Open standards increase adoption because they lower integration friction, but they also spread the same protocol surface across many teams and vendors. Without strong identity controls, the same openness that improves interoperability also multiplies unreviewed access paths, weak attribution, and inconsistent authorisation decisions.
Why open standards change the identity problem
Open agentic standards work by making the protocol surface reusable: the same request, delegation and tool invocation patterns can be implemented by many products, teams and platforms. That is the interoperability benefit. The identity consequence is that trust decisions no longer live inside one tightly governed system, so identity, authentication and authorisation controls have to travel with the standard rather than depend on a single vendor’s defaults.
That shift matters because openness expands the number of places where a principal can be represented, asserted, delegated or accepted. When the standard is widely adopted, weak identity design is also widely replicated. A sound control model therefore has to answer basic questions consistently: who is acting, on whose behalf, with what scope, for how long, and under what policy decision?
Open standards do not remove identity controls, they make them more visible and more reusable. The standard has to support stable actor identity, delegated authority, bounded access, and reliable attribution across different implementations. Without those guardrails, interoperability turns into a broad permission surface with inconsistent interpretation of the same protocol events.
What gets worse when identity is not standardised with the protocol
When many teams implement the same open surface differently, the failure is rarely one dramatic break. It is usually a collection of small inconsistencies: one integration trusts a token too broadly, another accepts a weaker proof, a third logs the action without preserving the actor, and a fourth grants access because the request came through a familiar broker. Those gaps compound across vendors and environments.
Open standards also increase the chance of confused delegation. If an agent can carry context across systems, the receiving system must distinguish the original user, the agent itself, and any intermediate service that forwarded the request. If that distinction is vague, the system may silently over-authorise an action or fail to prove later who really initiated it.
Identity controls therefore become a protocol-level requirement, not an optional overlay. Agentic AI Identity Guide is useful here because it treats identity as a lifecycle problem, registration, delegation, ownership, attestation and retirement, which is exactly the kind of structure open standards need if they are to scale safely. Likewise, the AI Agent Authorisation Guide shows why per-action policy decisions matter when many implementations consume the same standard.
Open standards also make attribution and auditability harder unless every participant preserves the same identity signals. AI Agent Observability, Audit and Incident Response Guide is relevant because once the same protocol is used across multiple systems, logs, correlation IDs and action traces become the only practical way to reconstruct responsibility after misuse.
How practitioners should treat openness as an identity design constraint
Teams should treat identity controls as part of the standard adoption checklist, not as a later hardening step. If a protocol can be implemented without clear delegation semantics, scoped credentials, and policy enforcement per action, it will be implemented inconsistently at scale. That is especially true when multiple vendors, internal teams and third-party integrations all speak the same standard.
Zero Trust for AI Agents is the right mental model: verify the principal and the request, remove standing privilege, and force a fresh policy decision when the action changes. Open standards benefit from that approach because it avoids assuming that protocol compatibility is the same thing as trust.
Agent Identity Standards Tracker helps teams compare identity-related specifications before they commit to one implementation path, which is important when the ecosystem is still converging. And MCP Security Guide is a practical reminder that an open protocol still needs strong authn/authz boundaries, otherwise the same convenience that drives adoption also increases the blast radius of a bad integration.
Risk and Threat Considerations
Open agentic standards create a larger and more repeatable attack surface because the same weakness can be exploited across many deployments. If identity is weak, an attacker does not need to break every implementation separately, they can target the common delegation, token, or authorisation pattern and then reuse that access path wherever the standard is accepted.
Failure mechanism: Inconsistent identity proof, overbroad delegation, or weak per-action authorisation allows an untrusted agent, integration, or intermediary to gain access that was never intended for it, then reuse that access at scale across participating systems.
Impact: The result is misattribution, privilege creep, unauthorised actions, and faster lateral movement across connected tools and vendors because the same protocol trust assumption is repeated everywhere.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Open standards spread agent trust decisions, making privilege abuse a core risk. |
| Recommendation — Enforce per-action authorization and bounded privilege for every agent request. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Shared protocol surfaces amplify excessive access when many teams adopt the same pattern. |
| Recommendation — Remove standing access and scope non-human credentials to the minimum needed. | ||
| NIST SP 800-53 Rev 5 | IA-9 — Identification and Authentication (Service) | Open agentic standards depend on service-to-service identity and authentication boundaries. |
| AC-6 — Least Privilege | The question centers on limiting the access granted through widely reused protocol paths. | |
| Recommendation — Authenticate service and workload calls with strong, verifiable non-human identities. Apply least privilege to every standard-based integration and delegated action. | ||
| NIST Zero Trust (SP 800-207) | PR.AA-05 — Identity Management, Authentication and Access Control | Zero trust directly addresses repeated trust decisions across open protocol implementations. |
| Recommendation — Verify identity and authorize each request before granting protocol access. | ||
Practitioner Guidance
What to prioritise: Decide identity semantics before broad rollout. The most important question is not whether the standard interoperates, but whether every implementation can answer who the actor is, what authority it has, and when that authority expires.
What to verify: Check that the standard is deployed with scoped credentials, explicit delegation, action-level authorisation, and logs that preserve the initiating principal as well as any acting agent or relay. If any of those are missing, treat the integration as high-risk even if it is functionally correct.
Practitioner takeaway: Open standards increase adoption, but adoption without identity discipline turns a shared protocol into a shared liability, so the control objective is to standardise trust decisions as aggressively as the wire format.
Related resources from NHI Mgmt Group
- Why do AI agents increase non-human identity risk in existing IAM programmes?
- How should security teams govern machine identity credentials in agentic AI environments?
- Why do AI agents increase non-human identity risk?
- Why do agentic AI systems increase the need for layered identity and access controls?