Identity · CA
ITU Opens a Standards Track for Agent Identity and Trust
On July 9, 2026, the International Telecommunication Union announced a new effort to develop international frameworks for the identity and trustworthiness of autonomous AI agents. This is a notable move: it puts agent identity on the agenda of a UN-affiliated standards body rather than leaving it entirely to vendors and industry consortia.
The new body is the ITU's Focus Group on Trust and Identity for Humans and Agentic AI, which will report to ITU-T Study Group 17, the study group responsible for security standardization. Its scope is broad — the group is expected to study common terminology, identity and trust architectures, agent discovery, credential interoperability, lifecycle models, security criteria, and benchmarks, working toward a roadmap for future standards. The first meeting is scheduled for Paris in November 2026, with a second in Geneva in January 2027.
Importantly, as of mid-July the initiative does not require developers to register an agent, connect it to a government identity, or seek approval before running it locally — so this is a standards-track exercise, not a licensing regime, at least for now.
The real stakes aren't whether agents need better credentials — they clearly do, so a bank, platform, or government service can tell an authorized agent from an impersonator. The stakes are who gets to issue those credentials, which institutions are obligated to recognize them, how much information a credential leaks about the agent or its principal, and who holds the power to revoke it. A well-designed standard lets an agent prove narrow, task-specific authority without exposing more than necessary. A poorly designed one risks becoming a gatekeeping layer where a handful of platforms, governments, or identity vendors decide which agents are allowed to exist in polite society.
This lands alongside a parallel industry push — NIST's AI Agent Standards Initiative, the DIF's Trusted AI Agents Working Group, and Microsoft's Entra Agent ID — all converging on the same underlying problem: agents acting on behalf of humans need identities that are scoped, short-lived, and revocable rather than borrowed human credentials. The ITU's entry adds a multilateral, treaty-body track to a conversation that has so far been driven mostly by corporate consortia. Whether that produces a genuinely open credential-issuance model or just a new layer of institutional gatekeepers will depend on who shows up to the Paris meeting in November.