| Internet-Draft | Agent Identity Governance | July 2026 |
| Drake | Expires 21 January 2027 | [Page] |
The Agent Identity Registry System (AIRS) is a federated architecture for issuing persistent, hardware-anchored identities to autonomous entities such as AI agents and robots. Its companion specifications deliberately do not define or empower a governance authority; they describe the functions such an authority must perform and defer its constitution to a separate effort.¶
This document defines that body: the Agent Identity Authority (AIA). It specifies the Authority's name, legal form, mission, and relationship to the protocol specifications; its membership categories and Board composition; binding geographic-diversity rules and non-binding advisory recommendations for ideal composition; the accreditation, dispute-resolution, hardware trust store, transparency, and funding frameworks it operates; and the bootstrap process by which the Authority forms and by which the shared "global" namespace is declared operational.¶
The Authority governs infrastructure, not behavior: it stewards names, hardware roots of trust, and accreditation. It does not regulate what agents do. Its legitimacy derives from being the least-objectionable steward of a shared resource, in the tradition of ICANN, the regional Internet registries, and the W3C, and its charter is designed so that no single nation, region, or company can capture or veto it.¶
This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.¶
Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.¶
Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."¶
This Internet-Draft will expire on 2 January 2027.¶
Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved.¶
This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document.¶
The Agent Identity Registry System ([I-D.drake-agent-identity-registry]) defines a three-tier federated architecture -- Governance Authority, Registry Operators, and Registrars -- for hardware-anchored identity of autonomous entities, modeled on the domain name registration industry. That specification states plainly: "This specification does not define or empower a governance authority." It enumerates the functions such an authority must perform (maintaining the "aid" URN registration, accrediting operators, curating the Global Hardware Trust Store, setting minimum standards, resolving disputes, and allocating shared namespaces), recommends multi-stakeholder representation, and defers "the specific organizational structure, charter, and membership criteria" to a separate effort.¶
This document is that separate effort. It defines the governance body -- the Agent Identity Authority -- that implements the governance role described by the companion specifications. It does not modify those specifications. Protocol syntax, identity semantics, enrollment ceremonies, and provisioning operations remain defined where they are defined today; this document specifies who decides the policy questions those documents leave open, and how.¶
Two design tensions dominate the governance of shared
Internet infrastructure, and both are addressed head-on
here. The first is capture: any body that controls a scarce
resource (here, the shared global namespace and the
hardware trust framework) attracts attempts by governments
and firms to control it. The second is scope creep: a body
constituted to run a registry is perpetually invited to
become a regulator. The Domain Name System survived four
decades because ICANN's authority was narrow, its structure
multi-stakeholder, and its legitimacy earned rather than
conferred; the ITU's periodic attempts to relocate Internet
naming into a treaty body failed for the same reasons in
reverse. This charter borrows deliberately from the bodies
that worked -- ICANN [ICANN-BYLAWS], the
Internet Society [ISOC-GOV], the W3C
[W3C-PROCESS], the RIPE NCC
[RIPE-ARTICLES], the Unicode Consortium
[UNICODE-CONSORT], and the Trusted Computing
Group -- and from the documented failure modes of the ones
that did not.¶
This document defines the constitution, structure, processes, and bootstrap plan of the Agent Identity Authority. It is informational and independent-stream; it defines no protocol, no data format, and no new IANA registry. Its normative-language requirements bind the Authority's charter and the parties that voluntarily contract with the Authority (accredited Registry Operators and Registrars), not implementers of the wire protocols.¶
The following are explicitly outside the Authority's mission and outside the scope of this document: regulation of agent behavior; content policy of any kind; licensing, evaluation, or certification of AI models; reputation scoring; remote disablement ("kill switches") of agents; and law-enforcement functions beyond responding to lawful process under a published policy. Behavior is the province of relying parties, independent reputation services, certification bodies, and public law -- separate layers, per the layered reference model of [I-D.drake-agent-identity-problem-statement].¶
