Identity · CA
ITU Opens Standards Effort for Agent Identity and Trustworthiness
On July 9, 2026, the International Telecommunication Union announced a new effort to develop international frameworks for the identity and trustworthiness of autonomous AI agents. The initiative doesn't mandate registration: as of July 16, developers aren't required to register an agent, tie it to a government identity, or seek approval before running it locally. That restraint is deliberate — early standards work shapes what comes later, and the technical choices made now will determine which credential issuers get trusted and which agents get locked out once institutions start requiring compliance.
The timing lines up with a broader scramble to fix a real gap: an agent can present a valid credential while acting outside the scope, time window, or spending limit it was actually issued for. Current IETF draft work on agent authentication and authorization is already trying to separate the question 'is this agent real' from 'is this agent allowed to do this specific thing right now' — two questions that existing web identity standards conflate.
The ITU's framing raises the governance question more than it answers it. Better agent credentials are clearly needed — that part isn't controversial. The harder questions are who issues them, which organizations are obligated to recognize them, how much they reveal about the underlying operator or user, and who holds revocation authority. A standard built around narrow, provable authority for a specific action is very different from one that functions as a universal admission ticket once accepted broadly. Given that ITU frameworks tend to become reference points for national regulators, the design decisions made in this early phase — before any enforcement mechanism exists — are likely to outlast the current voluntary framing.
This sits squarely in identity infrastructure rather than the adjacent world of signed receipts and audit trails that's developing in parallel (x401, Handshake, Agent Receipts, and IETF's delegation-receipt draft are all pushing on the accountability side). The ITU move is about establishing who an agent is and who authorized it — the prerequisite layer that those attestation systems build on top of. Whether it produces an interoperable, privacy-respecting standard or a de facto gatekeeping regime depends on details the ITU hasn't published yet.