ARTIFICIAL INTELLIGENCE

OpenID Foundation Whitepaper Maps Out How to Secure AI Agents' Identities

A report from the OpenID Foundation argues that today's login and permission systems work for simple AI agents but break down as they grow more autonomous, cross organizational boundaries, and start delegating tasks to each other.

Server room with illuminated racks symbolizing identity and access management infrastructure for AI systemsARTIFICIAL INTELLIGENCE

Image: IntraGoals Media · Uploaded by IntraGoals — usage rights confirmed

The OpenID Foundation has published a whitepaper, "Identity Management for Agentic AI," arguing that while existing authentication and authorization standards can handle today's AI agents, they are not built for the more autonomous, cross-domain systems coming next.

The report, led by Tobin South and produced with the Artificial Intelligence Identity Management Community Group, Stanford's Loyal Agents Initiative, and numerous industry contributors, frames AI agents as fundamentally different from traditional software. Unlike conventional applications that execute predetermined instructions, agents take autonomous actions based on real-time, non-deterministic decisions, often interacting with external tools and services on a user's behalf.

The authors find that current frameworks, including OAuth 2.1 and the increasingly popular Model Context Protocol (MCP), work reasonably well for straightforward cases, such as enterprise agents operating within a single company's systems or consumers using AI tools tied to their own accounts. Enterprise single sign-on and SCIM provisioning can also help organizations manage agent permissions much as they manage human employee access.

But the paper warns that these tools fall short once agents operate across organizational boundaries, act asynchronously over long periods, or need to represent multiple users at once. It identifies several looming problems: fragmented, vendor-specific identity systems that create duplicate security models; agents that impersonate users rather than acting through clearly delegated, auditable authority; and "consent fatigue," in which users bombarded with thousands of approval requests begin rubber-stamping them without real scrutiny.

Other flagged risks include recursive delegation, where agents spawn sub-agents without clear limits on what authority gets passed down; a lack of support for agents serving entire teams rather than single users; and the absence of automated ways to verify that an agent's actions stay aligned with its intended purpose as human oversight becomes impractical at scale. The report also highlights browser- and computer-use agents, which interact directly with visual interfaces and can bypass API-based security controls entirely, as well as the challenge of authenticating legitimate bots on the open web without locking out well-behaved agents.

To address near-term needs, the paper points to tools such as Client Initiated Backchannel Authentication for asynchronous approval requests, extended SCIM schemas for managing agent lifecycles, and working groups like the Interoperability Profiling for Secure Identity in the Enterprise (IPSIE) that are developing shared standards. For the longer term, it calls for new models of "on-behalf-of" delegation, scope attenuation across chains of agents, portable and verifiable agent identities, and interoperable trust frameworks that avoid locking the ecosystem into proprietary, incompatible systems.

The authors frame the document as a call to action for developers, standards bodies, and enterprises alike, urging them to treat AI agents as first-class identities within access-management systems rather than retrofitting tools designed for humans and static software. The full report is available from the OpenID Foundation.

Sources and further readingIdentity Management for Agentic AI [pdf] (2025) ↗
ABOUT THE DESK

IntraGoals News Desk

IntraGoals reports on important changes in technology and work. We check each story for clear writing, trusted sources and useful information before it is published.

KEEP READING

Latest from IntraGoals.

All latest stories ↗
OpenID Foundation Whitepaper Maps Out How to Secure AI Agents' Identities | IntraGoals