The IETF has published an experimental draft for the Autonomous Agent Certification Protocol (AACP), a framework designed to cryptographically verify AI agent capabilities. The protocol aims to standardize how systems validate agent performance against defined evaluation profiles, separating capability certification from existing identity and authorization mechanisms.
The introduction of AACP provides a standardized method for streaming platforms to verify that AI agents—such as those managing dynamic ad insertion or infrastructure scaling—have demonstrated specific technical competencies before they are permitted to act. By decoupling 'can do' from 'is allowed to do,' the protocol allows organizations to integrate AI into sensitive workflows with higher confidence in behavioral reliability. This development signals a shift toward more granular, evidence-based security models in the streaming ecosystem, moving beyond simple identity-based permissions. Watch for the adoption of these credentials by major cloud providers and the emergence of third-party evaluation services to validate specialized streaming agent profiles.
The IETF's Autonomous Agent Certification Protocol is one of several concurrent efforts within the standards body addressing AI agent trust and capability verification. In June 2026, researchers from Université Grenoble Alpes and Huawei Technologies France published draft-duda-agent-id-framework, proposing self-certifying identifiers derived from public keys for autonomous AI agents, using DNS/DNSSEC and IPFS/IPNS as distributed stores for managing agent identities and trust metadata. That draft introduces a Delegation and Authorization Protocol for negotiating mission-specific capabilities and an Identity and Authentication Protocol combining proof of possession with ephemeral Diffie-Hellman key exchange, representing a complementary rather than competing approach to the capability verification problem AACP addresses. The IETF ecosystem around agent credentialing has expanded rapidly in 2026. A separate draft published in July 2026 by engineers from Defakto Security, AWS, Zscaler, Ping Identity, OpenAI, and Okta proposes best practices for AI agent authentication using existing WIMSE architecture and OAuth 2.0 specifications rather than defining new protocols, explicitly positioning itself as a pragmatic alternative that avoids protocol proliferation. Meanwhile, the Agent Credential Attestation Protocol draft defines short-lived JWT credentials carrying scope-limited permissions and a SHA-256 hash of the originating human instruction, with delegation chains that narrow scope at each hop and append-only audit logs, offering a token-based approach distinct from AACP's evaluation-profile model. A fourth IETF draft, published in August 2026, takes yet another angle by extending X.509 v3 certificates. The AI Agent Identity Certificate extension binds an agent's cryptographic identity to a natural person principal, encoding capability declarations, delegation modality, and authorization boundary constraints within a single certificate that can be verified offline. The author explicitly notes that emerging regulatory frameworks require cryptographic traceability of autonomous actions to accountable principals, a requirement that AACP's separation of capability certification from identity and authorization is designed to complement rather than replace. The proliferation of these drafts within a single year signals that the IETF community recognizes agent verification as urgent but has not yet converged on a single architectural approach.
The IETF has proposed the Autonomous Agent Certification Protocol (AACP) to verify AI agent capabilities through cryptographically verifiable evidence. By separating capability certification from identity and authorization, this framework allows organizations to integrate AI into sensitive workflows with higher confidence, ensuring agents meet specific safety and performance standards before acting.
The AACP provides a standardized method to verify that AI agents have demonstrated specific technical competencies and safety invariants before they are permitted to perform tasks.
AACP separates capability certification from identity and authorization. While OAuth manages who an agent is and what it is allowed to do, AACP focuses on verifying what the agent is technically capable of doing.
Certification is bound to a specific Agent Configuration Digest. If the model, system instructions, or tool definitions change, the agent must be re-certified to ensure the active configuration matches the recorded digest.
The framework was authored by Nitzan Levi and Oren Yeger.
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source