Agent identity and authority have no settled trust chain: 32 sourced gaps, all answered only by drafts and proposals

Asked (summary):

What are the unresolved problems in AI-agent security, identity, delegation, and authorization when agents call tools and APIs on behalf of users — including capability delegation, identity propagation, and auditability? Name the sources.

This is a structured synthesis of 32 explicitly stated gaps drawn from 8 independent hosts — IETF Internet-Drafts, the A2A specification, Microsoft identity-standards commentary, and multiple research papers — not a claim to enumerate every open problem. No single URL supplies more than 3 of the 32 rows (9.4%). The rows consolidate into 11 problem families arranged along the delegated call chain below; every proposed fix is an Internet-Draft or research proposal, none an adopted standard.

Where the trust chain breaks: 11 problem families along the delegated call

protocol / standards gapmodel-level / enforcement gapblock height = number of sourced statements

Hover a block for the problems and sources behind it; click to filter the table below. Darker chevrons mark the hand-offs where authority must survive each hop.

What the landscape alone cannot say

Three IETF Internet-Drafts — AIP (datatracker.ietf.org), Agentic JWT (ietf.org) and ATN (datatracker.ietf.org) — attack overlapping gaps with incompatible designs: DIDs plus capability manifests, intent-bound JWTs, and negotiated session receipts respectively.
Microsoft’s identity-standards lead notes that consent is a human concept — software cannot grant access on behalf of other software — yet agents are delegating anyway, and the standards debate (token exchange, OBO, transaction tokens) is unresolved. techcommunity.microsoft.com
The A2A specification leaves the scope, representation, validity and revocation semantics of inter-agent credentials undefined — an explicit hole at the delegation hop itself. github.com
Model-level gaps resist protocol fixes: multi-turn prompt injection hits a structural ceiling for external filtering (arxiv.org), and attacks that steer tool selection evade both input filters and policy engines (arxiv.org).

All 32 sourced problem statements

FamilyProblemProposed direction (status)Source

Method: 32 problem statements on AI-agent identity, delegation, authorization and audit, each quoted from its source page and linked; gathered from 8 independent hosts (IETF datatracker and archive, a mirror, arxiv.org and ar5iv, Microsoft Tech Community, GitHub, aegis-governance.com); dates where published span Dec 2025 – May 2026. Statements were grouped by hand into 11 thematic families and 6 chain stages; near-duplicate statements from successive draft versions are kept as separate rows. "Status" labels IETF items as Internet-Drafts and academic items as research proposals — none is an adopted standard, and audit evidence does not itself enforce policy. Long explanations are truncated in the table; full text is on the linked pages.

This report was generated automatically by Keenable SELECT at a user's request, from publicly available web sources linked herein. Keenable does not review, verify, or endorse its contents and makes no representation as to accuracy, completeness, or timeliness; AI-based extraction may contain errors. Nothing in this report is investment, legal, financial, or other professional advice. All trademarks and referenced content remain the property of their respective owners; no affiliation or endorsement is implied. To report an error, rights concern, or request removal: legal@keenable.ai.

Keenable SELECTAsk your own question
Made with Keenable SELECT