The Authority implements the "Governance Authority" role referenced throughout the companion documents:¶
Where this document and a companion protocol specification appear to conflict on a protocol matter, the protocol specification controls. Where they appear to conflict on a policy or institutional matter, this document controls. The Authority MAY adopt policies that constrain accredited parties beyond the protocol minimums, but MUST NOT adopt policies that contradict protocol invariants (for example, the retire-only handle remedy, the permanence of canonical identifiers, or the prohibition on fingerprint reassignment).¶
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. In this document these key words express requirements on the Authority's charter, bylaws, and contracts, not on protocol implementations.¶
The terms "Agent Identity Document", "canonical identifier", "handle", "hardware fingerprint", "trust tier", "Shared Namespace", "Registry Operator", "Registrar", and "Relying Party" are used as defined in [I-D.drake-agent-identity-registry]. In addition:¶
The body is named the Agent Identity Authority, abbreviated AIA. The name is descriptive of the function (stewardship of agent identity infrastructure), contains no national, commercial, or ideological reference, and translates cleanly. "Authority" is used in the registry sense -- the authoritative source for a namespace, as in "certificate authority" and "numbering authority" -- and not in a regulatory sense.¶
One collision deserves acknowledgment: in X.509 PKI, "AIA" also abbreviates the Authority Information Access certificate extension, which appears throughout the hardware-attestation ecosystem this body serves. The collision was judged acceptable because the two usages never occupy the same grammatical position, but technical documents discussing certificate contents SHOULD write the body's name in full, or as "the Authority", where ambiguity could arise. No alternative name was found that preserved descriptiveness and neutrality without introducing a different collision.¶
The Authority SHALL be constituted as a non-profit, non-governmental membership association. The RECOMMENDED form is an association under Articles 60-79 of the Swiss Civil Code [SWISS-CC]: a legal personality created by adoption of statutes, with governance vested in a general assembly of members and an elected committee. This is the form used by ISO, the IEC, and numerous international technical and standards bodies, and it maps directly onto the membership-and-board structure defined in this document. The RIPE NCC's Dutch membership association [RIPE-ARTICLES] demonstrates the same pattern operating registry infrastructure for three decades.¶
Two alternatives were considered and rejected:¶
The Authority's statutes MUST provide that: it operates on a non-profit basis with no distribution of surplus to members; membership is open on objective criteria without regard to nationality; and dissolution transfers assets and escrowed data to a successor steward designated under Section 14, never to members or to any government.¶
The Authority MUST be headquartered and legally constituted in a jurisdiction widely perceived as neutral, with a strong rule of law, an established ecosystem of international organizations, and no history of using domestic legal process to project policy onto global technical infrastructure. The RECOMMENDED seat is Geneva, Switzerland. Singapore is a suitable alternative, and the Formation Committee (Section 12) MAY select it, or another jurisdiction meeting the same criteria, after publishing a comparative analysis for public comment.¶
To bound residual jurisdictional risk, the Authority SHOULD, within three years of constitution, establish a secondary legal presence in a second neutral jurisdiction in a different region, capable of continuing the Authority's critical functions (trust store publication, escrow custody, accreditation administration) if the primary seat becomes untenable. See Section 16.3.¶
The mission of the Agent Identity Authority is to steward the shared "aid" namespace and the trust framework on which it depends, for the benefit of all who rely on verifiable identity for autonomous entities. In service of that mission, and limited to it, the Authority:¶
The Authority governs the registry, not the registered. It records that an identity exists and how it is anchored; it takes no position on what the identified entity does.¶
