{"slug": "cosai-hosts-working-session-on-open-delegation-identity-standard-odis", "title": "CoSAI Hosts Working Session on Open Delegation & Identity Standard (ODIS)", "summary": "The Coalition for Secure AI (CoSAI), an OASIS Open Project, hosted a hybrid working session on August 28 to advance the Open Delegation & Identity Standard (ODIS), a vendor-neutral architecture for cryptographic identity and delegation in AI agents. The session included live demonstrations and community feedback to shape the standard, which extends OAuth 2.0, OpenID Connect, SPIFFE, and SCIM for agentic AI. ODIS aims to establish a common approach for AI agent identity, delegation, and governance across enterprise trust domains.", "body_md": "Treat Your Agent Like an Insider Threat: Why AI Sandboxing Can’t Wait\n\nAugust 25, 2026As AI agents become more autonomous across enterprise systems, one foundational challenge is emerging: how do we establish who, or what, an AI agent represents, what authority it has been delegated, and whether it can be trusted to take action?\n\nAnswering that means connecting three things: the principal the agent represents, the authority it has been given, and the specific instance of the agent taking the action.\n\nThe [Open Delegation & Identity Standard (ODIS)](https://github.com/cosai-oasis/ws4-odis/) is an open community effort, developed through the [Coalition for Secure AI (CoSAI)](https://www.coalitionforsecureai.org/), an OASIS Open Project, that aims to establish a common approach for AI agent identity, delegation, and governance. ODIS defines a vendor-neutral architecture for cryptographic identity across enterprise trust domains while extending existing technologies such as OAuth 2.0, OpenID Connect (OIDC), SPIFFE, and SCIM for the unique requirements of agentic AI.\n\nAs AI agents increasingly operate across enterprise applications, APIs, and organizational boundaries, interoperable identity and delegation have become challenges no single organization can solve alone. That’s why ODIS is being developed as an open standard—bringing together contributors from across the AI, identity, and security communities to build a shared foundation for trusted agentic systems.\n\nOn August 28, CoSAI convened technical practitioners, identity experts, and governance leaders for a hybrid working session focused on advancing ODIS. The session brought the community together to review the latest work, demonstrate early implementations, and gather feedback that will help shape the next evolution of the standard.\n\n### Building ODIS in the Open\n\nThe session opened with an overview of ODIS, the problem it is designed to solve, and the current state of the specification. From there, attendees moved into two live demonstrations, grounding the standard in working implementations rather than abstract discussion.\n\nHeld under the Chatham House Rule, the working session encouraged candid technical discussion among implementers, identity experts, AI practitioners, and governance leaders. Participants shared feedback, identified implementation challenges, and explored opportunities to improve interoperability as the specification continues to evolve.\n\n### Where ODIS Comes From\n\nODIS is one of several open initiatives underway within CoSAI, which brings together industry leaders to develop practical security guidance, reference implementations, and open standards for AI systems. The work is developed under [CoSAI Workstream 4](https://github.com/cosai-oasis/ws4-secure-design-agentic-systems), which focuses on secure design patterns for agentic systems. Alongside CoSAI’s work on software supply chain security for AI, defender readiness, and AI security risk governance, Workstream 4 is helping define the foundational building blocks needed for trustworthy AI agents to operate across organizations and ecosystems.\n\n### Why Open Contributions Matter\n\nIdentity standards only succeed when they are broadly adopted and shaped by the communities that will ultimately implement them. Building ODIS as an open specification enables AI platforms, cloud providers, identity vendors, enterprise software companies, researchers, and open source contributors to collaborate on a shared approach from the beginning.\n\nCommunity feedback helps improve interoperability, identify real-world deployment challenges, and ensure the specification reflects practical implementation needs rather than a single vendor’s perspective. Every issue raised, pull request submitted, specification review, and reference implementation strengthens the standard and accelerates adoption across the broader AI ecosystem.\n\n### How to Get Involved\n\nCoSAI’s organizers closed the session with steps for attendees and the broader community to help move ODIS forward:\n\n**Review and improve the draft**. Read the[ODIS draft on GitHub](https://github.com/cosai-oasis/ws4-odis), open issues, and provide feedback.** Build, test, and share reference implementations**. Implement an ODIS deployment, come back and show it to the community to help validate the architecture and uncover opportunities to improve interoperability.**Join the community**. Subscribe to the[Workstream 4 mailing list](https://lists.oasis-open-projects.org/g/cosai-agentic-systems-ws)and participate in our meetings. Technical discussions on GitHub or in Workstream 4 meetings all help advance the work.\n\nWant to get involved with CoSAI more broadly? Contributors can sign the contributor license agreement and [join at any time](https://github.com/cosai-oasis/oasis-open-project/blob/main/ONBOARDING.md). Organizations interested in sponsorship, which includes a seat on the CoSAI Project Governing Board (PGB), can reach out to us at [join@oasis-open.org](mailto:join@oasis-open.org).", "url": "https://wpnews.pro/news/cosai-hosts-working-session-on-open-delegation-identity-standard-odis", "canonical_source": "https://www.coalitionforsecureai.org/cosai-hosts-working-session-on-open-delegation-identity-standard-odis/", "published_at": "2026-09-01 16:10:56+00:00", "updated_at": "2026-09-01 16:52:17.987323+00:00", "lang": "en", "topics": ["ai-policy", "ai-safety", "ai-infrastructure"], "entities": ["Coalition for Secure AI", "OASIS Open Project", "Open Delegation & Identity Standard", "OAuth 2.0", "OpenID Connect", "SPIFFE", "SCIM"], "alternates": {"html": "https://wpnews.pro/news/cosai-hosts-working-session-on-open-delegation-identity-standard-odis", "markdown": "https://wpnews.pro/news/cosai-hosts-working-session-on-open-delegation-identity-standard-odis.md", "text": "https://wpnews.pro/news/cosai-hosts-working-session-on-open-delegation-identity-standard-odis.txt", "jsonld": "https://wpnews.pro/news/cosai-hosts-working-session-on-open-delegation-identity-standard-odis.jsonld"}}