July 2026 · 8 min read
CrowdStrike and IETF Move in Parallel:
AI Agent Identity Is Becoming Its Own Security Category
In July 2026, two independent events point in the same direction: AI agent identity management is becoming a standalone security category. CrowdStrike launched a dedicated "Continuous Identity for AI Agents" product, while the IETF published the Agent Identity Protocol (AIP) draft, defining a decentralized identity standard for agents.

Key Definitions
AI Agent Identity A security framework that gives non-human, automated, short-lived AI agent entities verifiable identities, permission boundaries, and audit chains. Traditional human IAM models do not apply — agents execute hundreds of operations in seconds and need continuous verification rather than static login.
Agent Identity Protocol (AIP) An IETF draft defining a decentralized identity, delegation, and authorization framework for AI agents, combining W3C Decentralized Identifiers (DIDs), capability-based authorization, cryptographic delegation chains, and deterministic validation.
CrowdStrike: AI Agents Need Continuous Identity Verification
CrowdStrike's "Continuous Identity for AI Agents" is built on a simple premise: traditional human user identity models do not fit AI agents. Agents are non-human, automated, short-lived entities with behavior patterns completely different from humans — an agent may execute hundreds of operations in seconds, jumping from one context to another.
The solution provides continuous identity verification for every AI agent, rather than static one-time identity assignment. Key features include:
- Continuous verification. Agent identity is not static — re-verify at every operation
- Behavioral baselines.The system learns each agent's normal behavior pattern and alerts on deviation
- Real-time revocation. Revoke agent access immediately upon anomaly detection, without waiting for credential rotation
- Cross-platform compatibility. Supports multiple agent frameworks and runtime environments
CrowdStrike's entry is a significant signal. When one of the world's largest cybersecurity companies treats AI agent identity as an independent category, enterprise security teams should pay attention.
IETF AIP: Building a Decentralized Identity Standard for Agents
Almost simultaneously, the IETF published the Agent Identity Protocol (AIP) draft (draft-singla-agent-identity-protocol-03), proposed by P. Singla. AIP defines a decentralized identity, delegation, and authorization framework for AI agents, combining W3C Decentralized Identifiers (DIDs), capability-based authorization, cryptographic delegation chains, and deterministic validation.
AIP's core design principles include:
- Decentralization. No central identity authority — agents can autonomously generate and verify identities
- Capability-based authorization.Agents carry "capability tokens" proving access to specific resources, rather than sharing credentials
- Delegation chains. One agent can delegate capabilities to another, forming auditable delegation chains
- Deterministic verification. All identity verification steps are deterministic and machine-executable without human intervention
This is especially critical for multi-agent collaboration. When multiple agents need to work together to complete a task, AIP ensures each agent can verify the identity and permission scope of others without sharing credentials or relying on centralized identity systems.
Why Agent Identity Management Differs from Traditional IAM
Traditional Identity and Access Management (IAM) systems were designed for human users. Humans have stable identities, fixed working hours, and predictable behavior patterns. AI agents are fundamentally different:
- Non-human.Agents don't "log in" — they execute operations via APIs and tool calls
- Automated. Agents make decisions and execute actions in milliseconds
- Short-lived. Many agents are created for specific tasks and destroyed upon completion
- Cascading. One agent may call another, forming complex invocation chains
These differences mean you cannot simply apply human IAM policies to AI agents. A dedicated identity model for agents is needed — exactly what CrowdStrike and the IETF are building.
Implications for Enterprise AI Governance
Both events point to a clear direction: AI agent identity management is becoming the infrastructure layer of enterprise AI governance. Just as the internet era needed IP addresses and DNS, the AI era needs agent identity protocols and continuous verification systems.
For enterprises deploying AI agents, now is the time to start building agent identity management. You don't need to wait for standards to fully mature — CrowdStrike's commercial solution and the IETF draft already provide a clear roadmap. Start with one independent identity per agent, then gradually build continuous verification and capability-based authorization. This will lay a solid foundation for enterprise AI governance.
