Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →ITU Focus Group on Trust and Identity for Humans and Agentic AI
Issued by
International Telecommunication Union
The International Telecommunication Union has launched a Focus Group to develop frameworks for trusted digital identity and accountable behavior across the lifecycle of agentic AI systems. The initiative addresses how autonomous AI agents are identified, credentialed, and authorized to act, including in agent-to-agent interactions. It is relevant to any organization deploying or developing AI agents that operate with delegated authority or interact with external systems.
Applies To
Overview
Announced at the AI for Good Global Summit in July 2026, the ITU Focus Group on Trust and Identity for Humans and Agentic AI is a pre-standardization body convened to define technical and governance frameworks for non-human identity (NHI) management in agentic AI contexts. The Focus Group will address agent credentials, delegation models, and authentication protocols such as OAuth flows adapted for autonomous systems that act on behalf of humans or other systems. Its scope spans the full agent lifecycle, from provisioning and authorization through to revocation and audit. Outputs are expected to inform future ITU-T Recommendations, which member states and industry participants may incorporate into national and sector-specific requirements. The Focus Group operates as a consensus-building mechanism and does not itself carry binding enforcement authority; obligations will arise downstream as its outputs are adopted into formal standards or referenced by regulators. Enterprises operating AI agents in cross-border or multi-party environments should monitor the group's working documents as early indicators of emerging international norms.
Key Requirements
- •No binding obligations exist at this stage; the Focus Group is a pre-standardization body producing draft frameworks and technical specifications.
- •Organizations participating as contributors must adhere to ITU membership and contribution procedures for Focus Group activities.
- •Future ITU-T Recommendations derived from this work may require conforming identity and credentialing architectures for AI agents operating in regulated or interconnected environments.
- •Agent identity systems will likely be expected to support verifiable credentials, delegation chains, and revocation mechanisms aligned with emerging ITU specifications.
- •OAuth and related authorization flows for autonomous agents may need to meet authentication assurance levels to be defined in forthcoming technical outputs.
- •Timelines for formal Recommendations have not been published; enterprises should track Focus Group meeting cycles for draft deliverable releases.
What Your Organization Must Do
- →Inventory all agentic AI systems in use and document how each agent is identified, authenticated, and authorized to act on behalf of users or systems.
- →Assign ownership of non-human identity governance to a named function, such as an identity and access management team or a responsible AI program, before standards solidify.
- →Review existing OAuth and API credential policies to assess their applicability to autonomous agent workflows and identify gaps relative to emerging ITU guidance.
- →Engage with the ITU Focus Group process directly or through industry associations to influence technical specifications and receive early access to draft deliverables.
- →Update AI procurement and vendor management requirements to include agent identity and credential documentation as a due-diligence item.
- →Establish a monitoring process to track Focus Group outputs and translate finalized ITU-T Recommendations into internal policy updates on a defined review cycle.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Does the ITU FG-TIHA create any binding compliance obligations for enterprises deploying AI agents right now?
- No binding obligations exist at this stage. The Focus Group is a pre-standardization body, meaning enforceable requirements will only arise after its outputs are adopted into formal ITU-T Recommendations or referenced by national regulators. Organizations should treat current drafts as early signals rather than hard mandates.
- Which types of organizations need to monitor ITU FG-TIHA outputs most closely?
- Enterprises running AI agents with delegated authority in cross-border or multi-party environments face the greatest exposure. This includes large technology firms, financial institutions using automated trading or advisory agents, and public sector bodies deploying autonomous systems that interact with external platforms or other AI agents.
- How does ITU FG-TIHA treat OAuth and API credential frameworks for autonomous AI agents?
- The Focus Group is specifically examining how OAuth flows and related authorization protocols must be adapted for agents operating without continuous human oversight. Future ITU-T Recommendations are expected to define authentication assurance levels that autonomous agent credentials will need to meet.
- What is the expected timeline for ITU-T Recommendations to emerge from this Focus Group?
- No formal publication timeline has been announced. Organizations should track the Focus Group's meeting cycles and working document releases to anticipate when draft deliverables might mature into formal Recommendations that regulators or procurement frameworks could reference.
- How does ITU FG-TIHA differ from the EU AI Act in terms of non-human identity requirements for AI agents?
- The EU AI Act addresses AI system transparency and risk classification but does not establish a dedicated framework for agent-to-agent identity or credential delegation chains. ITU FG-TIHA is specifically designed to fill that technical gap at a global level, making it complementary rather than duplicative.
- What internal governance steps should compliance teams take now to prepare for future ITU agent identity standards?
- Start by inventorying all agentic AI systems and documenting how each is authenticated and authorized. Assign formal ownership of non-human identity governance to an existing function such as an identity and access management team, and incorporate agent credential documentation into AI vendor due-diligence requirements before standards finalize.