The Authority MUST NOT: assess, score, or publish opinions on the behavior, safety, or trustworthiness of any identified entity; condition identity issuance on the purpose, content, or politics of an agent's activity; operate or mandate any mechanism for remotely disabling an agent; regulate, license, or certify AI models or robotic products; or act as an agent of any government. Requests that the Authority perform such functions are, by this charter, out of scope, and declining them requires no Board action.¶
This narrowness is not modesty; it is the mechanism by which universal participation is possible (Section 6.2) and by which the Authority avoids becoming a single point of political control over autonomous systems worldwide.¶
The Authority is a membership organization. Membership confers participation rights in policy development and, for Full Members, voting rights in Stakeholder Group elections. Membership MUST be open to qualified applicants from any country; nationality, and the political system of an applicant's home jurisdiction, MUST NOT be admission criteria.¶
Full Membership is open to legal entities and, in the Civil Society and Academia group, natural persons, that demonstrate a bona fide operational, commercial, research, or public-interest stake in agent identity infrastructure and that self-assign to exactly one Stakeholder Group (Section 5.2). Full Members pay annual dues on a published, revenue-banded schedule with reduced bands for small organizations, academic institutions, non-profit organizations, and applicants headquartered in regions underrepresented in the membership.¶
For all voting purposes, an organization and its affiliates (entities under common control) count as a single Full Member and cast a single vote. The Authority MUST require affiliate disclosure at admission and annually thereafter; concealment of affiliation is grounds for suspension. This rule is the primary structural defense against electoral capture by a single firm registering many subsidiaries.¶
Associate Membership is open to any interested party at nominal or waived cost. Associate Members receive all public materials, participate in working groups and public comment, and may attend all open meetings, but do not vote in Stakeholder Group elections. Associate Membership is the intended on-ramp for individuals, students, and organizations evaluating deeper participation.¶
Observer status is reserved for governmental and intergovernmental participants and is exercised through the Government and Regulatory Advisory Committee (Section 5.9). Observers have voice -- the right to speak, to file advice, and to receive a reasoned written response -- but no vote and no Board seat. This mirrors the role of ICANN's Governmental Advisory Committee and is deliberate: government expertise is valuable; government control is disqualifying (Section 16.1).¶
The Board MAY conclude liaison arrangements with standards and operational bodies whose work adjoins the Authority's, including the IETF and IAB, the W3C, the Trusted Computing Group, the FIDO Alliance, M3AAWG, FIRST, the Unicode Consortium, regional Internet registries, and robotics standards bodies. Liaisons receive a non-voting observer seat at Board meetings and reciprocal document exchange. Liaison arrangements MUST be published.¶
Admission decisions are made by staff against published objective criteria, with refusals appealable to the Independent Review Panel (Section 7.5). A member may be suspended or expelled only for cause stated in the bylaws (non-payment, affiliation fraud, sustained disruption of process), by two-thirds Board vote, with written reasons published and appeal available. Disagreement with Authority policy is never cause.¶
The Board consists of fifteen (15) voting Directors, allocated across Stakeholder Groups as follows, plus the non-voting participants listed in Section 5.3.¶
| Stakeholder Group | Seats | Selection |
|---|---|---|
| Issuers (Registry Operators and Registrars) | 3 | Elected by group |
| Infrastructure Operators and Relying Parties | 3 | Elected by group |
| Hardware Security Manufacturers | 2 | Elected by group |
| Robotics and Embodied AI Manufacturers | 2 | Elected by group |
| Anti-Abuse and Trust and Safety | 2 | Elected by group |
| Civil Society and Academia | 2 | Elected by group |
| Independent Director | 1 | Nominating Committee |
The allocation is designed so that supplier interests (Issuers plus the two manufacturer groups: seven seats) cannot outvote consumer and public interests (Infrastructure Operators and Relying Parties, Anti-Abuse, Civil Society, and the Independent Director: eight seats), and so that no single group approaches the eight votes an ordinary majority requires or the ten a supermajority requires.¶
