I-D Action: draft-sharif-agent-trust-enforcement-00.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178785231449.899251.14602274482284014606@dt-datatracker-786f84c586-vck88> |
Internet-Draft draft-sharif-agent-trust-enforcement-00.txt is now available. Title: Agent Trust Enforcement for Autonomous AI Systems Author: R. Sharif Name: draft-sharif-agent-trust-enforcement-00.txt Pages: 59 Dates: 2026-08-27 Abstract: This document specifies a trust enforcement architecture for autonomous AI agents operating within container orchestration environments such as Kubernetes. It defines a sidecar injection pattern using mutating admission webhooks, graduated trust enforcement (L0-L4) on every outbound call from an agent workload, credential isolation via secret management systems, bilateral revocation propagation across clusters, and tamper- evident evidence generation. The architecture operates alongside existing workload identity frameworks including SPIFFE/SPIRE without replacement, extends X.509v3 certificates with agent-specific extensions under a registered IANA Private Enterprise Number (PEN 66339), and provides compliance evidence for EU AI Act Article 12, FDA 21 CFR Part 11, IEC 62443, and NERC CIP. Three enforcement gates -- LLM gate, Database gate, and API gate -- intercept every outbound call from an agent container. Each gate classifies the call against the agent's trust level, records the decision in a hash-chained evidence ledger with ECDSA P-256 signatures, and either permits or refuses the call. The architecture defaults to deny: if no policy matches, the call is refused. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-sharif-agent-trust-enforcement/ There is also an HTMLized version available at: https://datatracker.ietf.org/doc/html/draft-sharif-agent-trust-enforcement-00 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]