li><a href=\"https://arxiv.org/abs/2603.24775?ref=hackernoon.com\" target=\"_blank\" rel=\"noopener noreferrer ugc\">AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A</a> (arXiv, March 25, 2026) and <a href=\"https://datatracker.ietf.org/doc/draft-prakash-aip/?ref=hackernoon.com\" target=\"_blank\" rel=\"noopener noreferrer ugc\">IETF draft-prakash-aip</a></li>\n<li><a href=\"https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/?ref=hackernoon.com\" target=\"_blank\" rel=\"noopener noreferrer ugc\">The 2026-07-28 MCP Specification Release Candidate</a> (MCP Blog, May 21, 2026)</li>\n<li><a href=\"https://blog.modelcontextprotocol.io/posts/enterprise-managed-auth/?ref=hackernoon.com\" target=\"_blank\" rel=\"noopener noreferrer ugc\">Enterprise-Managed Authorization: Zero-touch OAuth for MCP</a> (MCP Blog, June 18, 2026)</li>\n</ul>\n<p class=\"line-space\"> <br/> </p><p class=\"line-space\"> <br/> </p></div></div></div></div></div><div class=\"hidden xl:flex xl:flex-col self-stretch\"><div class=\"sticky top-[99px] px-3\"><div class=\" flex flex-col flex-row-reverse  items-start gap-4 \"><span class=\"tooltip tooltip-left cursor-pointer\" data-tip=\"Bookmark\"><button class=\"3xl:hover:bg-lightAlt hover:bg-light p-1 md:p-2 rounded h-[40px] w-[40px] flex items-center justify-center border border-lightBorder\"><i class=\"hn hn-bookmark text-lightText text-2xl\"></i></button></span><span class=\"tooltip tooltip-left   cursor-pointer\" data-tip=\"Comment\"><button class=\"3xl:hover:bg-lightAlt hover:bg-light p-1 md:p-2 rounded h-[40px] w-[40px] flex items-center justify-center border border-lightBorder\"><i class=\"hn hn-comment text-lightText text-2xl\"></i></button></span><div class=\"dropdown  dropdown-bottom dropdown-hover group  \"><label tabindex=\"0\" class=\"flex items-center  cursor-pointer justify-center border border-lightBorder  3xl:group-hover:bg-lightAlt group-hover:bg-light h-[40px] w-[40px] p-2 rounded \"><i class=\"hn hn-share text-2xl\"></i></label><ul tabindex=\"0\" class=\"dropdown-content bg-light z-[1] py-4 px-4 3xl:px-0  3xl:py-2 border 3xl:border-none flex flex-col items-center justify-center gap-2 \"><button class=\"border p-2 rounded hover:bg-lightAlt\"><i class=\" hn hn-copy text-lightText  text-2xl \"></i></button><button class=\"border p-2 rounded hover:bg-lightAlt\"><i class=\"hn hn-facebook-round text-lightText text-2xl\"></i></button><button class=\"border p-2 rounded hover:bg-lightAlt\"><i class=\"hn hn-x text-lightText text-2xl\"></i></button><button class=\"border p-2 rounded hover:bg-lightAlt\"><i class=\"hn hn-linkedin text-lightText text-2xl\"></i></button><a href=\"mailto:?subject=I&#x27;d like to share a link with you &amp;body=\" class=\"border p-2 rounded inline-block hover:bg-lightAlt\"><i class=\"hn hn-envelope text-lightText text-2xl\"></i></a></ul></div></div></div></div></div><div class=\"px-4 lg:px-0 mx-auto w-full lg:max-w-[1000px] flex-col flex items-center justify-center \"><div id=\"commentSection\" class=\" font-sans max-w-[1000px] mt-4 mb-10 px-4 sm:px-0 items-center rounded-xl w-full  flex flex-col\"><div class=\"flex w-full flex-col xs:flex-row items-stretch justify-between gap-5 \"><a href=\"/ai-agents-dont-have-identities-and-thats-a-security-crisis\" rel=\"external\" class=\"flex xs:w-1/2 flex-col group justify-between no-underline border border-lightBorder rounded-[5px] transition-all duration-300 hover:scale-[1.03]\"><div class=\"flex-grow p-3 text-lightText\"><span class=\"font-bold hover:text-lightTextStrong\">← Previous</span><p class=\"mt-2 font-light  hover:underline\">AI Agents Don’t Have Identities and That’s a Security Crisis</p></div></a></div></div></div><div id=\"aboutCard\" class=\" max-w-[1000px] mx-auto flex flex-col items-center gap-6 \"><div class=\"w-full lg:border border-lightBorder rounded-2xl\"><div class=\" w-full  px-4 py-3 sm:px-8 sm:py-6   \"><h3 class=\"text-xl xs:text-2xl sm:text-3xl font-bold mb-6\">About Author</h3><div class=\"flex flex-col items-start\"><div class=\"flex gap-4 flex-row items-start w-full\"><div class=\"relative shadow-md rounded-full flex-shrink-0 min-w-[50px] w-[50px] h-[50px] sm:min-w-[75px] sm:h-[75px] ring-4 ring-gray-300\"><a href=\"/u/garagon\"><img alt=\"Gus Aragón HackerNoon profile picture\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"rounded-full\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;object-fit:cover;color:transparent\" sizes=\"100vw\" srcSet=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=640 640w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=750 750w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=828 828w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=1080 1080w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=1200 1200w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=1920 1920w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=2048 2048w, https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=3840 3840w\" src=\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg?auto=format%2Ccompress&amp;w=3840\"/></a></div><div class=\"flex-1 min-w-0 flex flex-col justify-center\"><div class=\"flex flex-col\"><div class=\"flex flex-wrap items-center gap-1 sm:gap-2 text-base text-bodyTxtLight\"><span class=\"text-xs font-light mr-1\">by</span><a class=\"hover:underline\" href=\"/u/garagon\"><strong class=\"font-bold text-lightTextStrong\">Gus Aragón</strong></a><span class=\"text-xs font-light opacity-50\">|</span><a class=\"hover:underline text-sm sm:text-base text-bodyTxtLight\" href=\"/u/garagon\">@<!-- -->garagon</a></div><div class=\"text-sm text-bodyTxtLight mt-1\">Founder<!-- --> at <!-- --> <span class=\"font-medium\">Oktsec.com</span></div></div></div></div><p class=\"text-sm text-bodyTxtLight break-words overflow-wrap mt-4 mb-4 w-full\">Founder @ Oktsec | Security for AI agent work | AAIF Ambassador | Cybersecurity | Open Source</p><div class=\"w-full mb-4\"><div class=\"w-full flex justify-start\"><div class=\"w-full\"><form class=\"w-full flex flex-col items-start gap-2 \"><div class=\"flex w-full\"><input class=\"p-2 flex-grow  border rounded-l-md text-lightText bg-light focus:outline-none focus:ring-0 focus:ring-transparent border-lightBorder w-full text-base px-2} \n                  }\" placeholder=\"name@company.com\" type=\"email\" required=\"\" name=\"email\" value=\"\"/><button type=\"submit\" class=\"text-base} \n                bg-lightAlt border border-l-0 border-lightBorder hover:bg-green-700 text-lightText hover:bg-dark hover:text-darkText  px-2 py-1 rounded-r-md  font-bold\">Subscribe</button></div></form></div></div></div><div class=\"flex-1 w-full\"><div class=\"flex flex-col flex-wrap gap-2 items-start justify-start mt-2 mb-2\"></div><div class=\"flex flex-col sm:flex-row gap-4 w-full\"><a class=\"text-base flex-1 px-4 py-2 font-bold rounded-lg border-2 border-lightBorder transition text-center w-full sm:w-auto bg-light hover:bg-lightAlt text-lightText hover:bg-bodyAccent hover:text-bodyAccentTxt  \" href=\"/u/garagon\">Read my stories</a><a class=\"text-base break-words flex-1 break-all px-4 py-2 font-bold rounded-lg