Directors serve three-year terms, staggered so that one-third of seats (as nearly as allocation permits) turn over each year. The initial Board draws lots to assign one-, two-, and three-year initial terms within each Stakeholder Group. No person may serve more than two consecutive full terms; a former Director becomes eligible again after a break of one full term. A Director who changes employment such that their Stakeholder Group assignment would change MUST disclose the change; the seat is vacated if the group's members so petition and a majority of the Board concurs.¶
Each Stakeholder Group elects its Directors by vote of the Full Members assigned to that group, using the single transferable vote for multi-seat elections. Elections are administered by an Election Committee of members not standing for election, with published voter rolls (member names, not natural-person contact data), published candidate statements, and a published tally. A candidate need not be an employee of a member.¶
The Nominating Committee -- seven persons drawn by published procedure from the six Stakeholder Groups and the liaison community, none of whom may be a current Director -- appoints the Independent Director, and MUST use the appointment to remedy the Board's most significant gap in skills, geography, or independence at the time. The Nominating Committee also fills mid-term vacancies in any seat until the next scheduled election for that seat.¶
For the purposes of this charter the regions are: Africa; Asia-Pacific; Europe; Latin America and the Caribbean; Middle East; and North America. A Director's region is determined by country of primary professional domicile, declared at candidacy. The following constraints are binding on every election and appointment cycle, and the Election and Nominating Committees MUST resolve any conflict between raw election results and these constraints by the published rebalancing procedure (successive elimination of the lowest-ranked surplus candidate from the over-represented country or region):¶
Ordinary business is decided by a majority of Directors present and voting, quorum per Section 5.6. The following require the affirmative vote of two-thirds of the full Board (ten of fifteen):¶
The following require the affirmative vote of three-quarters of the full Board (twelve of fifteen) AND ratification by a two-thirds vote of Full Members voting, with every Stakeholder Group's participation solicited:¶
No class of decision may be reserved to any single member, Stakeholder Group, government, or external body. The bylaws MUST NOT create golden shares, appointment rights for governments, or any mechanism by which one party can unilaterally block a decision the thresholds above would otherwise carry.¶
Every Director MUST file, and annually update, a public disclosure of employment, directorships, and material financial interests in accredited parties, Trust Store applicants, and dispute-resolution providers. A Director MUST recuse from any matter in which the Director or the Director's employer has a direct financial interest -- including, for Hardware Security Manufacturer Directors, Trust Store decisions concerning their own or a direct competitor's roots. Recusals are recorded in the published minutes. Directors owe their duty to the Authority's mission, not to the constituency that elected them.¶
The Government and Regulatory Advisory Committee (GRAC) is open to representatives of national and subnational governments, intergovernmental organizations, AI governance bodies, robotics safety regulators, and digital identity authorities. Membership is open to any government without regard to its political system, recognition disputes notwithstanding; the GRAC's own rules of procedure handle representation questions, as the ICANN GAC's do.¶
The GRAC may issue formal advice to the Board on any matter within the Authority's mission. The Board MUST consider such advice and MUST respond in writing, with reasons, before finalizing the decision concerned; where the Board acts contrary to GRAC advice it MUST publish its reasons. GRAC advice is never binding, and GRAC participants hold no vote in any Authority process. This "voice without vote" design gives regulators a documented, legitimate channel -- and removes the argument that capture is the only way to be heard.¶
This section is advisory. It records the founding community's considered view of what a healthy Board and membership look like, for the guidance of the Formation Committee, the Nominating Committee, electorates, and future Boards. Nothing in this section overrides the binding rules of Section 5; equally, satisfying the binding rules while ignoring this section would honor the letter of the charter and miss its point.¶
