appliedbits
DISPATCH  ·  Sector Watch PUBLISHED
PUBLISHED 2026-07-18  ·  UPDATED 2026-08-08

Week ending July 17, 2026

Updated August 8: trimmed editorial asides for concision. No facts, sources, or conclusions changed.

Agent identity moved in three venues in nine days, and none of them tried to invent a new credential. The ITU stood up a Focus Group under SG17, the OpenID Foundation opened an interop event built entirely on existing OAuth drafts, and Entrust shipped a commercial program into the same gap. Read together they answer a question that was open six months ago: whether machine identity would arrive as a fresh stack — a new token, a new registry, a new authority — or as a profile over what already works. This week it broke toward profile. That is the cheaper outcome for implementers and the harder one to capture, because a spec assembled from OAuth 2.1, DPoP, and token exchange has no natural owner. Worth watching whether it holds, since the pressure to introduce a purpose-built agent credential will come from whoever would operate the registry.

Standards in motion

The ITU opened a Focus Group on agent identity, reporting to SG17. Trust and Identity for Humans and Agentic AI (TIDA) was announced July 9 at AI for Good and reports to ITU-T Study Group 17, the security group. Two co-chairs are named, with the rest of the leadership team still being assembled. The deliverables are: common terminology, reference architectures for identity and agent discovery, trust and assurance lifecycle models, interoperability mechanisms for credentials, and a standardization roadmap. That last item is an admission — the ITU is positioning as coordinator across bodies rather than as the author of the credential. First meeting Paris, November; second Geneva, January 2027. Open to all interested experts. Adoption read: nothing to adopt yet. A Focus Group is pre-standardization, its output is study material, and the honest label here is announced, not adopted. Note also that the release names no participating company and no external body — not ISO, not IETF, not the OpenID Foundation, whose work overlaps directly. The thing to watch between now and Paris is whether that roadmap cites the OAuth and OpenID work by name or routes around it; the first would make TIDA a coordinating venue, the second would make it a competing one.

OpenID Foundation put agent security on existing OAuth drafts and set a date to prove it. The Artificial Intelligence Identity Management Community Group published a call for participation July 14 for an interop event at the Gartner IAM Summit in December. The specs are all existing work: OAuth 2.1 as the baseline, Client ID Metadata Document (CIMD, an IETF draft letting a client identify itself by URL with no prior registration), and Enterprise Managed Authorization built on the Identity Assertion JWT Authorization Grant (ID-JAG) over identity chaining. Two scenarios: agent governance within an enterprise, and identity assurance for an agent crossing into another organization. Nothing new was minted for either. The motivation is stated plainly — “an organization can choose its own MCP clients, gateways and servers and expect the security properties to hold, regardless of which products it picks”. Adoption read: real but unproven, and the structure is designed to make the difference legible. Participants keep an interop matrix, both sides must agree a result before it counts, and the group publishes the consolidated record. Commitment closes August 10; at least one successful cross-vendor test is required by October 16. The group is co-chaired out of CrowdStrike and the results get presented with Gartner; a core MCP maintainer has also signed on. No vendor list yet — that is what the call is for. Participation is free and open.

RATS shipped its wrapper. RFC 9999 — the Remote Attestation Procedures Conceptual Messages Wrapper — was published July 14 from the IETF RATS working group, after twenty-three drafts. It gives the conceptual messages in the RATS architecture (evidence, attestation results, endorsements, reference values, appraisal policies) a common encapsulation, with a CBOR tag, JWT and CWT claims, and an X.509 extension. Attestation is how you answer “is this thing what it claims to be” for a piece of hardware or a workload, and the same question is now being asked of agents one venue over. Adoption read: too new to score. The draft history means implementers have been tracking it for years. Worth watching whether the agent-identity work picks it up rather than reinventing attestation — the overlap is obvious and so far unremarked.

Two OpenID Connect drafts entered review. Ephemeral Subject Identifier 1.0 is in final-specification review; it defines a subject identifier that stays constant for an authentication session and changes between them, so a relying party cannot correlate a user across visits. That is data minimization written into the identifier itself, which puts it firmly on the consumer-protective end of the axis. Key Binding is in a 45-day implementer’s-draft review running July 9 to August 23, with voting to follow through September 7; it binds a public key to an ID Token using DPoP (RFC 9449). Both are incremental.

