Four separate signals we logged this month all point at the same quiet problem: as software agents start acting on our behalf, nobody has settled how an agent proves who it is or what it is allowed to do. It is the kind of plumbing question that decides more than it looks like it will.
The signals
- IETF drafts an AI-agent authentication and authorization spec
sig-2026-09-19-002· From ad hoc API keys → To standardized, scoped, revocable agent credentials · strength: emerging · source - NIST NCCoE opens an AI-agent identity and authorization project
sig-2026-09-19-003· From voluntary experimentation → To formal governance of autonomous systems · strength: emerging · source - Research surveys the gaps in AI-agent identity standards
sig-2026-09-19-004· From fragmented identity practices → To a converging research agenda · strength: early · source - Compositional frameworks formalize delegation and scope for agents
sig-2026-09-19-008· From all-or-nothing access → To composable, scoped delegation across agent chains · strength: early · source
Why it matters
On their own, each of these reads like a niche standards story. Together they suggest a driver forming, call it agent identity and delegation, moving from ad hoc keys and borrowed human logins toward scoped, revocable credentials that a machine can carry and a service can trust. The signals span an unusual mix of sources for something this early: a standards body drafting the wire format (sig-2026-09-19-002), a national lab opening a governance project (sig-2026-09-19-003), and academic work both mapping the gaps (sig-2026-09-19-004) and proposing how permissions compose across chains of agents (sig-2026-09-19-008). When the plumbers, the regulators, and the researchers start pulling in the same direction at once, it usually means the underlying need is real rather than hype.
Why now is straightforward. Agents are moving into production and running continuously, so "let it use my login" stops being acceptable the first time an agent does something expensive or irreversible without a clear, auditable trail of whose authority it was acting under. The interesting tension is not whether agent identity arrives. It is who issues it. If a few large platforms define identity in their own private dialects, delegation becomes a lock-in mechanism; if the open standards mature first, agents stay portable across services. That fork is not yet decided, and it is worth watching closely: the standards are still early, but they are the hinge.
What it could mean for digital assets
As agents proliferate, so does the need for legible, ownable names for the things that vouch for them: the registries, brokers, and identity services that issue and verify agent credentials. A namespace built for machine identity is a plausible early beneficiary of this shift. We think this is where curated names in the AI & Agents category earn their keep: the connective tissue of an agent economy has to be named before it can be trusted.