border-2 border-lightBorder transition text-center w-full sm:w-auto bg-light hover:bg-lightAlt text-lightText hover:bg-bodyAccent hover:text-bodyAccentTxt  \" href=\"/about/garagon\">About @garagon</a></div></div></div></div></div><span id=\"aboutCard\" class=\"hidden\"></span><section class=\"w-full py-3 px-4 sm:px-0 sm:py-6 \"><h4 class=\"text-xl xs:text-2xl sm:text-3xl  font-bold mb-4 sm:mb-6\">TOPICS</h4><div class=\"flex flex-wrap gap-2\"><div class=\" flex flex-wrap items-center gap-2 border-lightBorder\"><a href=\"/c/cybersecurity\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-lg border-lightBorder hover:bg-lightAccent hover:text-lightAccentText hover:border-lightAccentText bg-lightAlt text-lightText  flex items-center px-2 py-1 border rounded\"><span class=\"mr-2\"><i class=\"hn hn-cybersecurity !leading-[inherit]\"></i></span><span>cybersecurity</span></a></div><a href=\"/tagged/ai-agents\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sm xs:text-base sm:text-lg flex items-center px-2 py-1 border hover:bg-lightAlt border-lightBorder rounded\">#<!-- -->ai-agents</a><a href=\"/tagged/ai-security\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sm xs:text-base sm:text-lg flex items-center px-2 py-1 border hover:bg-lightAlt border-lightBorder rounded\">#<!-- -->ai-security</a><a href=\"/tagged/a2a-protocol\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sm xs:text-base sm:text-lg flex items-center px-2 py-1 border hover:bg-lightAlt border-lightBorder rounded\">#<!-- -->a2a-protocol</a><a href=\"/tagged/mcp-server\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sm xs:text-base sm:text-lg flex items-center px-2 py-1 border hover:bg-lightAlt border-lightBorder rounded\">#<!-- -->mcp-server</a><a href=\"/tagged/ai-agent-identity\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sm xs:text-base sm:text-lg flex items-center px-2 py-1 border hover:bg-lightAlt border-lightBorder rounded\">#<!-- -->ai-agent-identity</a><a href=\"/tagged/oauth-2.1\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sm xs:text-base sm:text-lg flex items-center px-2 py-1 border hover:bg-lightAlt border-lightBorder rounded\">#<!-- -->oauth-2.1</a><a href=\"/tagged/enterprise-ai\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sm xs:text-base sm:text-lg flex items-center px-2 py-1 border hover:bg-lightAlt border-lightBorder rounded\">#<!-- -->enterprise-ai</a><a href=\"/tagged/hackernoon-top-story\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sm xs:text-base sm:text-lg flex items-center px-2 py-1 border hover:bg-lightAlt border-lightBorder rounded\">#<!-- -->hackernoon-top-story</a></div></section></div></div></div></div></div><div class=\"min-h-[200px]\"></div></main><div class=\"flex flex-col gap-4 hidden\"><button class=\"mr-auto\"><i class=\"hn-sun hn text-2xl\"></i></button><h2 class=\"text-sm font-semibold  text-darkText\">Light-Mode</h2><div class=\"cursor-pointer p-3 rounded-lg hover:scale-105 transition-transform \"><h3 class=\"text-sm uppercase mb-2 \">Classic</h3><div class=\"flex space-x-1\"><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#0F0\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#F5EC43\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#212428\"></span></div></div><div class=\"cursor-pointer p-3 rounded-lg hover:scale-105 transition-transform \"><h3 class=\"text-sm uppercase mb-2 \">Newspaper</h3><div class=\"flex space-x-1\"><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#FFFFFF\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#F5F5F5\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#454545\"></span></div></div><div class=\"cursor-pointer p-3 rounded-lg hover:scale-105 transition-transform \"><h3 class=\"text-sm uppercase mb-2 \">Proof of Usefulness</h3><div class=\"flex space-x-1\"><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#FFFFFF\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#26AB5C\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#D2FBE2\"></span></div></div><h2 class=\"text-sm font-semibold  text-darkText\">Dark-Mode</h2><div class=\"cursor-pointer p-3 rounded-lg hover:scale-105 transition-transform \"><h3 class=\"text-sm uppercase mb-2 \">Neon Noir</h3><div class=\"flex space-x-1\"><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#1E1E1E\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#0F0\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#F5EC43\"></span></div></div><div class=\"cursor-pointer p-3 rounded-lg hover:scale-105 transition-transform \"><h3 class=\"text-sm uppercase mb-2 \">Minty</h3><div class=\"flex space-x-1\"><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#061F19\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#2AAA74\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#63FF86\"></span></div></div><div class=\"cursor-pointer p-3 rounded-lg hover:scale-105 transition-transform \"><h3 class=\"text-sm uppercase mb-2 \">Startups of the Year</h3><div class=\"flex space-x-1\"><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#08085E\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#A2EF44\"></span><span class=\"w-6 h-6 rounded border border-darkBorder\" style=\"background-color:#1B1B95\"></span></div></div></div></div></div><script id=\"__NEXT_DATA__\" type=\"application/json\">{\"props\":{\"pageProps\":{\"data\":{\"pageLang\":\"en\",\"datePublished\":\"2026-07-11\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"articleBody\":\"In March I published a piece arguing that AI agents don't have identities and that this was already a security crisis. The claim was operational. We were deploying systems that read files, call APIs and chain tools together, while the answer to the most basic security question, who exactly is acting right now, was still a shared account, a reused API key and permissions far broader than any single task required. Four months later the diagnosis holds. Agent identity is not solved end to end. What changed is that the problem became explicit. Between March and July 2026 it showed up in protocol releases, enterprise features and papers with measured results. The identity layer for AI agents is finally being built. It just isn't finished. A2A grew up first The first milestone landed almost on top of my original article. On March 12, the A2A project shipped v1.0.0, its first stable specification. The release touches security directly: it removes the legacy OAuth implicit and password flows, adds Device Code (RFC 8628) and PKCE support, introduces native multi-tenancy, adds mTLS to the security schemes and formalizes Agent Card signature verification using JWS and JSON Canonicalization. The signed Agent Cards are the piece I care about most. In v0.x, an Agent Card was self-declared metadata. Any agent could claim to be anything. With v1.0, clients can cryptographically verify agent identity and metadata before trusting an interaction across organizational boundaries. The spec also formalizes in-task authorization through the TASK_STATE_AUTH_REQUIRED state, which gives agents a standard fallback when an operation needs human or client approval mid-flight. The