Identity · CA
ITU Opens the Question of Who Issues AI Agent Passports
On July 9, 2026, the International Telecommunication Union announced a new effort to develop international frameworks for the identity and trustworthiness of autonomous AI agents, launching a Focus Group on Trust and Identity for Humans and Agentic AI. The stated goal is straightforward: give banks, platforms, and government services a way to distinguish an authorized agent from an impersonator, and give those institutions grounds to decide which agents they'll let operate at all.
The interesting part isn't that agents need credentials — that's now assumed across the industry. It's who gets to hand them out. A workable identity layer needs to let an agent prove narrow, task-specific authority without exposing everything else about who's behind it. But identity standards are also chokepoints. An open technical spec can still produce a closed market if only a handful of large platforms or governments end up recognized as valid issuers — at that point, credential recognition, not the standard itself, becomes the real point of control.
This tension isn't hypothetical. The ITU's move follows a busy few months of overlapping identity efforts: Microsoft's Entra Agent ID went generally available in May, giving agents identities scoped to blueprints rather than standalone keys; the Cloud Security Alliance published its Agentic Trust Framework in February; and in March, Vouched donated the MCP-Identity framework to the Decentralized Identity Foundation, where it's now being stewarded — and renamed KYA-OS — by DIF's Trusted AI Agents Working Group. Each of these solves identity within a bounded scope: one vendor's cloud, one working group's spec. None of them settle the cross-jurisdictional question ITU is now trying to take on.
What a good outcome looks like is fairly well specified even if nobody's built it: multiple issuers instead of one, pseudonymous identities where privacy matters, selective disclosure so an agent reveals only what a transaction requires, short-lived permissions instead of standing credentials, and revocation that actually propagates. What a bad outcome looks like is also easy to name — a de facto admission system where a small set of vendors or governments decide which software is allowed to act on your behalf.
None of this is settled yet. ITU focus groups typically run for a defined study period before producing recommendations, not binding rules, so the practical effect of this announcement is an agenda-setting move rather than a deployed standard. But it puts a UN body's name on a question that, until now, mostly enterprise vendors and industry consortia were answering on their own terms.