FAQ
Why do AI agents need dedicated identity management instead of reusing human IAM?+
Traditional IAM is designed for humans: stable identities, fixed working hours, predictable behavior. AI agents are fundamentally different — non-human (execute via APIs), automated (millisecond decisions), short-lived (destroyed after task completion), and cascading (one agent calls another forming complex chains). These differences mean human IAM policies cannot be simply applied to AI agents.
What are the key features of CrowdStrike's Continuous Identity for AI Agents?+
Continuous verification (re-verify at every operation, not static one-time assignment), behavioral baselines (learn each agent's normal behavior and alert on deviation), real-time revocation (revoke access immediately upon anomaly, without waiting for credential rotation), and cross-platform compatibility (supports multiple agent frameworks and runtime environments).
What are the core design principles of the IETF Agent Identity Protocol (AIP)?+
Decentralization (no central identity authority — agents autonomously generate and verify identities), capability-based authorization (agents carry capability tokens instead of sharing credentials), delegation chains (agents can delegate capabilities to others, forming auditable chains), and deterministic verification (all steps are machine-executable without human intervention).
How does AI agent identity management differ from traditional Identity and Access Management (IAM)?+
Traditional IAM assumes users are human: they log in, have stable identities, and behave predictably. AI agent identity management targets non-human entities: no login (API calls instead), short lifecycles (destroyed after tasks), millisecond automated operations, and cascading invocation chains. A dedicated identity model for agents is needed, not a reuse of human IAM.
How should enterprises start building agent identity management?+
You don't need to wait for standards to fully mature. CrowdStrike's commercial solution and the IETF draft already provide a clear roadmap: start with one independent identity per agent, then gradually build continuous verification and capability-based authorization. This becomes the infrastructure layer of enterprise AI governance — just as the internet era needed IP addresses and DNS, the AI era needs agent identity protocols.
相关文章
OpenAI 承认 Astra 思维链更难监控:审计证据必须从模型推理搬到动作边界
OpenAI 在 Astra 系统卡中首次承认:模型对自身思维链的控制力增强,链式思维监控的可信度下降,隐蔽作弊可能无法被发现。三天后首席科学家 Pachocki 撰文称没有任何实验室已解决对齐与监控。当被审计的实体能控制审计所读取的推理,审计就不再是独立证据。
知道坏了,不知道是谁干的:七成企业无法定位肇事 Agent
Kore.ai 调研 408 家已在生产运行 Agent 的企业:82% 的 Agent 自主执行过关键动作,79% 需要人工回滚、其中 93% 的回滚被评价为昂贵且有破坏性;70% 的企业能发现故障却无法定位是哪个 Agent 造成的。可观测性≠可归因,没有身份绑定的动作证据,遏制、回滚与问责都无从谈起。
2026年AI Agent安全市场格局:四大方法对比
AI Agent安全已成为独立的安全品类。2026年市场分为四类:企业套件、运行时防护、身份治理、生命周期治理。对比Zenity、Microsoft、Noma、Arthur等平台。
影子AI Agent危机:企业正在运行看不见的Agent
超过53%的企业Agent超出预期权限范围,47%在过去一年发生过Agent安全事件。影子AI Agent正成为企业最大的安全盲区,平均事件成本高出67万美元。
OOMeta's Agent Identity Infrastructure
OOMeta's AI agent governance platform natively supports capability-based authorization and continuous identity verification. We help enterprises build auditable identity systems in multi-agent environments, ensuring every agent operation has clear identity credentials and permission boundaries.
References
- CrowdStrike: "CrowdStrike Unveils Continuous Identity for AI Agents"
- IETF: "Agent Identity Protocol (AIP) — Decentralized Identity and Delegation for AI Agents"
- VentureBeat: "The agent security gap: 54% of enterprises have already had an AI agent incident"
- GitHub: "Zero-Trust-Agents — Zero-trust security layer for Autonomous AI Agents"