Treat Your Agent Like an Insider Threat: Why AI Sandboxing Can’t Wait
August 25, 2026As AI agents become more autonomous across enterprise systems, one foundational challenge is emerging: how do we establish who, or what, an AI agent represents, what authority it has been delegated, and whether it can be trusted to take action?
Answering that means connecting three things: the principal the agent represents, the authority it has been given, and the specific instance of the agent taking the action.
The Open Delegation & Identity Standard (ODIS) is an open community effort, developed through the Coalition for Secure AI (CoSAI), an OASIS Open Project, that aims to establish a common approach for AI agent identity, delegation, and governance. ODIS defines a vendor-neutral architecture for cryptographic identity across enterprise trust domains while extending existing technologies such as OAuth 2.0, OpenID Connect (OIDC), SPIFFE, and SCIM for the unique requirements of agentic AI.
As AI agents increasingly operate across enterprise applications, APIs, and organizational boundaries, interoperable identity and delegation have become challenges no single organization can solve alone. That’s why ODIS is being developed as an open standard—bringing together contributors from across the AI, identity, and security communities to build a shared foundation for trusted agentic systems.
On August 28, CoSAI convened technical practitioners, identity experts, and governance leaders for a hybrid working session focused on advancing ODIS. The session brought the community together to review the latest work, demonstrate early implementations, and gather feedback that will help shape the next evolution of the standard.
Building ODIS in the Open
The session opened with an overview of ODIS, the problem it is designed to solve, and the current state of the specification. From there, attendees moved into two live demonstrations, grounding the standard in working implementations rather than abstract discussion.
Held under the Chatham House Rule, the working session encouraged candid technical discussion among implementers, identity experts, AI practitioners, and governance leaders. Participants shared feedback, identified implementation challenges, and explored opportunities to improve interoperability as the specification continues to evolve.
Where ODIS Comes From
ODIS is one of several open initiatives underway within CoSAI, which brings together industry leaders to develop practical security guidance, reference implementations, and open standards for AI systems. The work is developed under CoSAI Workstream 4, which focuses on secure design patterns for agentic systems. Alongside CoSAI’s work on software supply chain security for AI, defender readiness, and AI security risk governance, Workstream 4 is helping define the foundational building blocks needed for trustworthy AI agents to operate across organizations and ecosystems.
Why Open Contributions Matter
Identity standards only succeed when they are broadly adopted and shaped by the communities that will ultimately implement them. Building ODIS as an open specification enables AI platforms, cloud providers, identity vendors, enterprise software companies, researchers, and open source contributors to collaborate on a shared approach from the beginning.
Community feedback helps improve interoperability, identify real-world deployment challenges, and ensure the specification reflects practical implementation needs rather than a single vendor’s perspective. Every issue raised, pull request submitted, specification review, and reference implementation strengthens the standard and accelerates adoption across the broader AI ecosystem.
How to Get Involved
CoSAI’s organizers closed the session with steps for attendees and the broader community to help move ODIS forward:
Review and improve the draft. Read theODIS draft on GitHub, open issues, and provide feedback.** Build, test, and share reference implementations**. Implement an ODIS deployment, come back and show it to the community to help validate the architecture and uncover opportunities to improve interoperability.Join the community. Subscribe to theWorkstream 4 mailing listand participate in our meetings. Technical discussions on GitHub or in Workstream 4 meetings all help advance the work.
Want to get involved with CoSAI more broadly? Contributors can sign the contributor license agreement and join at any time. Organizations interested in sponsorship, which includes a seat on the CoSAI Project Governing Board (PGB), can reach out to us at join@oasis-open.org.