What are the unresolved problems in AI-agent security, identity, delegation, and authorization when agents call tools and APIs on behalf of users — including capability delegation, identity propagation, and auditability? Name the sources.
This is a structured synthesis of 32 explicitly stated gaps drawn from 8 independent hosts — IETF Internet-Drafts, the A2A specification, Microsoft identity-standards commentary, and multiple research papers — not a claim to enumerate every open problem. No single URL supplies more than 3 of the 32 rows (9.4%). The rows consolidate into 11 problem families arranged along the delegated call chain below; every proposed fix is an Internet-Draft or research proposal, none an adopted standard.
Hover a block for the problems and sources behind it; click to filter the table below. Darker chevrons mark the hand-offs where authority must survive each hop.
| Family | Problem | Source |
|---|
Method: 32 problem statements on AI-agent identity, delegation, authorization and audit, each quoted from its source page and linked; gathered from 8 independent hosts (IETF datatracker and archive, a mirror, arxiv.org and ar5iv, Microsoft Tech Community, GitHub, aegis-governance.com); dates where published span Dec 2025 – May 2026. Statements were grouped by hand into 11 thematic families and 6 chain stages; near-duplicate statements from successive draft versions are kept as separate rows. "Status" labels IETF items as Internet-Drafts and academic items as research proposals — none is an adopted standard, and audit evidence does not itself enforce policy. Long explanations are truncated in the table; full text is on the linked pages.