The UN's standards body takes on the agent identity problem
Which agent is acting, for whom, and can it be trusted? The ITU just opened the first UN-level standards track to answer that, and vendors will eventually have to comply with what it writes.
- The ITU established a Focus Group on Trust and Identity for Humans and Agentic AI, announced at the AI for Good summit in Geneva.
- Deliverables include common terminology, reference architectures for agent identity, discovery, and interoperability, trust and assurance frameworks, and security benchmarks for continuous assessment.
- The group reports into security standards body ITU-T Study Group 17; first meeting is Paris in November 2026.
The International Telecommunication Union, the UN's standards body for telecommunications, has established a Focus Group on Trust and Identity for Humans and Agentic AI, announced at the AI for Good Global Summit in Geneva. It is the first UN-level standards effort aimed at the question underneath every agent deployment: how an AI agent is identified, when its behavior can be trusted, and how humans retain authority over it.
What the group will actually produce
The deliverables list reads like the missing bottom half of the agent stack: common terminology, reference architectures for agent identity, discovery, and interoperability, trust frameworks and lifecycle assurance models, interoperability mechanisms for digital identity and credentials, security criteria and benchmarks for continuous agent assessment, and a standardization roadmap. The group reports into ITU-T Study Group 17, the ITU's security committee, with co-chairs Debora Comparin and Amir Banifatemi. The first meeting is set for Paris in November 2026, with a second in Geneva in January 2027, per Telecompaper.
The ITU's framing of the risk is blunt: agents that impersonate people or organizations, take unauthorized actions across interconnected systems, or operate in ways that are difficult to audit.
Where it sits against the industry stack
Industry got here first. A2A settled into the Linux Foundation with over 150 backers, and MCP grew an auth story of its own. What the ITU adds is the layer those efforts have avoided: identity and trust requirements that governments and telecoms can cite in procurement. Vendors selling agents into telecom, government, and cross-border enterprise should assume this group's output eventually shows up in RFPs, the way the EU AI Act's August deadline already does. Standards bodies move slowly, but they only move in one direction.