limitation is that Agent Cards remain a declarative layer. The signature proves who published the card. It says nothing about what a specific running instance of that agent is doing right now, or under whose delegated authority. Identity per instance, portable across heterogeneous stacks, still doesn't exist in the spec. MCP put authorization at the center MCP moved on a different front. On March 9, the maintainers published their 2026 roadmap, acknowledging that the protocol had outgrown its \\\"connect local tools\\\" phase and was now production infrastructure with governance to match. In April the project expanded its maintainer team, citing the move to the Agentic AI Foundation and a growing volume of Specification Enhancement Proposals. When a protocol starts adding lead maintainers to handle SEP throughput, it has stopped being an experiment. On May 21, the maintainers published the release candidate for MCP 2026-07-28 and described it as the largest revision since launch. It brings a stateless core, Tasks and MCP Apps as extensions, a formal deprecation policy and six SEPs hardening authorization to align with how OAuth 2.0 and OpenID Connect actually get deployed in production, including issuer validation per RFC 9207. The most tangible piece landed on June 18, when Enterprise-Managed Authorization went stable. EMA lets organizations control MCP server access centrally through their identity provider. Users log in once and inherit access to every approved server, with no per-app OAuth consent screens. Okta is the first supported IdP through Cross App Access. Anthropic implemented it across Claude, Claude Code and Cowork, Microsoft shipped it in VS Code, and MCP servers from Asana, Atlassian, Figma, Linear and Supabase support it at launch. EMA fixes something real. Before it, the typical enterprise pattern was a shared service account with a long-lived token in a .env file. No audit trail, no role scoping, no revocation path. EMA replaces that with IdP-governed access: group membership, conditional access rules, deprovisioning on offboarding. For anyone running agents in an enterprise, this is the most important practical improvement since my original article. What EMA answers is which humans in this org may connect to which servers. What it doesn't answer is which agent instance received which delegated authority to perform which specific action inside a chain of tools. Provisioning and governance improved dramatically. Per-action, per-instance identity did not. Research went where the protocols don't reach While the protocols hardened their edges, academic work attacked the middle. Two papers stand out. PAuth (arXiv 2603.17170, March 17) goes straight at overprivilege. Its argument: OAuth scopes are bound to operators, not operations. If your agent needs to transfer $100 to Bob, OAuth forces you to grant a blanket TRANSFER permission that covers any amount to any recipient. PAuth proposes task-scoped implicit authorization instead. Submitting a natural-language task authorizes only the concrete operations required to execute it faithfully. In the AgentDojo evaluation, all benign tasks complete without extra permissions and all injected attack operations trigger warnings, with zero false positives and zero false negatives. This is the operation-level policy layer I sketched in March, now with a working prototype. AIP (arXiv 2603.24775, March 25) is the most direct confirmation of the original thesis. The paper states that neither MCP nor A2A natively verifies agent identity, and cites a Knostic scan of roughly 2,000 internet-exposed MCP servers in which every single one lacked authentication. Its answer is Invocation-Bound Capability Tokens: an append-only chain that fuses identity, attenuated authorization and provenance into one cryptographic artifact, with bindings for MCP, A2A and plain HTTP. The measured overhead is 2.35ms in a real multi-agent deployment, 0.086% of end-to-end latency, with a 100% rejection rate across 600 adversarial attempts. AIP is now also an IETF Internet-Draft, which tells you where this conversation is heading. Around these two, a broader research cluster is forming: decentralized identity approaches built on DIDs and verifiable credentials, IETF drafts on attenuating authorization tokens for delegation chains, and work reframing the problem from \\\"who are you\\\" to \\\"what portable authority can you prove\\\". None of it is deployed at scale. All of it targets the layers the protocols still leave open. Scoring my March claims The original article made five claims. This is how they held up. Agents don't fit the identity models for humans, services or bots. Confirmed. Every serious paper published since starts from this exact insufficiency and proposes agent-specific frameworks. Agents don't fit the identity models for humans, services or bots. Agents don't fit the identity models for humans, services or bots. Delegation on behalf of a user is badly modeled*.* Confirmed, with nuance. MCP's authorization is still built on standard OAuth 2.1 flows. EMA improves the enterprise operation of those flows enormously without introducing universal agentic identity. Better plumbing, same conceptual gap. Delegation on behalf of a user is badly modeled Delegation on behalf of a user is badly modeled Multi-tool composition creates emergent privileges nobody approved. Confirmed and expanded. MCP elevated tool annotations as a risk vocabulary, threat modeling work flagged tool poisoning as a critical client-side vulnerability, and A2A added in-task authorization. The ecosystem now agrees this is where attacks live. Multi-tool composition creates emergent privileges nobody approved. Multi-tool composition creates emergent privileges nobody approved. You can't reliably audit who did what*.* Partially mitigated. Signed Agent Cards and AIP-style completion records add provenance. There is still no dominant standard for per-instance audit across stacks. You can't reliably audit who did what You can't reliably audit who did what The fix is a layered stack, not a single patch. Confirmed. MCP is building the authorization layer. A2A is building declarative identity and inter-agent trust. Research is building task scoping, verifiable delegation and portable authority. Nobody is shipping one magic fix, because there isn't one. The fix is a layered stack, not a single patch. The fix is a layered stack, not a single patch. The right question for July 2026 The question is no longer whether agents have an identity crisis. They do, and now everyone from protocol maintainers to IETF draft authors says so in writing. The right question is which parts of the stack finally exist and which parts remain aspirational. My answer today: enterprise authorization for MCP exists and works. A serious foundation for inter-agent trust exists in A2A v1.0. Measured proposals exist for task scoping and verifiable delegation. What still doesn't exist is the layer that binds them into an interoperable default: identity per running instance, authority that attenuates correctly across multi-hop delegation and provenance you can