{"slug": "three-standards-bodies-are-writing-the-rules-for-agent-infrastructure-and-theyre", "title": "Three Standards Bodies Are Writing the Rules for Agent Infrastructure — And They’re Not Waiting for the Market", "summary": "Three standards bodies—OWASP, NIST, and the Agentic AI Foundation (AAIF)—are independently writing rules for agent infrastructure, converging on a unified stack for authentication, authorization, and runtime enforcement. The OWASP Agent Control Standard (ACS), launched in September 2026 and donated by Zenity, focuses on runtime enforcement; NIST's AI Agent Standards Initiative formalizes identity protocols like OAuth 2.0/2.1 and SPIFFE/SPIRE; and AAIF, which grew from 146 to over 290 members by August 2026, hosts interoperability projects including MCP and agentgateway. Builders must align with these emerging standards to remain viable in the agent-native economy.", "body_md": "Autonomous agents are moving from experimental sandboxes to production environments, yet the infrastructure supporting them remains fragmented. While developers have prioritized model performance, the industry is now forced to address the architectural requirements for securing and scaling these systems. Three distinct bodies—the [OWASP Agent Control Standard (ACS)](https://genai.owasp.org/resource/agent-control-standard-acs/), the [NIST AI Agent Standards Initiative](https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative), and the [Agentic AI Foundation (AAIF)](https://aaif.io)—are independently defining the rules for agentic operations. Although these efforts lack formal coordination, they are converging on a unified stack that will dictate how agents authenticate, authorize, and execute.\n\nThe OWASP ACS, which debuted under the OWASP umbrella in September 2026, focuses on the runtime enforcement layer. Originally developed by Zenity (co-founder Michael Bargury, CTO), the standard provides vendor-agnostic middleware hooks at agent execution points. This allows for granular control within the agent’s execution environment. The standard was MIT-licensed and launched at the AI Agent Security Summit in San Francisco in May 2026 before being donated to OWASP.\n\nParallel to this, the NIST AI Agent Standards Initiative is formalizing the identity and authorization layer. In its [NCCoE concept paper](https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure), NIST identifies six essential standards for agent identity: OAuth 2.0/2.1, OpenID Connect, SPIFFE/SPIRE, SCIM, NGAC, and the Model Context Protocol (MCP). By extending these protocols to include agent-specific permission scoping and multi-hop delegation, NIST is establishing a trust framework designed for enterprise-grade adoption. Their focus areas include moving beyond static API keys toward least-privilege access and treating prompt injection as a control design problem rather than a bug to patch.\n\nThe AAIF serves as the hub for interoperability and open-source infrastructure. Since its inception in December 2025, the foundation has scaled rapidly, growing from 146 members in February 2026 to over 290 by August 2026, with major enterprise players like Alibaba, Visa, and Wells Fargo joining the ecosystem. The AAIF hosts eight working groups, including Agentic Commerce and Security & Privacy, and manages foundational projects such as MCP, goose, and AGENTS.md. In June 2026, the foundation added [agentgateway](https://aaif.io) as its fourth hosted initiative, providing MCP virtualization with tool-level access policies.\n\nThe Model Context Protocol (MCP) has emerged as the primary interface layer, appearing as a foundational element in both the NIST identity framework and the AAIF’s project portfolio. This shared reliance on MCP suggests that while governance tracks remain distinct, the industry is coalescing around a common interface for agent-to-tool communication.\n\nFor builders, this convergence necessitates a shift in strategy. The architecture of agentic systems is trending toward a model where identity, authorization, and runtime enforcement are decoupled but interoperable. Developers must ensure their stacks are compatible with these emerging standards to remain viable in the agent-native economy. Specifically, builders should monitor the integration of OWASP ACS runtime hooks with the identity protocols defined by NIST. As these standards mature, the ability to enforce least-privilege authorization by design—while maintaining the flexibility of multi-hop agent chains—will become the primary differentiator for production-grade agent infrastructure.\n\nThe alignment of runtime enforcement, identity protocols, and interoperability standards is creating a more predictable environment for deployment. For those building in the agent-native economy, the focus must shift from experimental implementation to architectural compliance with these evolving, yet converging, standards.", "url": "https://wpnews.pro/news/three-standards-bodies-are-writing-the-rules-for-agent-infrastructure-and-theyre", "canonical_source": "https://forkast.news/three-standards-bodies-are-writing-the-rules-for-agent-infrastructure-and-theyre-not-waiting-for-the-market/", "published_at": "2026-09-09 09:43:18+00:00", "updated_at": "2026-09-09 10:11:47.582427+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy", "ai-infrastructure"], "entities": ["OWASP", "NIST", "Agentic AI Foundation", "Zenity", "Michael Bargury", "Alibaba", "Visa", "Wells Fargo"], "alternates": {"html": "https://wpnews.pro/news/three-standards-bodies-are-writing-the-rules-for-agent-infrastructure-and-theyre", "markdown": "https://wpnews.pro/news/three-standards-bodies-are-writing-the-rules-for-agent-infrastructure-and-theyre.md", "text": "https://wpnews.pro/news/three-standards-bodies-are-writing-the-rules-for-agent-infrastructure-and-theyre.txt", "jsonld": "https://wpnews.pro/news/three-standards-bodies-are-writing-the-rules-for-agent-infrastructure-and-theyre.jsonld"}}