Identity · CA
ITU Opens a Standards Track for Agent Identity, With the Hard Questions Still Unsettled
On July 9, 2026, the ITU announced its Focus Group on Trust and Identity for Humans and Agentic AI, a new effort to build international frameworks for verifying who an autonomous agent is and whether it can be trusted. The group will report to ITU-T Study Group 17, the security standardization body, with its first meeting set for Paris in November 2026 and a second in Geneva in January 2027.
The scope is broad: common terminology, identity and trust architectures, agent discovery, credential interoperability, lifecycle models, security criteria, and benchmarks. That's the right list of problems. A bank, platform, or government service needs a way to tell an authorized agent from an impersonator, and right now there's no shared way to do that across organizational boundaries.
But the framework question is not just technical. Who issues these credentials, which organizations have to recognize them, how much they reveal about the agent or its principal, and who can revoke them — those are governance decisions, not protocol details. A narrow, purpose-bound credential that lets an agent prove limited authority for one action is very different from a universal admission system controlled by a handful of platforms or governments deciding which agents count as legitimate.
This lands in the middle of a busier identity landscape than it might appear. NIST's own AI Agent Standards Initiative, launched in February, has already flagged agent identity and authorization as a core research priority. The Decentralized Identity Foundation is stewarding the MCP-I framework (now renamed KYA-OS), which uses DIDs and verifiable credentials to answer four questions any relying party should be able to answer about an agent: who it is, who authorized it, what it's allowed to do, and the scope of that delegation. Microsoft's Entra Agent ID and various enterprise identity vendors are shipping narrower, single-perimeter versions of the same idea.
The ITU effort is notable less for technical novelty and more for scope: it's an attempt at an international, cross-jurisdictional layer rather than a vendor-specific or single-government one. Given how fragmented agent identity already is — one identity inside a cloud platform, another inside an enterprise, different credentials across every tool an agent touches — a body whose job is literally security standardization taking this on is a meaningful data point. Whether it produces something narrow and revocable, or something closer to a global admission list, will depend on decisions the focus group hasn't made yet. Worth watching what comes out of Paris in November.
Developers building agents today shouldn't wait for this to resolve. The near-term fix — issuing agents their own scoped, short-lived credentials instead of borrowed human sessions — is already available and doesn't depend on any international standard landing first.