The initial and ongoing composition of the Board, committees, and senior staff SHOULD, taken together, include people with the following backgrounds:¶
Beyond the binding rules of Section 5.6, the following recommendations apply:¶
Accreditation is required for any party operating as a Registry Operator or Registrar within a shared namespace. Accreditation criteria are published, objective, and applied equally; onboarding is permissionless in the sense that no incumbent's approval is required.¶
Accreditation criteria MUST be objective, published, and applied without regard to the applicant's nationality. They incorporate the requirements of [I-D.drake-agent-identity-registry] -- for Registrars: verified capability to perform hardware attestation for at least three of the five hardware types, an OIDC-compliant token service, the provisioning client interface of [I-D.drake-agent-identity-epp], minimum data-retention and privacy standards, enrollment tooling, annual compliance audit, and a financial bond or insurance covering escrow and wind-down; for Registry Operators: availability commitments, non-discriminatory provisioning access for all accredited Registrars, fingerprint-index integrity, daily escrow deposits per [I-D.drake-agent-identity-epp], and annual security audit by an Authority-approved assessor -- plus demonstration of organizational and financial stability proportionate to the role.¶
Standard agreements MUST be uniform: individually negotiated side terms with particular accredited parties are prohibited, closing the favored-operator channel through which registry regimes have historically been captured.¶
Accredited parties undergo annual audits and MUST report material security incidents within seventy-two hours of determination. Escalating enforcement applies: notice and cure period; suspension of new-enrollment rights; revocation. Revocation requires a two-thirds Board vote (Section 5.7) and triggers the registrar-failure transition of [I-D.drake-agent-identity-epp]: sponsored identities are transferred to accredited successors, using escrowed data where the failed party does not cooperate, such that no enrolled identity is stranded by its Issuer's failure. Enforcement actions and their reasons are published.¶
The Authority MUST maintain an Independent Review Panel (IRP) of at least seven jurists and technical experts, appointed by the Board for staggered five-year non-renewable terms, none of whom may be a Director, staff member, or affiliate of an accredited party. Accreditation refusals, enforcement actions, membership refusals and expulsions, and claims that the Board has acted outside this charter are appealable to a three-person IRP panel, whose decisions on charter conformance bind the Board. IRP procedures, filings, and decisions are public.¶
The Authority MUST adopt and maintain an Agent Handle Dispute Resolution Policy (AHDRP), incorporated by reference into every handle registration in a Shared Namespace, modeled on ICANN's Uniform Domain-Name Dispute Resolution Policy [UDRP] with the substantive adaptations the identity architecture requires.¶
A complainant prevails by establishing each of the following, mirroring the UDRP's three-part test:¶
The only available remedy is permanent retirement of the handle. A handle MUST NOT be transferred to the complainant or to any other identity, and a retired handle string MUST NOT ever be registered again by any identity. This departs deliberately from the UDRP, whose principal remedy is transfer, because handles alias non-transferable identities: transferring a handle would transfer accumulated recognition to a different entity, violating the indelibility principle of [I-D.drake-agent-identity-registry]. The retire-only remedy also eliminates the economics of handle squatting -- a squatter can never profit from a dispute, because the asset is destroyed rather than conveyed -- while fully protecting mark holders, whose interest is the removal of the infringing name from use. The losing registrant's identity, canonical URN, reputation history, and authentication capability are unaffected; only the alias is withdrawn.¶
Procedural provisions follow the UDRP pattern: disputes are heard by panels of one or three panelists convened by Authority-approved independent providers; the complainant bears provider fees (both parties share them when the respondent elects a three-member panel); proceedings are conducted in writing; decisions are published in full; and implementation of a retirement is stayed for ten business days to permit either party to commence court proceedings, which are never precluded by the AHDRP. The Authority MUST approve at least two providers in different regions, and MUST publish panelist rosters and per-panelist outcome statistics.¶
