
An AI Agent Did Weeks of Network Work in a Day. Its Identity Standard Is Being Written Now.
Deutsche Telekom and Vodafone compressed multi-vendor network policy work from weeks to a single day, while NIST's National Cybersecurity Center of Excellence works through public comments on the standard that will say who an agent is and what it may touch.
Key Takeways
- Deutsche Telekom and Vodafone's TM Forum Catalyst proof-of-concept compressed multi-vendor network policy work from an engineer's multiple weeks into a single day, using an identity layer from Tallence and models from Anthropic and Mistral.
- Ryan Galluzzo and Bill Fisher of NIST reported on August 27, 2026 that AI agents doing real work today mostly borrow their human operator's credentials rather than holding a verifiable identity of their own.
- NIST's National Cybersecurity Center of Excellence has an active project, Software and AI Agent Identity and Authorization, whose public comment period has closed and is now in review.
- An agent can change your network in an afternoon. A person still has to own the decision.
Hand an AI agent a network policy change that spans several vendors and several engineering domains. It can finish in one day what a human engineer needs weeks to coordinate. Deutsche Telekom and Vodafone measured that in a proof-of-concept run through TM Forum's Catalyst program, reported on August 28. The agent did the work. The question underneath it decides whether any of this holds at scale. What identity was that agent carrying while it worked?
That question sits at the center of agentic AI security right now, and NIST put it in writing on August 27. Ryan Galluzzo leads the Digital Identity Program at NIST. Bill Fisher is a security engineer at NIST's National Cybersecurity Center of Excellence. Together they published a post making the case that agentic AI needs a strong identity foundation. Agents doing real work today mostly borrow the credentials of the human who owns or operates them. Few carry a verifiable identity of their own.
NIST described the scope in its own words. Agentic AI is being applied across "a multitude of use cases, from buying personal items on Amazon to customer service applications to enterprise security and software development." The NCCoE has a project under way called Software and AI Agent Identity and Authorization. The aim is standards-based ways to identify, manage, and authorize the actions agents take. Its public comment period has closed, and the team is working through the responses. FIDO, the Open Identity Foundation, and Anthropic are named in the same post. All three are working the problem from their own direction.
Two carriers put an AI agent on real network work
The Deutsche Telekom and Vodafone test ran an agent at cross-domain, multi-vendor coordination. That is the kind of work that fills an engineer's calendar for weeks. The reported result:
"A process that would typically take an engineer multiple weeks of cross-domain, multi-vendor coordination can be completed by an AI agent within a single day."
Behind that sentence is an engineer who spent those weeks on calls with four vendors. Now that engineer reviews an agent's output instead. The identity-management layer under the test came from a company called Tallence, with large language models from Anthropic and Mistral. Karsten Thon, Senior Business Architect at Deutsche Telekom, called network infrastructure identity existential, because that infrastructure carries public and government services. Steffen Krippner, Senior Manager for OSS Fulfillment at Vodafone, named the goal "governed intelligence." Part of the testing method, in his words: "deliberately injecting conflicting or incomplete data to expose weaknesses in the AI's decision-making."
That last line is the most useful thing in the whole story for anyone running agents today. They fed the agent bad data on purpose, to see whether it would catch its own errors. Around it they built four safeguards: a policy dry-run before anything moved, human approval in the loop, a controlled rollout, and negative testing. Every one of those safeguards is available to any enterprise or agency this quarter. All four are a matter of decision and discipline.
NIST is building the AI agent identity layer these systems need
Credit where it belongs. The NCCoE opened this work while most enterprises were arguing about whether agents were real. It published its case under the names of the people doing it. That matters more than it sounds. The NCCoE put Galluzzo and Fisher on a public post, opened a comment period, and is working through what came back. Outsiders can actually join a process built that way. I have watched standards work land well and land badly. The difference is almost always whether practitioners showed up while comments were open.
One structural fact sits underneath all of it. It runs through most of what I write about AI governance: rules written for a slower world. Software ships on a weekly clock. A standard that hundreds of vendors will implement has to be right the first time, which is a slower and entirely necessary clock. When those two clocks run beside each other, capability lands in production before the standard describing it arrives. The identity problem showed up in the network before the identity standard did.
This is the moment when outside expertise is worth the most. A federal standards project keeps taking input well past the day its comment window closes, through workshops, draft revisions, and the informal channel of practitioners who show up with real deployment evidence. Bring the negative-test results, the failure modes, the place where a borrowed credential broke something. Industry has been building on the same problem on its own initiative, which I wrote about when an alliance of vendors stood up its own governance work. Parallel effort is the healthy version of this, and it works best when the people running agents in production put their evidence on the record.
Above the Algorithm is where accountability lives
An agent can execute a policy change across four vendors in an afternoon. A person has to own the decision it made. Judgment, taste, trust, and accountability are the territory I call Above the Algorithm. Agent identity is the plumbing that makes that territory enforceable. Without a verifiable identity attached to the action, "who approved this" becomes a question your logs cannot answer.
I spent 20 years at Cisco, where I shaped a $1.1B innovation portfolio across 14 countries. Every time we let a system act on its own authority, the review came down to one line: whose name is on this. That line has held up. The number of things that can act has changed.
Most organizations cannot answer it today. When I wrote about how few of them can even count the agents already running inside their walls, the replies came from security leaders. Their audit committee had asked the same question and gotten a shrug.
So carry one question into your next leadership meeting, whether you run an enterprise security function or a public agency. When an agent in our environment changes something, whose identity is attached to that change, and what were the limits on what it could touch? If the answer is a person's login, you have found this quarter's work. Ask it before an auditor asks it for you. And if you see this differently, I'm easy to find.
Sources: NIST Cybersecurity Insights blog, "Back to the Future: Why Agentic AI Needs a Strong Identity Foundation," August 27, 2026, by Ryan Galluzzo and Bill Fisher. NIST NCCoE, "Software and AI Agent Identity and Authorization" project page. Biometric Update, "NIST, European telcos converge on identity as foundation for agentic AI," August 28, 2026, by Joel R. McConvey, reporting on the TM Forum Catalyst proof-of-concept with Deutsche Telekom and Vodafone.
What does it mean for an AI agent to have its own identity?
It means the agent holds a credential issued to the agent itself, with its own authorization scope, instead of acting under a person's login. That separation is what lets an audit trail show which agent acted, on whose authority, and what it was permitted to touch.
What can an organization do about AI agent identity while NIST's standard is still being finalized?
Every safeguard in the Deutsche Telekom and Vodafone test is available today: a policy dry-run, human approval in the loop, a controlled rollout, and negative testing with deliberately bad data. None of it requires waiting on a finished federal standard.
Here is what makes Alex a credible voice on this topic: Alex advises the California State University system on AI governance and spent 20 years at Cisco, where he shaped a $1.1B innovation portfolio across 14 countries on 5 continents, built on exactly the kind of multi-vendor network infrastructure this proof-of-concept put an agent to work on.
Bring Alex in to help your leadership team answer who your agents act for. Start the conversation →
