Identity · CA
The ITU Opens a Fight Over Who Issues AI Agents Their Passports
On July 9, 2026, the International Telecommunication Union announced it is standing up a Focus Group on Trust and Identity for Humans and Agentic AI, aiming to develop international frameworks for how autonomous agents prove who they are. The stated goal is to let a bank, platform, or government service tell an authorized agent apart from an impersonator, and to shape which agents get permitted to operate at all.
The group's charter is broad: it will study common terminology, identity and trust architectures, agent discovery, credential interoperability, lifecycle models, security criteria, and benchmarks on the way to a roadmap for future standards. That scope puts the ITU alongside a growing list of parallel efforts — NIST's AI Agent Standards Initiative, the Decentralized Identity Foundation's work absorbing the MCP-Identity framework, and Microsoft's Entra Agent ID — all converging on the same unresolved problem: agents currently operate as generic service accounts with no dedicated identity layer of their own.
What makes the ITU move worth flagging isn't the technical content — there isn't much yet — but the governance question it surfaces before any spec exists. A workable identity standard needs to let an agent prove narrow, task-specific authority without exposing everything else about it. The harder problem is who gets to issue the credentials, which institutions are obligated to recognize them, and who holds revocation power. An open technical standard can still produce a closed ecosystem if the major relying parties only accept credentials from a handful of issuers — effectively turning identity infrastructure into an admissions filter for which software gets to act in the world.
This lands three weeks after Identity Digital's Innovation Labs submitted a separate DNS-anchored durable identity proposal to the IETF, aiming to give agents a neutral, ownership-and-revocation registry that sits below the authentication layer rather than replacing it. Between the ITU's institutional framing and the IETF's DNS-rooted mechanism, the pattern is the same: standards bodies are racing to define agent identity before enterprise vendors lock in incompatible, proprietary versions of it first. Whether either effort produces something agents and relying parties actually adopt, rather than another comment period that fizzles, is still an open question — the ITU group itself is just getting organized, and there's no working implementation yet to test against real deployments.