Registry Operators MAY implement a sunrise period at Shared Namespace launch during which holders of registered trademarks may register matching handles ahead of general availability, under Authority-published sunrise rules.¶
Complaints that an accredited party has violated its agreement or a Consensus Policy -- including alleged violations of the anti-Sybil invariants -- are filed with Authority compliance staff, investigated on a published timeline, and resolved under Section 7.4, with IRP appeal available to both complainant and respondent. Remedies run against the accredited party and the record, never against an identity: per [I-D.drake-agent-identity-registry], a finding of fraudulent enrollment is recorded as an annotation on the affected records, and no Authority process can decommission, suspend, or impair an identity's authentication or resolution.¶
The Authority curates the Global Hardware Trust Store: the versioned, signed collection of hardware manufacturer root and intermediate CA certificates against which Registrars validate enrollment evidence. Governance follows the pattern of the public web PKI root programs, particularly the Mozilla Root Store Policy [MOZ-ROOT-POLICY]: transparent criteria, public application processing, mandatory disclosure, and published removal proceedings.¶
A manufacturer CA is eligible for inclusion when the manufacturer demonstrates, in a public application:¶
Inclusion decisions MUST be made on technical criteria only. The nationality of a manufacturer, and the political system of its home jurisdiction, are not criteria; a root earns inclusion by evaluation evidence and practice, wherever it is made. This rule is a direct application of the neutrality principle and is entrenched as a Fundamental Commitment (Section 13).¶
The Trust Store is published at a well-known endpoint, signed with an Authority key held under the threshold arrangements of Section 17.1, mirrored by Registry Operators, and maintained as a public version-controlled repository with a complete change history. Every inclusion, every parameter change, and every removal appears in the history with its rationale. Included manufacturers undergo review at least every three years, and the Authority MAY commission targeted audits on evidence of concern.¶
Removal of a CA requires a two-thirds Board vote after publication of a reasoned removal proposal and at least thirty days of public comment, except that the Authority's security function MAY execute an emergency removal immediately upon credible evidence of CA key compromise, subject to Board ratification within thirty days (failing which the removal lapses). Removal is prospective: it bars new enrollments against the removed root. Identities already anchored to devices under a removed root are not revoked -- identity is never revoked -- but the Authority MUST publish the removal so that Relying Parties can apply their own policy, and SHOULD publish migration guidance for affected device populations. Deprecation timelines for non-emergency removals SHOULD be long enough that deployed fleets are not stranded.¶
The Authority operates in public. Specifically:¶
The Authority's independence depends on its revenue structure. Funding sources are, in intended order of magnitude:¶
The Authority MUST NOT accept government funding -- operating grants, subsidies, in-kind secondments to decision-making roles, or state-directed contributions -- whose acceptance could create dependency or a perception of state control. Governments participate through the GRAC, not through the balance sheet. Ordinary commercial payments by state-owned enterprises acting as accredited parties (accreditation fees at the published schedule) are not "government funding" within this rule; discretionary payments above the schedule are.¶
Fee changes follow Section 10 comment procedure and the two-thirds threshold of Section 5.7. The Authority SHALL build and maintain an operating reserve with a target of twelve months of budgeted expenses, so that no single revenue source's withdrawal can coerce a decision. During the bootstrap period, before fee revenue exists, the Formation Committee MAY accept capped, disclosed, non-governmental seed contributions under the same five-percent concentration principle applied to the formation budget.¶
The registry architecture is deliberately operable before
the Authority exists: the shared global namespace
operates from the outset under an interim Registry Operator
bound by published commitments -- open-source
implementations, full escrow, non-discriminatory Registrar
onboarding, and a public undertaking to transfer the
registry role through the Authority's selection process
([I-D.drake-agent-identity-registry]).
Because identities are permanent and never renumbered, the
eventual handover is invisible to every enrolled agent.