audit end to end without trusting every intermediary. In March I wrote that the best time to close this gap was before deployment, and the second best time was now. That line deserves an update. We're no longer starting from zero. We're starting from an ecosystem that finally admits, in specs and in code, that an agent can't keep being treated as a weird user or as just another service. An agent needs verifiable identity, bounded authority and auditable provenance. Until that's the default behavior in production, the crisis hasn't ended. It has started to professionalize. References Original article: AI Agents Don't Have Identities, and That's a Security Crisis (HackerNoon, March 2026)\\nThe 2026 MCP Roadmap (MCP Blog, March 9, 2026)\\nA2A Protocol v1.0 announcement and What's New in v1.0\\nPAuth: Precise Task-Scoped Authorization For Agents (arXiv, March 17, 2026)\\nAIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A (arXiv, March 25, 2026) and IETF draft-prakash-aip\\nThe 2026-07-28 MCP Specification Release Candidate (MCP Blog, May 21, 2026)\\nEnterprise-Managed Authorization: Zero-touch OAuth for MCP (MCP Blog, June 18, 2026) Original article: AI Agents Don't Have Identities, and That's a Security Crisis (HackerNoon, March 2026) AI Agents Don't Have Identities, and That's a Security Crisis The 2026 MCP Roadmap (MCP Blog, March 9, 2026) The 2026 MCP Roadmap A2A Protocol v1.0 announcement and What's New in v1.0 A2A Protocol v1.0 announcement What's New in v1.0 PAuth: Precise Task-Scoped Authorization For Agents (arXiv, March 17, 2026) PAuth: Precise Task-Scoped Authorization For Agents AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A (arXiv, March 25, 2026) and IETF draft-prakash-aip AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A IETF draft-prakash-aip The 2026-07-28 MCP Specification Release Candidate (MCP Blog, May 21, 2026) The 2026-07-28 MCP Specification Release Candidate Enterprise-Managed Authorization: Zero-touch OAuth for MCP (MCP Blog, June 18, 2026) Enterprise-Managed Authorization: Zero-touch OAuth for MCP\",\"arweave\":\"BcU1tuQG4aEfFF043K9cOzM4LDROZ4OGDZw7BLceKPs\",\"createdAt\":\"2026-07-11T13:00:43.870Z\",\"draftId\":\"6a45bd39acdf1c8e2e7d18d3\",\"emoji\":[{\"description\":\"This story contains new, firsthand information uncovered by the writer.\",\"label\":\"Original Reporting\",\"prompt\":\"\",\"image\":\"https://cdn.hackernoon.com/images/img-oi03r0q.png\",\"value\":0},{\"label\":\"AI-assisted \",\"image\":\"https://cdn.hackernoon.com/images/img-w003rvs.png\",\"prompt\":\"\",\"description\":\"This story contains AI-generated text. The author has used AI either for research, to generate outlines, or write the text itself. \",\"value\":17}],\"excerpt\":\"The identity layer for AI agents is finally being built. What MCP, A2A and new research delivered since March, and what's still missing.\",\"firstSeenAt\":false,\"fromSlack\":false,\"id\":\"6a45bd39acdf1c8e2e7d18d3\",\"imageSizes\":{},\"linkAccreditation\":{\"goals\":\"\",\"isBlogging\":null,\"isBusiness\":null,\"debut\":true,\"isPersonal\":null},\"mainImage\":\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png\",\"mainImageHeight\":941,\"mainImageWidth\":1672,\"markup\":null,\"owner\":\"v9PFbuka6VdBHUxyM4afyDLGViL2\",\"parsed\":\"\\u003cp\\u003e\\u003c/p\\u003e\\u003cp\\u003eIn March I published a piece arguing that AI agents don't have identities and that this was already a security crisis. The claim was operational. We were deploying systems that read files, call APIs and chain tools together, while the answer to the most basic security question, who exactly is acting right now, was still a shared account, a reused API key and permissions far broader than any single task required.\\u003c/p\\u003e\\u003cp\\u003eFour months later the diagnosis holds. Agent identity is not solved end to end. What changed is that the problem became explicit. Between March and July 2026 it showed up in protocol releases, enterprise features and papers with measured results. The identity layer for AI agents is finally being built. It just isn't finished.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"h-a-2-a-grew-up-first\\\"\\u003eA2A grew up first\\u003c/h2\\u003e\\n\\u003cp\\u003eThe first milestone landed almost on top of my original article. On March 12, the A2A project shipped v1.0.0, its first stable specification. The release touches security directly: it removes the legacy OAuth implicit and password flows, adds Device Code (RFC 8628) and PKCE support, introduces native multi-tenancy, adds mTLS to the security schemes and formalizes Agent Card signature verification using JWS and JSON Canonicalization.\\u003c/p\\u003e\\n\\u003cp\\u003eThe signed Agent Cards are the piece I care about most. In v0.x, an Agent Card was self-declared metadata. Any agent could claim to be anything. With v1.0, clients can cryptographically verify agent identity and metadata before trusting an interaction across organizational boundaries. The spec also formalizes in-task authorization through the TASK_STATE_AUTH_REQUIRED state, which gives agents a standard fallback when an operation needs human or client approval mid-flight.\\u003c/p\\u003e\\n\\u003cp\\u003eThe limitation is that Agent Cards remain a declarative layer. The signature proves who published the card. It says nothing about what a specific running instance of that agent is doing right now, or under whose delegated authority. Identity per instance, portable across heterogeneous stacks, still doesn't exist in the spec.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"h-mcp-put-authorization-at-the-center\\\"\\u003eMCP put authorization at the center\\u003c/h2\\u003e\\n\\u003cp\\u003eMCP moved on a different front. On March 9, the maintainers published their 2026 roadmap, acknowledging that the protocol had outgrown its \\\"connect local tools\\\" phase and was now production infrastructure with governance to match. In April the project expanded its maintainer team, citing the move to the Agentic AI Foundation and a growing volume of Specification Enhancement Proposals. When a protocol starts adding lead maintainers to handle SEP throughput, it has stopped being an experiment.\\u003c/p\\u003e\\n\\u003cp\\u003eOn May 21, the maintainers published the release candidate for MCP 2026-07-28 and described it as the largest revision since launch. It brings a stateless core, Tasks and MCP Apps as extensions, a formal deprecation policy and six SEPs hardening authorization to align with how OAuth 2.0 and OpenID Connect actually get deployed in production, including issuer validation per RFC 9207.\\u003c/p\\u003e\\n\\u003cp\\u003eThe most tangible piece landed on June 18, when Enterprise-Managed Authorization went stable. EMA lets organizations control MCP server access centrally through their identity provider. Users log in once and inherit access to every approved server, with no per-app OAuth consent screens. Okta is the first supported IdP through Cross App Access. Anthropic implemented it across Claude, Claude Code and Cowork, Microsoft shipped it in VS Code, and MCP servers from Asana, Atlassian, Figma, Linear and Supabase support it at launch.