Connecting the world and beyond

ITU Workshop on "Advancing Standardization for Secure Agentic AI"

​​​​​​​​​​​​​​​​​​​​
 7 September 2026 (Afternoon)

Chongqing, China



The International Telecommunication Union (ITU)  organized a  workshop on  "Advancing Standardization for Secure Agentic AI”  on the afternoon of 7 September 2026  in Chongqing, China, at the kind invitation of the China Automotive Engineering Research Institute (CAERI). 

The workshop was organized alongside the 2nd Content Week meetings of ITU-T Study Group 17, Security, 7-11 September 2026 (see TSB Collective 9/17​).

The objectives of the workshop were to:
 The workshop was preceeded  by a first workshop,  ITU Workshop on "Intelligent Transport System and Connected Autonomous Vehicle Security"​  which took place at  the same venue, on the  morning  of 7 September 2026.

Participation was free of charge and open to all interested stakeholders including ITU Member States, Sector Members, Associates and Academic Institutions and to any individual from a country that is a member of ITU and who wishes to contribute to the work.​ 

​​Watch the recording of the session here 

Programme  

14:0014:20
Master of Ceremony: Liang Wei Vice Chair of ITU-T Study Group 17 (SG 17) I Vice President, China Academy of Information and Communications Technology (CAICT)

Opening Remarks
14:2014:40
Group Photo (Hotel Lobby / 1st Floor)

Master of Ceremony : Naying Hu Associate Rapporteur Question 16/17, CAICT
14:4015:00

Session 1: Security Risks and Attack Surface Analysis of Agentic AI

This ​session maps the distinctive attack surface of Agentic AI — unauthorized tool and action execution, cross-agent identity spoofing, behavioral deception and goal hijacking, supply-chain poisoning, and loss of autonomous control. Using the recent OpenAI–Hugging Face security incident and other red-team findings as starting points, the session will examine how autonomous pla​​nning and self-directed execution may enable AI agents to go beyond intended boundaries, combine multiple attack steps, access external systems, and take actions that are neither anticipated nor authorized by human operators. The aim is to turn these findings into a shared, evidence-based threat picture for SG17's later work.

Moderator
: Heung Youl Youm, Soonchunhyang University, Korea (Rep. of)​

15:00-16:50

Session 2: Security Mechanisms for Agentic AI
This session examines security mechanisms built into the agent itself — secure-by-design architecture, policy-driven decision constraints, runtime self-inspection, chain-of-thought and behavioral monitoring, and secure update. It explores the standardization needs arising from these new situations, focusing on the gap between what Agentic AI now demands and what SG17's existing standards already cover. ​

Moderator: Zhiyuan Hu, vivo Mobile Communication Ltd., WP4/17 Chair

15:50-16:00
Coffee Break
16:00-16:50
Session 3: Security Evaluation and Verification Methods for Agentic AI

This session explores how to evaluate and verify the security of Agentic AI systems — security testing, formal verification, runtime audit and security metrics — within standardized assessment frameworks. It takes an integration-centric view: as agents are integrated into real ICT systems, evaluation must establish a verifiable baseline at the point of integration, and define what security evidence and assurances integrators should require from the suppliers of agents, tools and models.​

Moderator : Kai Wei,
 ITU-T WP2/21 Vice-chair, Director of AI Institute, CAICT​

16:50-17:30
Session 4: What Frontier Developers Can Give Us — Securing Agentic AI in Practice

This session asks whether it is affordable in practice, and brings in the frontier model developers best placed to answer. The focus is on the trade-offs that only appear once a real model ships. How much capability does security cost? Where does assurance break down at frontier scale? Which of the requirements cannot yet be met? Developers from leading frontier model enterprises will give a frank verdict on what is easy and what is hard. They will also share what they can offer the wider ecosystem, including the practices and evidence ready to be reused, and the open problems where industry still needs support.​

Moderator: Debora Comparin​, Thales Group | WP1/17 Chair​

17:30-17:40
Future outlook and closing remarks

​​​
















RELATED INFORMATION

DOCUMENTATION AND REGISTRATION

ORGANIZED BY

.​​​