Two AI agent security group standards initiated in China
Two group standards for AI agent identity and runtime security were initiated at the 2026 Inclusion Bund Conference in China, as Ant Group and partners seek a shared security baseline for large-scale agent use.
The effort reflects a change in the security landscape as large model capabilities improve. Agents are moving from providing information and generating content to autonomous planning, tool invocation, data access and operational execution. Traditional security systems mainly protect objects such as databases, interfaces and files, while agents are becoming new subjects that can make decisions and act. They have identities and permissions, but may also behave unreasonably because of hallucination, prompt injection or intent deviation. A legitimate identity does not necessarily mean reasonable behavior.
“Agents are becoming a new subject in the digital world,” said Wang Yu, vice president of security at Ant Group and general manager of its Information Security Business Unit. “A security system needs to know who it is, whom it represents, what it can access, and also see why it acts and what it is doing. Only by connecting identity, permissions, intent and behavior can agents be truly trusted, controllable and traceable.”
The first standard, on agent identity authentication and authorization, focuses on who an agent is, whom it represents and what it can do. It proposes an identity authentication and permission control framework for agents, establishing a multi-layer trusted identity chain among agents, users and operating environments, and issuing unique, trusted and continuously verifiable digital identities for agents. It also introduces dynamic access control based on task intent. Under a least-privilege principle, permissions are activated with a task and recovered promptly when the task ends, reducing risks of over-authorization and permission abuse.
The second standard, on agent runtime security, focuses on what an agent does during operation, whether it deviates from its task and how risks are handled in time. It covers requirements for risk monitoring and control, risk detection and decision-making, centralized analysis, and performance and stability. It connects key stages including the user’s initial intent, agent planning, tool invocation, system execution and result delivery. Through layered detection and defense, an over-privileged call, an abnormal chain or an intent deviation can be identified, assessed and handled.
The two standards are linked. The first builds a foundation of trusted identity and authorization, while the second strengthens governance of intent and behavior during operation. Together they form an agent security baseline described as identifying identity, recognizing intent and guarding runtime. This means agent security governance is moving from single-point capability building to a systematic phase covering development, deployment, operation and evaluation, and provides a unified technical reference for developers, application operators and third-party evaluators.
Agents are accelerating into office, financial and life service scenarios. Building security standards requires real-scenario experience from technology companies as well as joint validation and continuous improvement by research institutions, operators and industry partners. The initiation of the two group standards is intended to further build industry consensus and create a trust foundation for the large-scale application of agents.