STIR is rechartering. The IETF STIR working group moved its charter from Approved back to Draft, with a new charter revision posted. Rechartering is where a working group decides what it is still for, and STIR arriving at that question now — with call authentication broadly deployed and the interesting problems moving toward what the signature actually carries — makes the scope discussion worth reading directly rather than waiting for the outcome. Adoption read: not applicable yet; this is upstream of any spec.

A telecom-specific CBOM, argued rather than published. ATIS made the case for a telecom cryptographic bill of materials, on the grounds that general-purpose CBOM schemas miss 5G primitives — 5G-AKA, MILENAGE, EAP-AKA, PRINS — and that a telecom profile over CycloneDX is needed. Pegged to EO 14412 (June 22, 2026), which gives CISA and NIST 270 days to publish minimum CBOM elements. The regulatory clock is real and the pattern matches the rest of the week: profile the existing schema, don’t mint a new one. The policy layer belongs to Regulatory Watch.

Implementations & adoption

Entrust launched a commercial program into the gap the standards bodies just opened, stating conformance to no open standard. The Agentic AI Trust Accelerator, announced July 14, is a co-development program for enterprises and partners building agent identity infrastructure, organized around identity, authorization, cryptographic assurance, and accountability — four pillars that map almost line-for-line onto the TIDA deliverables list published five days earlier. Entrust describes it as a “trust plane” of verifiable identity, real-time authorization, and cryptographic proof of action travelling across systems and partners. Participation is by registration and aimed at a selected group: enterprises in regulated industries, cloud and SaaS providers, integrators, with an executive sponsor and a pilot already running.

The gap is genuine. Enterprises deploying agents now cannot wait for a Focus Group whose second meeting is in January 2027, and Entrust has real PKI and signing depth to bring to it.

Neither the announcement nor the program page names a single standard the trust plane implements — not CIMD or ID-JAG, not RATS attestation despite the cryptographic-proof framing, not SPIFFE, not the OpenID interop event working the same two problems in the same quarter. Every claim sits at the level of capability. That is unusual for a PKI vendor whose existing business is built on X.509 and published certificate standards, where naming the spec is normally the selling point. The architecture may well be standards-based with the marketing simply omitting it; on the public record there is no way to tell. Unclassifiable on the open↔proprietary axis — which for a program soliciting co-development commitments is itself the problem, since participants are asked to help shape reference architectures without being told whether the result will be portable. The question a prospective participant should ask before signing: which specifications does the trust plane implement, and will conformant implementations interoperate with systems that were not built by Entrust?

The OpenID interop event covers the same two problems — agent governance, cross-organizational identity assurance — names its specs in the call, is free to join, and publishes what interoperated with what. Commitments close August 10.

C2PA conformance produced its first music-industry validator. SoundPatrol announced July 16 that it completed C2PA validator product conformance, which it says makes it the first in recorded music able to check whether an audio file carries intact content credentials. The conformance program turns “we support C2PA” into a testable claim with a published result. Adoption read: one validator in one vertical is a beachhead, not a deployment. Audio has had the fewest C2PA validators of any medium. Adjacent: the Content Credentials ecosystem is the broadest open provenance effort running, with the usual caveat that a standard backed heavily by one large vendor needs watching on the interoperable↔captured axis even when the spec itself is open.

Passkeys, and the enterprise gap that will not close. FIDO and RSA published a joint briefing on enterprise passkey deployment, putting active passkeys above 5 billion and RSA’s own workforce at 98–99% passwordless. Consumer adoption continues to outrun enterprise deployment, and both parties attribute the lag to change management rather than technical limits. Treat the vendor framing accordingly — RSA sells the migration it is describing — but the underlying FIDO numbers are the most-adopted open authentication standard in the sector and the direction is not in dispute. Separately, Microsoft and Google both pushed passkeys deeper into workplace authentication this week. Adoption read: adopted, unambiguously.

EUDI awareness is the adoption problem. Biometric Update reports that public awareness of the EU Digital Identity Wallet remains low as the deadline approaches. Signicat’s move on TrustTech ahead of the eIDAS 2.0 shift is the vendor side of the same clock.

Capital & motivation

Three positioning moves in agent identity this week, none of them a funding round: Entrust opening a co-development program, CrowdStrike staffing a senior continuous-identity role whose occupant co-chairs the OpenID AIIM group, Gartner attaching its IAM Summit to the interop results. Positioning is arriving before anyone knows which spec wins, and it is arriving through people and venues rather than announced capital. Separately, Sensity AI received EIC funding for deepfake-detection forensics: European public money going to detection rather than provenance, worth watching as a hedge against C2PA-style signing solving the problem upstream.