Committed to connecting the world

  •  

ITU-T work programme

[2025-2028] : [SG17] : [Q16/17]

[Declared patent(s)]  - [Associated work]

Work item: X.S-AIAI
Subject/title: Security framework and requirements for invocation by AI agent
Status: Under study 
Approval process: TAP
Type of work item: Recommendation
Version: New
Equivalent number: -
Timing: 2028-Q1 (Medium priority)
Liaison: ITU-T SG21, ISO/IEC JTC/1 SC27, ETSI TC SIA, IETF SEC, ART
Supporting members: China Mobile, CAICT, Ant Group Co. Ltd.
Summary: 2025 marks the beginning of the AI agent era, with technologies that can perceive, decide, and act autonomously, seeing rapid growth in their applications. A key development is their move toward capability invocation, calling upon other agents, tools, and MCUs(Modular Capability Unit) to complete complex tasks. This shift, however, introduces significant security risks. Communications between agents may be intercepted, resulting in data leakage. Standardized protocols can be exploited to poison workflows. Invoking tools or MCUs carries the risk of misuse, and weak controls in cross-domain scenarios can allow identity impersonation. Current security standards remain inadequate. They tend to focus on individual agents or isolated aspects of the invocation process, failing to address the dynamic permissions and cross-domain risks that arise throughout it. They also lack systematic security requirements for all participating entities. There is therefore an urgent need to establish unified security standards that cover the entire invocation by AI agent to ensure comprehensive protection. Therefore, to promote the healthy and sustainable development of AI agent technology and to fill the current gap in full-process protection within standards for the capability invocation domain, this recommendation identifies threat to the invocation by AI agent to other AI agents, external tools, and MCUs and proposes the construction of a forward-looking, universal security framework for invocation by AI agent and workflow. The goal is to advance the invocation by agent through standardized, full-process security. This reduces risks and builds trust in cross-entity calls, encouraging deeper cross-agent capability integration and innovation in tools/modular capability units.
Comment: -
Reference(s):
  Historic references:
-
Contact(s):
Jia CHEN, Editor
Jing JING, Editor
Guanchen LIN, Editor
Ke WANG, Editor
Feng ZHANG, Editor
ITU-T A.5 justification(s):
Generate A.5 drat TD
-
[Submit new A.5 justification ]
See guidelines for creating & submitting ITU-T A.5 justifications
First registration in the WP: 2026-04-02 14:21:57
Last update: 2026-06-10 16:15:41