[Rats] Re: [agent2agent] Re: New draft on AI Agent Auditing and proposed BoF/WG charter
Henk Birkholz <henk.birkholz@ietf.contact> Wed, 20 May 2026 11:14 UTC
Return-Path: <henk.birkholz@ietf.contact>
X-Original-To: rats@mail2.ietf.org
Delivered-To: rats@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 73A03F181182 for <rats@mail2.ietf.org>; Wed, 20 May 2026 04:14:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779275663; bh=v/vyR3Rz3ClnWJDNF/wcQs6vaR0QlBW9K3t++bjzLoU=; h=Date:Subject:To:References:From:Cc:In-Reply-To; b=aOOoUvj2X5x/ZBYcDVoKTuVn6JSZH2NoJPLI/gosfSqg6V7AnrLrPflaRjoFVaZ1z eh7jNS77M2njpTR6SG57d8JslFN2GXf+ttEr3i3LT6uNLmgZ640X3F7tcgIagTExvT Uer9kImWywNQb80SEa9K9VRMXdmeEJA2KTmwMIwc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.423
X-Spam-Level:
X-Spam-Status: No, score=-4.423 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-1.624, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ietf.contact
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Qn1xduQgFyuk for <rats@mail2.ietf.org>; Wed, 20 May 2026 04:14:22 -0700 (PDT)
Received: from smtp06-ext.udag.de (smtp06-ext.udag.de [62.146.106.76]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 67878F181150 for <rats@ietf.org>; Wed, 20 May 2026 04:14:22 -0700 (PDT)
Received: from [IPV6:2a01:599:702:35b1:f18f:b19a:6767:13d] (tmo-126-54.customers.d1-online.com [80.187.126.54]) by smtp06-ext.udag.de (Postfix) with ESMTPA id EE374E086D; Wed, 20 May 2026 13:14:20 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ietf.contact; s=uddkim-202310; t=1779275661; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=aHK9kRKpvEg3YKLp5zNbNiqxzxBttNrmCyhWOiKTu6U=; b=XfHHic0xJArVymeqm9A0FcrEsrwo/kB1AwrGoBQRrvq1g9JoWA9mUtsk9hCN3PshjGqYmK ELlHIdGIP7zFD8fgD7yKRkaF1C/czgKt4uVsnMKl4vsGjplDNeWT5cn7YmHrOzpNUcQuGX O+vKGkI5Yd5XT4Uut+VEMf2MF53B50OIGLgnsMl4wbQrLuRPJrnDZUFK7rGnybeAPv9KRR L6rswo77SUUYpWO2+cvO9te9vI39Akg6ep8OU2rlZjh/wHhPIdMdxe7ssIiT/v0ivD60NW oqXXCkU4khl0cgeX7phjG1zBdnRtS6t/Rpdyc+3itVnni9FGPA4YvvZ8LzUV2Q==
Authentication-Results: smtp06-ext.udag.de; auth=pass smtp.auth=henk.birkholz@ietf.contact smtp.mailfrom=henk.birkholz@ietf.contact
Message-ID: <3ad7df2a-271c-fc75-b4c6-14dfba8ceb48@ietf.contact>
Date: Wed, 20 May 2026 13:14:20 +0200
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.11.0
Content-Language: en-US
To: "rats@ietf.org" <rats@ietf.org>
References: <0F12E264-D8D7-4746-B9F4-1C72A9D862F5@kuehlewind.net> <extvmht4nh2c6drh62vhwrlzucobkjecoquktbnyleqnys5iym@bofrnxusdzwy>
From: Henk Birkholz <henk.birkholz@ietf.contact>
In-Reply-To: <extvmht4nh2c6drh62vhwrlzucobkjecoquktbnyleqnys5iym@bofrnxusdzwy>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Message-ID-Hash: 4VU6ZJ3MP4NORAMAB7Y3NYFQOWYFSZLE
X-Message-ID-Hash: 4VU6ZJ3MP4NORAMAB7Y3NYFQOWYFSZLE
X-MailFrom: henk.birkholz@ietf.contact
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-rats.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "Mirja Kuehlewind (IETF)" <ietf@kuehlewind.net>, Thomas Fossati <thomas.fossati@linaro.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Rats] Re: [agent2agent] Re: New draft on AI Agent Auditing and proposed BoF/WG charter
List-Id: Remote ATtestation procedureS <rats.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/WhsQO8zQL5wsxc0NpUb8cEw3mX8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Owner: <mailto:rats-owner@ietf.org>
List-Post: <mailto:rats@ietf.org>
List-Subscribe: <mailto:rats-join@ietf.org>
List-Unsubscribe: <mailto:rats-leave@ietf.org>
Dear Rodent Enthusiasts, on the agent2agent email list, Thomas highlighted that we should share the charter draft for the AUDIT WG BoF proposal with aligned WGs. AUDIT: Agent Use of Delegation and Interaction Traceability On 20.05.26 09:48, Thomas Fossati wrote: > 2. There seems to be quite a lot of overlap with WIMSE, OAUTH, SCITT, > RATS -- at least, which is both good and bad. To minimise the risk of > overlap, conflict, et cetera, I suggest you make the proposal visibile > to these groups (if you haven't already done it). I understand it may > be a bit too early to properly engage, but a quick heads-up would not > hurt (_maybe_). Mirja just send a sharable copy of the charter text to the agent2agent list. Please let me repost it to RATS for your convenience and awareness (as this proposed charter text makes use of the authenticity assurances RATS building blocks create). Please have look! Either in: https://mailarchive.ietf.org/arch/msg/agent2agent/QHFRoQ5g8S7FvoN_Bz6olgx1hn4 or verbatim below. Viele Grüße, Mirja & Henk On 20.05.26 12:35, Mirja Kuehlewind (IETF) wrote: > Hi all, > > To make it easier to comment on the proposed charter text directly, I thought I send