\\u003c/p\\u003e\\n\\u003cp\\u003eEMA fixes something real. Before it, the typical enterprise pattern was a shared service account with a long-lived token in a .env file. No audit trail, no role scoping, no revocation path. EMA replaces that with IdP-governed access: group membership, conditional access rules, deprovisioning on offboarding. For anyone running agents in an enterprise, this is the most important practical improvement since my original article.\\u003c/p\\u003e\\n\\u003cp\\u003eWhat EMA answers is which humans in this org may connect to which servers. What it doesn't answer is which agent instance received which delegated authority to perform which specific action inside a chain of tools. Provisioning and governance improved dramatically. Per-action, per-instance identity did not.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"h-research-went-where-the-protocols-dont-reach\\\"\\u003eResearch went where the protocols don't reach\\u003c/h2\\u003e\\n\\u003cp\\u003eWhile the protocols hardened their edges, academic work attacked the middle. Two papers stand out.\\u003c/p\\u003e\\n\\u003cp\\u003ePAuth (arXiv 2603.17170, March 17) goes straight at overprivilege. Its argument: OAuth scopes are bound to operators, not operations. If your agent needs to transfer $100 to Bob, OAuth forces you to grant a blanket TRANSFER permission that covers any amount to any recipient. PAuth proposes task-scoped implicit authorization instead. Submitting a natural-language task authorizes only the concrete operations required to execute it faithfully. In the AgentDojo evaluation, all benign tasks complete without extra permissions and all injected attack operations trigger warnings, with zero false positives and zero false negatives. This is the operation-level policy layer I sketched in March, now with a working prototype.\\u003c/p\\u003e\\n\\u003cp\\u003eAIP (arXiv 2603.24775, March 25) is the most direct confirmation of the original thesis. The paper states that neither MCP nor A2A natively verifies agent identity, and cites a Knostic scan of roughly 2,000 internet-exposed MCP servers in which every single one lacked authentication. Its answer is Invocation-Bound Capability Tokens: an append-only chain that fuses identity, attenuated authorization and provenance into one cryptographic artifact, with bindings for MCP, A2A and plain HTTP. The measured overhead is 2.35ms in a real multi-agent deployment, 0.086% of end-to-end latency, with a 100% rejection rate across 600 adversarial attempts. AIP is now also an IETF Internet-Draft, which tells you where this conversation is heading.\\u003c/p\\u003e\\n\\u003cp\\u003eAround these two, a broader research cluster is forming: decentralized identity approaches built on DIDs and verifiable credentials, IETF drafts on attenuating authorization tokens for delegation chains, and work reframing the problem from \\\"who are you\\\" to \\\"what portable authority can you prove\\\". None of it is deployed at scale. All of it targets the layers the protocols still leave open.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"h-scoring-my-march-claims\\\"\\u003eScoring my March claims\\u003c/h2\\u003e\\n\\u003cp\\u003eThe original article made five claims. This is how they held up.\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cem\\u003e\\u003cstrong\\u003eAgents don't fit the identity models for humans, services or bots.\\u003c/strong\\u003e\\u003c/em\\u003e Confirmed. Every serious paper published since starts from this exact insufficiency and proposes agent-specific frameworks.\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cem\\u003e\\u003cstrong\\u003eDelegation on behalf of a user is badly modeled\\u003c/strong\\u003e\\u003c/em\\u003e*.* Confirmed, with nuance. MCP's authorization is still built on standard OAuth 2.1 flows. EMA improves the enterprise operation of those flows enormously without introducing universal agentic identity. Better plumbing, same conceptual gap.\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cem\\u003e\\u003cstrong\\u003eMulti-tool composition creates emergent privileges nobody approved.\\u003c/strong\\u003e\\u003c/em\\u003e Confirmed and expanded. MCP elevated tool annotations as a risk vocabulary, threat modeling work flagged tool poisoning as a critical client-side vulnerability, and A2A added in-task authorization. The ecosystem now agrees this is where attacks live.\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cem\\u003e\\u003cstrong\\u003eYou can't reliably audit who did what\\u003c/strong\\u003e\\u003c/em\\u003e*.* Partially mitigated. Signed Agent Cards and AIP-style completion records add provenance. There is still no dominant standard for per-instance audit across stacks.\\u003c/p\\u003e\\n\\u003cp\\u003e\\u003cem\\u003e\\u003cstrong\\u003eThe fix is a layered stack, not a single patch.\\u003c/strong\\u003e\\u003c/em\\u003e Confirmed. MCP is building the authorization layer. A2A is building declarative identity and inter-agent trust. Research is building task scoping, verifiable delegation and portable authority. Nobody is shipping one magic fix, because there isn't one.\\u003c/p\\u003e\\n\\u003ch2 id=\\\"h-the-right-question-for-july-2026\\\"\\u003eThe right question for July 2026\\u003c/h2\\u003e\\n\\u003cp\\u003eThe question is no longer whether agents have an identity crisis. They do, and now everyone from protocol maintainers to IETF draft authors says so in writing. The right question is which parts of the stack finally exist and which parts remain aspirational.\\u003c/p\\u003e\\n\\u003cp\\u003eMy answer today: enterprise authorization for MCP exists and works. A serious foundation for inter-agent trust exists in A2A v1.0. Measured proposals exist for task scoping and verifiable delegation. What still doesn't exist is the layer that binds them into an interoperable default: identity per running instance, authority that attenuates correctly across multi-hop delegation and provenance you can audit end to end without trusting every intermediary.\\u003c/p\\u003e\\n\\u003cp\\u003eIn March I wrote that the best time to close this gap was before deployment, and the second best time was now. That line deserves an update. We're no longer starting from zero. We're starting from an ecosystem that finally admits, in specs and in code, that an agent can't keep being treated as a weird user or as just another service. An agent needs verifiable identity, bounded authority and auditable provenance. Until that's the default behavior in production, the crisis hasn't ended. It has started to professionalize.