|
Work item:
|
X.aaia-sec
|
|
Subject/title:
|
Security framework and technical requirements for autonomous AI agents
|
|
Status:
|
Under study
|
|
Approval process:
|
TAP
|
|
Type of work item:
|
Recommendation
|
|
Version:
|
New
|
|
Equivalent number:
|
-
|
|
Timing:
|
2028-Q4 (Medium priority)
|
|
Liaison:
|
ITU-T SG13, ITU-T SG20, ITU-T SG21, ETSI TC SAI, ISO/IEC JTC1/SC27, ISO/IEC JTC1/SC42, IETF SAAG, CEN/CENELEC JTC21
|
|
Supporting members:
|
China Telecom, ZTE Corporation, China Mobile, China Unicom, ETRI
|
|
Summary:
|
Currently, AI agents have evolved from ordinary passive response systems into autonomous AI agents capable of autonomous planning, long-cycle execution, proactive notification, dynamic skill invocation, and self-evolution. Represented by systems such as OpenClaw, engineering deployments have introduced module capabilities like an independent control plane, long-cycle task planning, skills, scheduled tasks, and self-evolving long/short-term memory. These additions have also expanded new risk boundaries, including control plane risks, skills&tools supply chain risks, memory and self-evolution risks, and high-privilege runtime execution risks. Therefore, the security paradigms for autonomous AI agents, extending the security protection from the traditional "planning + memory + execution + model input/output" to "control plane + runtime + skills + self-evolution".
This Recommendation proposes a comprehensive security framework for autonomous AI agents, covering initial phase security, agent runtime phase security, security observation. It serves as a critical reference for developers, operators, and users to build, deploy, and interact with trustworthy autonomous AI agent systems that meet foundational security requirements.
|
|
Comment:
|
-
|
|
Reference(s):
|
|
|
Historic references:
|
|
Contact(s):
|
|
| ITU-T A.5 justification(s): |
|
|
|
|
First registration in the WP:
2026-06-10 08:31:31
|
|
Last update:
2026-06-18 14:02:00
|
|