The FIDO Alliance formed an Agentic Authentication Technical Working Group this week, with Google contributing its Agent Payments Protocol (AP2) and Mastercard contributing its Verifiable Intent framework. The group will focus on three areas: verifiable user instructions, agent authentication, and trusted delegation for commerce. The premise is straightforward. AI agents are starting to spend money, and nobody has agreed on how they should prove they are allowed to.
This is not the only group trying to answer that question. There are at least four parallel tracks now converging on agent identity, each approaching it from a different institutional angle, and none of them coordinating with the others in any formal way.
NIST launched its AI Agent Standards Initiative in February, convening more than 200 organizations to define interoperability profiles for agent systems. The initiative identified Anthropic's Model Context Protocol and Google's Agent-to-Agent protocol as interoperability baselines and is targeting a formal AI Agent Interoperability Profile by the end of 2026. NIST's own concept paper asks the question plainly: are existing identity standards like OAuth, SPIFFE, and OpenID Connect sufficient for agentic systems, or does something fundamentally new need to be built?
The IETF, meanwhile, has multiple competing Internet-Drafts circulating through its OAuth working group. One proposes attenuating tokens for delegation chains. Another addresses on-behalf-of user authorization. A third describes verifiable actor chains. A fourth binds tokens to TLS sessions. They share a common observation: current OAuth flows assume a human is present at some point in the authorization loop, and that assumption is becoming less reliable by the month. No single draft has consensus.
Then there is the Agentic AI Foundation, a Linux Foundation fund co-founded by Anthropic, Block, and OpenAI, with Google, Microsoft, AWS, and Cloudflare among the members. It now houses the Model Context Protocol, goose, and AGENTS.md, and has accumulated more than 170 member organizations in its first four months. The foundation's mandate is agent interoperability broadly, but identity is embedded in the substrate: agents that call tools, browse the web, and execute code need to authenticate somewhere along the way.
Four tracks, then, all pointed at roughly the same gap. FIDO comes at it from payments and commerce. NIST comes at it from government interoperability requirements. The IETF comes at it from protocol engineering. The Agentic AI Foundation comes at it from the model and tool layer. Each brings its own constituency, its own institutional weight, and its own implicit answer to what agent identity should look like at the protocol level.
The reason this is not an abstract governance exercise is that the gap has commercial consequences right now. When an AI agent books a flight, approves a purchase order, or files a regulatory submission, someone needs to verify, after the fact, that the agent was authorized to do it, by whom, and within what constraints. The tolerance for ambiguity in that chain is inversely proportional to the dollar amount involved. Commerce is the forcing function. Payments are where the identity gap becomes a liability gap.
Agents are booking, buying, and filing today, mostly on ad hoc trust models that would not survive a serious audit. Whoever defines how agent identity works at the protocol level shapes the rules for agentic commerce, enterprise automation, and eventually government AI. That is a considerable piece of infrastructure to be designing, simultaneously, in four different rooms.
Sources: FIDO Alliance, NIST, PYMNTS
–
By the Control Plane Editorial Team