Identity · CA
ITU Opens a Front on Who Gets to Issue Agent Credentials
On July 9, 2026, the International Telecommunication Union announced a new effort to develop international frameworks for the identity and trustworthiness of autonomous AI agents. The initiative, a Focus Group on Trust and Identity for Humans and Agentic AI, is meant to give banks, platforms, and governments a way to tell an authorized agent from an impersonator, and could shape which agents institutions choose to permit at all.
This lands amid a crowded, fragmented push toward agent identity standards this year — NIST's Agent Identity and Authorization concept paper, Microsoft's Entra Agent ID, CrowdStrike's SPIFFE-based Continuous Identity, the DIF's KYA-OS spec, and Proof's x401 protocol, among others. None of these efforts talk to each other by default, which is exactly the gap ITU is stepping into. The group is expected to study common terminology, identity and trust architectures, agent discovery, credential interoperability, lifecycle models, security criteria, benchmarks, and a roadmap for future standards.
The interesting part isn't the technical scope — it's the governance question underneath it. A good identity standard would let an agent prove narrow, task-specific authority without exposing more than necessary. A bad one could turn into an admission system controlled by a small set of platforms, governments, or identity vendors deciding which agents are allowed to exist in a given context. The harder questions are who gets to issue those credentials, which organizations must recognize them, how much information they reveal, and who can revoke them.
That control-point risk is concrete, not abstract: an open technical standard can still produce a closed ecosystem if major services only accept credentials from a short list of issuers. The credible fix — multiple issuers, pseudonymous identities, selective disclosure, short-lived permissions, transparent revocation, and offline validation — is a design checklist, not a guarantee. ITU convening a focus group doesn't settle any of it; it just puts an international standards body's weight behind the question at the same moment commercial vendors are racing to ship competing answers.
Worth watching over the next few months: whether ITU's work ends up complementary to NIST's domestic track and the DIF's credential specs, or whether it becomes another parallel standard agents have to support alongside everything else. The article covering this notes that developers should already be moving away from giving agents reusable human credentials, issuing each production agent limited authority for a defined task, resource, and duration — a practice that will matter regardless of which standards body eventually wins.