\\u003c/p\\u003e\\n\\u003chr\\u003e\\n\\u003ch2 id=\\\"h-references\\\"\\u003eReferences\\u003c/h2\\u003e\\n\\u003cul\\u003e\\n\\u003cli\\u003eOriginal article: \\u003ca href=\\\"https://hackernoon.com/ai-agents-dont-have-identities-and-thats-a-security-crisis\\\"\\u003eAI Agents Don't Have Identities, and That's a Security Crisis\\u003c/a\\u003e (HackerNoon, March 2026)\\u003c/li\\u003e\\n\\u003cli\\u003e\\u003ca href=\\\"https://blog.modelcontextprotocol.io/\\\"\\u003eThe 2026 MCP Roadmap\\u003c/a\\u003e (MCP Blog, March 9, 2026)\\u003c/li\\u003e\\n\\u003cli\\u003e\\u003ca href=\\\"https://a2a-protocol.org/latest/announcing-1.0/\\\"\\u003eA2A Protocol v1.0 announcement\\u003c/a\\u003e and \\u003ca href=\\\"https://a2a-protocol.org/latest/whats-new-v1/\\\"\\u003eWhat's New in v1.0\\u003c/a\\u003e\\u003c/li\\u003e\\n\\u003cli\\u003e\\u003ca href=\\\"https://arxiv.org/abs/2603.17170\\\"\\u003ePAuth: Precise Task-Scoped Authorization For Agents\\u003c/a\\u003e (arXiv, March 17, 2026)\\u003c/li\\u003e\\n\\u003cli\\u003e\\u003ca href=\\\"https://arxiv.org/abs/2603.24775\\\"\\u003eAIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A\\u003c/a\\u003e (arXiv, March 25, 2026) and \\u003ca href=\\\"https://datatracker.ietf.org/doc/draft-prakash-aip/\\\"\\u003eIETF draft-prakash-aip\\u003c/a\\u003e\\u003c/li\\u003e\\n\\u003cli\\u003e\\u003ca href=\\\"https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/\\\"\\u003eThe 2026-07-28 MCP Specification Release Candidate\\u003c/a\\u003e (MCP Blog, May 21, 2026)\\u003c/li\\u003e\\n\\u003cli\\u003e\\u003ca href=\\\"https://blog.modelcontextprotocol.io/posts/enterprise-managed-auth/\\\"\\u003eEnterprise-Managed Authorization: Zero-touch OAuth for MCP\\u003c/a\\u003e (MCP Blog, June 18, 2026)\\u003c/li\\u003e\\n\\u003c/ul\\u003e\\n\\u003cp\\u003e\\u003c/p\\u003e\\u003cp\\u003e\\u003c/p\\u003e\",\"profile\":{\"handle\":\"garagon\",\"displayName\":\"Gus Aragón\",\"bio\":\"Founder @ Oktsec | Security for AI agent work | AAIF Ambassador | Cybersecurity | Open Source\",\"avatar\":\"https://cdn.hackernoon.com/images/v9PFbuka6VdBHUxyM4afyDLGViL2-3c83brv.jpeg\",\"isBrand\":false,\"currentJob\":{\"title\":\"Founder\",\"company\":\"Oktsec.com\",\"startDate\":\"\"},\"jobHistory\":[{\"title\":\"\",\"company\":\"\",\"startDate\":\"\",\"endDate\":\"\"}],\"about_page_settings\":{\"blocked\":false,\"createdAt\":\"2026-03-16T18:44:53.183Z\",\"updatedAt\":\"2026-03-16T18:44:53.183Z\",\"style\":{\"headline_pos\":\"center\",\"layout\":0,\"skin\":0},\"published\":true,\"owner\":\"v9PFbuka6VdBHUxyM4afyDLGViL2\"},\"callToActions\":[{\"active\":true,\"icon\":\"fa fa-book\",\"name\":\"Read My Stories\",\"url\":\"https://hackernoon.com/u/garagon\",\"id\":\"b9f516cff044\"}],\"isTrusted\":false,\"allowSubscribers\":true},\"publishedAt\":1783774846.362,\"super_category\":\"cybersecurity\",\"tags\":[\"ai-agents\",\"ai-security\",\"a2a-protocol\",\"mcp-server\",\"ai-agent-identity\",\"oauth-2.1\",\"enterprise-ai\",\"hackernoon-top-story\"],\"title\":\"The Identity Layer for AI Agents Is Finally Being Built\",\"tldr\":\"In March I wrote that AI agents lack verifiable identity and called it a security crisis. Four months later the diagnosis holds, but the ecosystem started to respond. MCP made authorization a first-class roadmap item and shipped Enterprise-Managed Authorization. A2A reached v1.0 with signed Agent Cards and modern OAuth. Research delivered task-scoped authorization and verifiable delegation chains. Still missing: per-instance identity, multi-hop attenuation and end-to-end provenance.\",\"youtubeTranscriptData\":null,\"backlinks\":{\"fetched\":\"2026-07-11T13:00:48.823Z\",\"urls\":[\"https://x.com/hackernoon/status/2075928290527711652\",\"https://bsky.app/profile/hackernoon.com/post/3mqept4jtwq23\",\"https://mas.to/@hackernoon/116901468483736136\"]},\"parentCategory\":\"machine-learning\",\"translation\":{\"en\":{\"code\":\"en\",\"name\":\"English\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"The Identity Layer for AI Agents Is Finally Being Built\",\"flag\":\"https://cdn.hackernoon.com/images/usa_flag.webp\",\"enLangTooltip\":\"Read this story in the original language, English!\"},\"es\":{\"code\":\"es\",\"name\":\"Spanish\",\"flag\":\"https://cdn.hackernoon.com/images/spain_flag.webp\",\"esLangTooltip\":\"Lee esta historia en Español!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"La Capa de Identidad para los Agentes de Inteligencia Artificial se está construyendo finalmente.\"},\"ja\":{\"code\":\"ja\",\"name\":\"Japanese\",\"flag\":\"https://cdn.hackernoon.com/flags/japanese_20jtajj.png\",\"jaLangTooltip\":\"この物語を日本語で読んでください！\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"AIエージェント用アイデンティティレイヤーがついに構築されている\"},\"hr\":{\"code\":\"hr\",\"name\":\"Croatian\",\"flag\":\"https://cdn.hackernoon.com/flags/croatian_bmb27tbg.png\",\"hrLangTooltip\":\"Pročitajte ovu priču na hrvatskom!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"Identitetni sloj za agente umjetne inteligencije konačno se gradi\"},\"fr\":{\"code\":\"fr\",\"name\":\"French\",\"flag\":\"https://cdn.hackernoon.com/images/fr_flag.webp\",\"frLangTooltip\":\"Lisez cette histoire en Français!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"La Couche d'identité pour les agents d'IA est enfin en cours de construction\"},\"zh\":{\"code\":\"zh\",\"name\":\"Chinese\",\"flag\":\"https://cdn.hackernoon.com/flags/chinese_vri67rp8.png\",\"zhLangTooltip\":\"用繁體中文閱讀這個故事！\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"AI代理的身份层终于开始建设\"},\"ps\":{\"code\":\"ps\",\"name\":\"Pashto\",\"flag\":\"https://cdn.hackernoon.com/images/afghanistan.jpg\",\"psLangTooltip\":\"دا کیسه په پښتو ژبه ولولئ!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"اېډنټيتي لایر د AI چارواکي لاء د نهري د بݔر کېږي\"},\"el\":{\"code\":\"el\",\"name\":\"Greek\",\"flag\":\"https://cdn.hackernoon.com/flags/greek_696idl18.png\",\"elLangTooltip\":\"Διαβάστε αυτή την ιστορία στα ελληνικά!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"Το Στρώμα Ταυτότητας για τους πράκτορες της τεχνητής νοημοσύνης τελικά κατασκευάζεται.\"},\"ca\":{\"code\":\"ca\",\"name\":\"Catalan\",\"flag\":\"https://cdn.hackernoon.com/flags/catalan_vidt0k2g.png\",\"caLangTooltip\":\"Llegeix aquesta història a Català!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"La Capa d'Identitat per a agents d'IA s'està construint finalment.\"},\"ko\":{\"code\":\"ko\",\"name\":\"Korean\",\"flag\":\"https://cdn.hackernoon.com/flags/korean_rceor8o8.png\",\"koLangTooltip\":\"이 이야기를 한국어로 읽어보세요!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"AI 에이전트용 신원 계층이 드디어 구축되고 있다\"},\"be\":{\"code\":\"be\",\"name\":\"Belarusian\",\"flag\":\"https://cdn.hackernoon.com/flags/belarusian_68crd5o8.png\",\"beLangTooltip\":\"Прачытайце гэтае апавяданне па-беларуску!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"Слой ідэнтыфікацыі для агентаў штучнага інтелекту насамрэч будуецца.\"},\"lo\":{\"code\":\"lo\",\"name\":\"Lao\",\"flag\":\"https://cdn.hackernoon.com/flags/lao_plfjm3t.png\",\"loLangTooltip\":\"ອ່ານເລື່ອງນີ້ເປັນພາສາລາວ!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"ຊັ້ນຄວາມຕົວຕິດຕໍ່ສຳລັບຕົວແທນ AI ໄດ້ຖືກສ້າງຂື້ນໃນທີ່ສຸດ\"},\"ru\":{\"code\":\"ru\",\"name\":\"Russian\",\"flag\":\"https://cdn.hackernoon.com/flags/russian_uchb3r98.png\",\"ruLangTooltip\":\"Прочтите эту историю на русском языке!