The International Telecommunication Union used last week's AI for Good Summit to open a Focus Group on Agentic AI. Its mandate sounds less dramatic than a new model launch and may matter more to whether agents become ordinary infrastructure: establish ways to identify them, decide when they can be trusted and keep people meaningfully in control of what they do. The group is responding to a simple problem. Software that can schedule, purchase, negotiate or operate a business process is no longer just producing content. It is exercising authority.
Identity before autonomy
A production agent needs more than a model name. A counterparty needs to know which person or organization it represents, what permissions it has, which tools and accounts it may use, how its actions are logged and how that authority can be revoked. Without those elements, an agent can impersonate a user, exceed a delegated task or leave no clear path to responsibility after a mistake. The ITU specifically highlighted financial transactions and critical infrastructure as areas where that ambiguity is unacceptable.
The agent economy will not run on personality. It will run on identity, permission, receipts and revocation.
Standards are arriving after the products
Companies are already shipping systems that browse, call tools and act across connected applications, but the trust layer remains fragmented. One platform's identity token, audit log or approval prompt does not automatically travel with an agent into another service. International standards cannot solve every liability question, and the ITU group is not a regulator. It can, however, define common technical expectations that regulators, banks, vendors and infrastructure operators can build around.
The Focus Group's first meeting is scheduled for Paris in November, followed by Geneva in January. That timeline means builders should not wait for a finished standard. The minimum viable trust layer is already clear enough to implement: explicit principals, least-privilege credentials, human approval for high-impact actions, tamper-evident logs and a kill switch that works outside the model's own reasoning loop.
The commercial consequence
Agent capability is improving faster than enterprise willingness to delegate authority. Identity and control are therefore not compliance features bolted onto the product; they are adoption infrastructure. The vendor that can prove who acted, under whose authority and within which boundary will often beat the vendor with the more impressive demo. Autonomy becomes valuable only when someone can safely say yes to it.
- The ITU opened a standards group on AI-agent identity, trust and human control.
- Agents now exercise authority — buying, scheduling, negotiating — not just producing content.
- A production agent needs identity, permissions, logs and revocation a counterparty can check.
- Don't wait for the standard: least privilege, approvals, tamper-evident logs, kill switch.
- The vendor that can prove who acted will beat the vendor with the better demo.
