|
Work item:
|
X.S-AIAI
|
|
Subject/title:
|
Security framework and requirements for invocation by AI agent
|
|
Status:
|
Under study
|
|
Approval process:
|
TAP
|
|
Type of work item:
|
Recommendation
|
|
Version:
|
New
|
|
Equivalent number:
|
-
|
|
Timing:
|
2028-Q1 (Medium priority)
|
|
Liaison:
|
ITU-T SG21, ISO/IEC JTC/1 SC27, ETSI TC SIA, IETF SEC, ART
|
|
Supporting members:
|
China Mobile, CAICT, Ant Group Co. Ltd.
|
|
Summary:
|
2025 marks the beginning of the AI agent era, with technologies that can perceive, decide, and act autonomously, seeing rapid growth in their applications. A key development is their move toward capability invocation, calling upon other agents, tools, and MCUs(Modular Capability Unit) to complete complex tasks. This shift, however, introduces significant security risks. Communications between agents may be intercepted, resulting in data leakage. Standardized protocols can be exploited to poison workflows. Invoking tools or MCUs carries the risk of misuse, and weak controls in cross-domain scenarios can allow identity impersonation.
Current security standards remain inadequate. They tend to focus on individual agents or isolated aspects of the invocation process, failing to address the dynamic permissions and cross-domain risks that arise throughout it. They also lack systematic security requirements for all participating entities. There is therefore an urgent need to establish unified security standards that cover the entire invocation by AI agent to ensure comprehensive protection.
Therefore, to promote the healthy and sustainable development of AI agent technology and to fill the current gap in full-process protection within standards for the capability invocation domain, this recommendation identifies threat to the invocation by AI agent to other AI agents, external tools, and MCUs and proposes the construction of a forward-looking, universal security framework for invocation by AI agent and workflow. The goal is to advance the invocation by agent through standardized, full-process security. This reduces risks and builds trust in cross-entity calls, encouraging deeper cross-agent capability integration and innovation in tools/modular capability units.
|
|
Comment:
|
-
|
|
Reference(s):
|
|
|
Historic references:
|
|
Contact(s):
|
|
| ITU-T A.5 justification(s): |
|
|
|
|
First registration in the WP:
2026-04-02 14:21:57
|
|
Last update:
2026-06-10 16:15:41
|
|