\",\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\",\"title\":\"Слой идентичности для агентов ИИ наконец-то создаётся\"}},\"mentions\":[{\"name\":\"Okta\",\"id\":\"okta\",\"collection\":\"companies\",\"image\":\"https://cdn.hackernoon.com/images/img-bz03b5j.jpeg\",\"filtered\":false,\"manual\":false}],\"annotations\":[],\"coAuthorProfiles\":[],\"commentsCount\":2,\"fromMongo\":true,\"relatedStories\":[{\"title\":\"Agents 101 — Build and Deploy AI Agents to Production using LangChain\",\"mainImage\":\"https://cdn.hackernoon.com/images/AGr8KngsfDgFeQNG1b8p0b616hy2-wq03cch.png\",\"slug\":\"agents-101-build-and-deploy-ai-agents-to-production-using-langchain\",\"tags\":[\"ai-agent\",\"langchain\",\"langchain-tutuorial\",\"agentic-ai\",\"machine-learning\",\"artificial-intelligence\",\"llms\",\"large-language-models\"],\"excerpt\":\"Learn how Langchain turns a simple prompt into a fully functional AI agent that can think, act and remember.\",\"publishedAt\":1764132967382,\"profile\":{\"handle\":\"manishmshiva\",\"avatar\":\"https://cdn.hackernoon.com/images/AGr8KngsfDgFeQNG1b8p0b616hy2-hf031tc.png\",\"displayName\":\"Manish Shivanandhan\",\"isBrand\":false},\"recommended\":true},{\"title\":\"Agents Unleashed Podcast: Inside the Decentralized AI Revolution Challenging Big Tech\",\"mainImage\":\"https://cdn.hackernoon.com/images/InxBRjRIs6M1kdhuWcyNHiiUrxm1-ie038gc.png\",\"slug\":\"agents-unleashed-podcast-inside-the-decentralized-ai-revolution-challenging-big-tech\",\"tags\":[\"agents-unleashed-podcast\",\"decentralized-ai-podcast\",\"olas-protocol\",\"co-owned-ai-agents\",\"crypto-ai-agents\",\"agent-economy\",\"autonomous-agent-coordination\",\"good-company\"],\"excerpt\":\"Agents Unleashed Podcast dives into decentralized AI, crypto agents, and co-owned infrastructure—giving builders a weekly pulse on the open AI movement.\\n\\n\",\"publishedAt\":1751348537317,\"profile\":{\"handle\":\"jonstojanjournalist\",\"avatar\":\"https://cdn.hackernoon.com/images/4HK5qyMbWfetPhAavzyTZrEb90N2-dv93t6b.jpeg\",\"displayName\":\"Jon Stojan Journalist\",\"isBrand\":true},\"recommended\":true},{\"title\":\"AI Agent Testing \\u0026 Testing of AI Agents: Two Sides of the Same Coin \",\"mainImage\":\"https://cdn.hackernoon.com/images/UwJZOcrJheRf65u8OwvCIXQGAVh1-mn83dy2.jpeg\",\"slug\":\"testing-ai-agents-and-testing-with-ai-agents-are-two-sides-of-the-same-coin\",\"tags\":[\"ai-testing\",\"ai-agent-testing\",\"software-testing\",\"qa-best-practices\",\"llm\",\"qa-engineering\",\"testing-of-ai-agents\",\"modern-engineering-teams\"],\"excerpt\":\"Traditional QA frameworks break under probabilistic AI systems. Discover how to test with AI agents and rigorously evaluate them before they hit production.\",\"profile\":{\"handle\":\"sahilthakurseasia\",\"avatar\":\"https://cdn.hackernoon.com/images/undefined-8183mcl.jpeg\",\"displayName\":\"Sahil Thakur\"},\"recommended\":true},{\"title\":\"AI Agents \\u0026 Non-Human Identities: Why They Must Be IAM Users\",\"mainImage\":\"https://cdn.hackernoon.com/images/InxBRjRIs6M1kdhuWcyNHiiUrxm1-jn83bgq.png\",\"slug\":\"ai-agents-and-non-human-identities-why-they-must-be-iam-users\",\"tags\":[\"identity-and-access-management\",\"non-human-identity\",\"enterprise-security\",\"autonomous-ai-agent-identity\",\"machine-identity-management\",\"enterprise-iam-for-ai-agents\",\"ai-access-governance\",\"agentic-ai-security\"],\"excerpt\":\"AI agents and non-human identities must exist as first-class IAM users before they act. Start with auditability, access review, and governance in your IAM.\",\"publishedAt\":1784579598167,\"profile\":{\"handle\":\"sebastianmartinez\",\"avatar\":\"https://cdn.hackernoon.com/images/O2fUY2CJvlNKbCnxvP09hPZYkj92-058210q.jpeg\",\"displayName\":\"Sebastian Martinez Torregrosa\"},\"recommended\":true},{\"title\":\"AI Agents and ADHD Brains Break in the Same Ways\",\"mainImage\":\"https://cdn.hackernoon.com/images/a-human-brain-and-a-digital-neural-network-side-by-side-both-showing-fragmented-connections-being-stabilized-by-structured-external-systems-no-text-silv27qp59293w8ci23rx61f.png\",\"slug\":\"ai-agents-and-adhd-brains-break-in-the-same-ways\",\"tags\":[\"ai-governance\",\"agentic-ai\",\"llm-failure-modes\",\"ai-context-loss\",\"ai-governance-patterns\",\"human-cognition-vs-ai\",\"external-memory-systems\",\"ai-drift\"],\"excerpt\":\"ADHD and AI share failure modes like context loss and drift. The same governance systems can improve reliability in both.\",\"publishedAt\":1776607199538,\"profile\":{\"handle\":\"avanrossum\",\"avatar\":\"https://lh3.googleusercontent.com/a/ACg8ocKZXEmPCHL9x02t641VY4iPeGuzmJlaRowAHqYD3N1_o7U85AU=s96-c\",\"displayName\":\"Alexander van Rossum\"},\"recommended\":true},{\"title\":\"AI Agents and Smart Contracts Set the Stage for Micro-Transaction Economy\",\"mainImage\":\"https://cdn.hackernoon.com/images/22qULrU2ZPb8VRsSedCeA6x7AJ13-0y238el.png\",\"slug\":\"ai-agents-and-smart-contracts-set-the-stage-for-micro-transaction-economy\",\"tags\":[\"ai\",\"agentic-ai\",\"microtransactions\",\"smart-contracts\",\"stablecoin\",\"crypto\",\"autonomous-ai-agents-payment\",\"blockchain-smart-contracts-ai\"],\"excerpt\":\"In the age of AI, the full potential of blockchain-enabled smart contracts will finally be realized.\",\"publishedAt\":1749025885341,\"profile\":{\"handle\":\"shaanray\",\"avatar\":\"https://hackernoon.com/images/avatars/22qULrU2ZPb8VRsSedCeA6x7AJ13.jpg\",\"displayName\":\"Shaan Ray\",\"isBrand\":false},\"recommended\":true},{\"title\":\"AI Agents and Smart Glasses Could Redesign the Buying Experience\",\"mainImage\":\"https://cdn.hackernoon.com/images/0aUsM51TYCYZBivPJwh7zf52flH3-ud038s9.png\",\"slug\":\"ai-agents-and-smart-glasses-could-redesign-the-buying-experience\",\"tags\":[\"ai-agents\",\"ecommerce\",\"augmented-reality\",\"machine-learning\",\"smart-glasses\",\"ai-augmented-reality\",\"ai-smart-glasses\",\"ai-buying-experience\"],\"excerpt\":\"AI agents + smart glasses are changing how we shop. From visual input to checkout, here’s how I prototyped the future of buying.\",\"publishedAt\":1748019861979,\"profile\":{\"handle\":\"srikrishnajayaram\",\"avatar\":\"https://cdn.hackernoon.com/images/undefined-pz83u10.jpeg\",\"displayName\":\"Srikrishna Jayaram \",\"isBrand\":false},\"recommended\":true},{\"title\":\"AI Agents and the End of Artisan Coding\",\"mainImage\":\"https://images.unsplash.com/photo-1548076805-5f8d6345df31?crop=entropy\\u0026amp;cs=tinysrgb\\u0026amp;fit=max\\u0026amp;fm=jpg\\u0026amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDY0fHxtdWx0aXBseXxlbnwwfHx8fDE3NjkwNDkzODZ8MA\\u0026amp;ixlib=rb-4.1.0\\u0026amp;q=80\\u0026amp;w=2000\",\"slug\":\"ai-agents-and-the-end-of-artisan-coding\",\"tags\":[\"ai-agent\",\"ai-coding-agents\",\"claude-code\",\"cloud-computing\",\"context-engineering\",\"ai-software-development\",\"developer-productivity\",\"ai-devops\"],\"excerpt\":\"How AI coding agents like Claude Code turn developers into CTOs—scaling projects with CI/CD pipelines, parallel sprints, and 10x test coverage.\",\"profile\":{\"handle\":\"anson\",\"avatar\":\"https://avatars.githubusercontent.com/u/4317872?v=4\",\"displayName\":\"Anson\"},\"recommended\":true},{\"title\":\"AI Agents and the End of Work as We Know It\",\"mainImage\":\"https://cdn.hackernoon.com/images/iN6H2UigxKapyOHZ6k4N9srFgsw1-x7039z6.png\",\"slug\":\"ai-agents-and-the-end-of-work-as-we-know-it\",\"tags\":[\"ai\",\"future-of-work\",\"ai-agent\",\"ai-job-disruption\",\"ai-replacing-human-jobs\",\"future-of-work-with-ai\",\"ai-automation-and-jobs\",\"ai-powered-job-loss\"],\"excerpt\":\"AI agents are transforming industries, replacing jobs, and redefining the future of work. Here’s what this means for careers, businesses, and society.