another mail with the text directly imbedded. Again any quick comments or expressions of interest before Friday are very welcome, so we can decide on Friday if we want to put a preliminary BoF request in! > > Here is the initial draft for the proposed charter text: > > ————— > # Agent Use of Delegation and Interaction Traceability (AUDIT) Working Group Charter > > Autonomous and semi-autonomous software agents, including those based on artificial intelligence (AI), are increasingly deployed to act on behalf of users, organizations, and services across the Internet. These agents interact across multiple administrative or trust domains and can initiate actions without direct human oversight at each step. > > This introduces challenges for auditability, accountability, and transparency, including: > > * Difficulty attributing actions to a specific user, agent instance, or delegation context > * Loss of visibility across long-running or distributed workflows > * Inconsistent capture of delegation relationships, authorization context, and identity transitions > * Cross-domain interactions lack interoperable means to exchange or verify audit-relevant information about the participating agents and their interactions > > AI agents participate in two distinct classes of interactions that must be audited: > > * User-facing interactions, such as prompts, conversations, and approvals, capturing user intent and human-in-the-loop decisions > * System-facing interactions, such as API calls, tool usage, and delegation to other agents or services > > Effective auditing requires linking user intent to resulting system actions across protocol and administrative boundaries. While traditional workflows support evolving authorization, these transitions are usually explicit and predefined. AI agent systems introduce dynamic, fine-grained authorization changes that arise during execution, driven by agent decisions, delegation, and human interaction. Auditing must therefore capture authorization as a time-evolving state and correlate these transitions across interactions and domains. > > Additionally, AI agent behavior may be non-deterministic and not fully predefined, requiring auditing mechanisms to capture execution context and structure as they emerge. Auditing must also distinguish between user, agent, and service identities, and ensure audit data remains interpretable across systems without shared assumptions. > > ## Scope and Goals > > The AUDIT working group will define interoperable mechanisms for auditing and accountability of AI agents and delegated systems across Internet protocols. > > The group will focus on architectures, protocol-layer specifications, and data representations that enable systems to record, exchange, and verify audit-relevant information across user-facing and system-facing interactions. This includes capturing delegation chains, evolving authorization state, and enabling consistent interpretation and correlation of audit data across domains. > > The working group will not define auditing policies or compliance frameworks, but instead provide the technical building blocks needed to support them. > > ## Deliverables > > The AUDIT working group is expected to produce: > > 1. Architecture for AI Agent Auditing > An Informational RFC describing roles, trust relationships, and data flows for interoperable auditing, including the relationship between user-facing and system-facing audit signals. > > 2. Audit Data Models and Semantics > One or more Standards Track RFCs defining data models for representing audit information, including interaction records, agent identity, delegation context, authorization state over time, and action provenance. > > 3. Protocol Extensions or Profiles > One or more Standards Track RFCs specifying extensions to existing IETF protocols (e.g., HTTP, OAuth, or token formats) to convey audit-related information. > > 4. Best Practices for Deployment and Operation > An Informational or BCP document providing guidance for secure, interoperable, and privacy-aware auditing, including correlation across interaction types. > ————— > > Again here is also the link to the charter text on github: https://github.com/mirjak/draft-audit-architecture/blob/main/audit-charter.md > > And the architecture draft as reference: https://www.ietf.org/archive/id/draft-kuehlewind-audit-architecture-00.html > -> The draft provides further details and also has four brief examples use cases. > > This is all early work, so any feedback is more than welcome! > > Mirja & Henk > >
- [Rats] Re: [agent2agent] Re: New draft on AI Agen… Henk Birkholz
- [Rats] Re: [agent2agent] Re: New draft on AI Agen… toshiyuki sato