\",\"publishedAt\":1752627690021,\"profile\":{\"handle\":\"hacker-Antho\",\"avatar\":\"https://cdn.hackernoon.com/images/iN6H2UigxKapyOHZ6k4N9srFgsw1-3a03zly.jpeg\",\"displayName\":\"Anthony Laneau\",\"isBrand\":false},\"recommended\":true},{\"title\":\"AI Agents Are a Scam: How Tech Bros Derailed Your JARVIS Future\",\"mainImage\":\"https://cdn.hackernoon.com/images/S78E4VTqvyTEfOPMpOp9EFYywDJ2_muc2egag.jpeg\",\"slug\":\"ai-agents-are-a-scam-how-tech-bros-derailed-your-jarvis-future\",\"tags\":[\"artificial-intelligence\",\"ai-agents\",\"creating-ai-agents\",\"ai-agents-at-work\",\"ai-agents-in-the-office\",\"specialized-ai-agents\",\"the-ai-broken-dream\",\"hackernoon-top-story\"],\"excerpt\":\"The uncomfortable truth about AI agents: How Silicon Valley killed your JARVIS dreams for profit.\",\"publishedAt\":1736276408922,\"profile\":{\"handle\":\"juancguerrero\",\"avatar\":\"https://cdn.hackernoon.com/images/S78E4VTqvyTEfOPMpOp9EFYywDJ2-m492nyi.jpeg\",\"displayName\":\"Juan C. Guerrero\",\"isBrand\":false},\"recommended\":true},{\"title\":\"AI Agents Are Coming for Crypto’s Blockspace\",\"mainImage\":\"https://cdn.hackernoon.com/images/a-futuristic-blockchain-network-visualized-as-a-high-speed-digital-auction-with-autonomous-ai-agents-competing-in-real-time-using-glowing-data-streams-and-transaction-flows-dgdb0tglifcwjcaob8ho3z1x.png\",\"slug\":\"ai-agents-are-coming-for-cryptos-blockspace\",\"tags\":[\"ai-agents-in-crypto\",\"blockspace-economics\",\"mev-strategies\",\"blockchain-fee-markets\",\"crypto-infrastructure\",\"autonomous-trading-agents\",\"validator-economics\",\"hackernoon-top-story\"],\"excerpt\":\"AI agents will compete for blockspace, not just use it. As they optimize fee markets, MEV, and execution, crypto becomes more competitive.\",\"publishedAt\":1775728312647,\"profile\":{\"handle\":\"valens\",\"avatar\":\"https://cdn.hackernoon.com/images/21tY9QbSoRN0eiXS3YPCZh2T2Fh2-xx136w1.jpeg\",\"displayName\":\"Valentina Rivas\"},\"recommended\":true},{\"title\":\"AI Agents Are Great at One Thing at a Time. Life Isn't Built That Way.\",\"mainImage\":\"https://cdn.hackernoon.com/images/InxBRjRIs6M1kdhuWcyNHiiUrxm1-bo93egl.jpeg\",\"slug\":\"ai-agents-are-great-at-one-thing-at-a-time-life-isnt-built-that-way\",\"tags\":[\"tethral-ai-orchestration\",\"ai-agent-coordination\",\"ai-smart-home-automation\",\"ai-systems-runtime\",\"iot-protocol-orchestration\",\"multi-agent-architecture\",\"tethral-ai-research\",\"good-company\"],\"excerpt\":\"AI agents can handle single tasks, but real-world automation requires coordination across devices and protocols. Tethral aims to solve this.\",\"publishedAt\":1773741604549,\"profile\":{\"handle\":\"jonstojanjournalist\",\"avatar\":\"https://cdn.hackernoon.com/images/4HK5qyMbWfetPhAavzyTZrEb90N2-dv93t6b.jpeg\",\"displayName\":\"Jon Stojan Journalist\",\"isBrand\":true},\"recommended\":true},{\"title\":\"AI Agents Are Growing Up - And They Need Zero-Trust Parenting\",\"mainImage\":\"https://cdn.hackernoon.com/images/xMFozA8xFqPickG9TmjRqH6mmCS2-5z039sm.jpeg\",\"slug\":\"ai-agents-are-growing-up-and-they-need-zero-trust-parenting\",\"tags\":[\"ai-agent\",\"ai-security\",\"cyber-security\",\"risk-management\",\"ai\",\"autonomous-agents\",\"cybersecurity\",\"ai-cybersecurity\"],\"excerpt\":\"AI is evolving fast, but security isn’t keeping up. Discover why zero-trust architecture is critical for safe, scalable AI agent deployment.\",\"publishedAt\":1752735932258,\"profile\":{\"handle\":\"arjun-subedi\",\"avatar\":\"https://cdn.hackernoon.com/avatars/xMFozA8xFqPickG9TmjRqH6mmCS2.png\",\"displayName\":\"Arjun Subedi\",\"isBrand\":false},\"recommended\":true}],\"previousRead\":{\"slug\":\"ai-agents-dont-have-identities-and-thats-a-security-crisis\",\"mainImage\":\"https://cdn.hackernoon.com/images/v9PFbuka6VdBHUxyM4afyDLGViL2-f083gn7.jpeg\",\"owner\":\"v9PFbuka6VdBHUxyM4afyDLGViL2\",\"title\":\"AI Agents Don’t Have Identities and That’s a Security Crisis\"},\"staticData\":{\"frLangTooltip\":\"Lisez cette histoire en Français!\",\"about\":\"About\",\"enLangTooltip\":\"Read this story in the original language, English!\",\"loggedOutBookmark\":\"Create an account to store your bookmarks\",\"learnMore\":\"Learn More\",\"stats\":\"Stats\",\"editStory\":\"Edit Story\",\"audioPresented\":\"Audio Presented by\",\"by\":\"by\",\"audioTranslationText\":null,\"newStory\":\"New Story\",\"loggedInBookmark\":\"Bookmark story\",\"esLangTooltip\":\"Lee esta historia en Español!\",\"relatedStories\":\"RELATED STORIES\",\"addComment\":\"Add Comment\",\"ptLangTooltip\":\"Leia esta história em português!\",\"hiLangTooltip\":\"इस कहानी को हिंदी में पढ़ें!\",\"comments\":\"Comments\",\"removeBookmark\":\"Remove bookmark\",\"commentReply\":\"Reply\",\"minutes\":\"min\",\"reads\":\"reads\",\"trLangTooltip\":\"Bu hikayeyi Türkçe okuyun!\",\"tags\":\"TOPICS\",\"jaLangTooltip\":\"この物語を日本語で読んでください！\",\"bnLangTooltip\":\"এই গল্পটি বাংলায় পড়ুন!\",\"storyMentions\":\"MENTIONED IN THIS STORY\",\"ruLangTooltip\":\"Прочтите эту историю на русском языке!\",\"deLangTooltip\":\"Lesen Sie diese Geschichte auf Deutsch!\",\"featuredIn\":\"THIS ARTICLE WAS FEATURED IN\",\"tldrTitle\":\"Too Long; Didn't Read\",\"koLangTooltip\":\"이 이야기를 한국어로 읽어보세요!\",\"zhLangTooltip\":\"用繁體中文閱讀這個故事！\",\"viLangTooltip\":\"Đọc bài viết này bằng tiếng Việt!\"},\"searchTopics\":[\"ai agents\"],\"stats\":{\"pageviews\":2419},\"socialPreviewImage\":\"https://hackernoon.imgix.net/images/v9PFbuka6VdBHUxyM4afyDLGViL2-9i83bw9.png\",\"audioData\":[{\"url\":\"https://storage.googleapis.com/hackernoon/audios/6a45bd39acdf1c8e2e7d18d3-en-US-Wavenet-I-MALE--3d47727880fa8.mp3\",\"nickname\":\"Dr. One (en-US)\",\"avatar\":\"https://cdn.hackernoon.com/avatars/robot-b5.png\",\"audioPath\":\"audios/6a45bd39acdf1c8e2e7d18d3-en-US-Wavenet-I-MALE--3d47727880fa8.mp3\"},{\"url\":\"https://storage.googleapis.com/hackernoon/audios/6a45bd39acdf1c8e2e7d18d3-en-US-Wavenet-H-FEMALE--4e288e9f6bd86.mp3\",\"nickname\":\"Ms. Hacker (en-US)\",\"avatar\":\"https://cdn.hackernoon.com/avatars/robot-b6.png\",\"audioPath\":\"audios/6a45bd39acdf1c8e2e7d18d3-en-US-Wavenet-H-FEMALE--4e288e9f6bd86.mp3\"}]},\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\"},\"__N_SSG\":true},\"page\":\"/[slug]\",\"query\":{\"slug\":\"the-identity-layer-for-ai-agents-is-finally-being-built\"},\"buildId\":\"Xk2r7uR-ZJNVqZdnbVuTv\",\"isFallback\":false,\"isExperimentalCompile\":false,\"dynamicIds\":[77618,63213,87127,71206,89752,41116,31486,42348],\"gsp\":true,\"scriptLoader\":[]}</script><script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML=\"window.__CF$cv$params={r:'a225c8898db357a9',t:'MTc4NTI2MTYyNQ=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);\";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body></html>","snapshot_chars":147291,"live_check":"changed"}]}