This section defines the path from that starting condition
to an Authority-governed global.¶
Formation begins with an open, publicly announced call for a Formation Committee of nine to fifteen volunteers, collectively spanning at least five of the six Stakeholder Group profiles and at least four regions, with no single organization (with affiliates) holding more than one seat and no single country holding more than three. Initial implementers of the companion specifications are expected and welcome participants but MUST NOT constitute a majority. The Formation Committee's mandate is limited to: drafting statutes and bylaws implementing this document; running at least two public comment rounds of at least forty-five days each on those drafts; selecting the seat per Section 2.3; incorporating the Authority; and administering the first membership drive and first elections.¶
Upon incorporation, the Formation Committee serves as the
interim board with enumerated, limited powers: admitting
members, appointing the Election Committee, adopting an
interim budget, and preparing -- but not deciding -- the
Registry Operator selection process and initial policy
drafts. The interim board MUST NOT allocate any Shared
Namespace, MUST NOT declare global operational,
MUST NOT adopt Consensus Policies, and MUST NOT enter
contracts exceeding twelve months. Interim service is a
disqualification from candidacy in the first Board
election, removing the incentive to entrench.¶
First elections proceed when at least four Stakeholder Groups each have at least five Full Members from at least two regions. Each qualified group elects its seats under Section 5.5; seats of not-yet-qualified groups are filled by the first Nominating Committee for one-year terms and revert to election as their groups qualify. The geographic constraints of Section 5.6 bind from the first election. The seated first Board draws lots for staggered initial terms and assumes full powers; the interim board dissolves.¶
The interim Registry Operator and bootstrap-era Registrars are the system's proving ground, and their experience is an input to governance formation, not a claim on its outcome:¶
The first Board conducts an open, competitive,
criteria-published selection for the global
Registry Operator, with independent technical evaluation
and public comment on the evaluation report before award.
In parallel it adopts the initial Consensus Policies
(enrollment minimums, anti-Sybil enforcement, data
retention), publishes Trust Store version 1, adopts the
AHDRP and appoints providers, stands up the IRP, and
establishes escrow operations under
Section 17.¶
The Board declares the global namespace
operational only when all of the following are true, and
the declaration itself requires a two-thirds vote:¶
Before this declaration, global operates under
the interim Registry Operator's published commitments;
the declaration marks the completed transfer of the
registry role into Authority governance, with no identity
renumbering and no interruption of verification.¶
Indicative, not binding: Phase 0, six to nine months;
Phase 1, three to six months; Phase 2, three to six
months; Phase 3, six to twelve months -- a total of
eighteen to thirty-three months from the formation call to
an operational global namespace. The 2016 IANA
stewardship transition and the launch histories of new
gTLD registries suggest these ranges are realistic. The
bootstrap design removes schedule pressure deliberately:
because global delivers full identity service
under the interim operator's commitments in the interim,
the Authority can afford to be
constituted correctly rather than quickly, and every phase
gate above is a quality gate, not a date.¶
The following provisions are entrenched and amendable only under the highest threshold of Section 5.7:¶
Because the Authority's substrate functions -- Trust Store curation, cross-namespace fingerprint uniqueness policy, and escrow custody -- are necessarily singular, the Authority that performs them must itself be replaceable. The bylaws MUST provide: a continuity plan, exercised annually, under which every critical function can be operated from the secondary jurisdiction of Section 2.3; publication and mirroring of all data (Trust Store, policies, decisions) sufficient for a successor to resume stewardship; and a pre-designated succession procedure under which, if the Authority is dissolved, captured (as adjudicated by the IRP), or rendered inoperative for more than one hundred eighty days, escrowed materials and the "aid" registrant role pass to a successor steward selected by the surviving accredited parties and Full Members under the same composition rules as this charter. The failure of the steward must never become the failure of the namespace.¶
This document requests no IANA actions. It records the intention, anticipated by the registration template in [I-D.drake-email-hardware-attestation], that the Agent Identity Authority, once constituted, assume the registrant role for the "aid" formal URN namespace ([RFC8141]) and any change-controller or designated-expert-nominating roles that the companion documents' IANA registrations assign to the governance authority, in each case subject to the applicable IANA and IESG procedures in force at the time of transfer.¶
The Authority is not a protocol element, but it is an attack surface: whoever controls it influences accreditation, the hardware roots of trust, and the policy floor for every identity in the shared namespace. The threats below are institutional, and the mitigations are structural.¶
Capture vectors and their designed counters:¶
The Authority concentrates functions that the registry architecture identifies as necessarily singular. A captured, compromised, or merely defunct Authority would degrade the entire shared namespace. The registry architecture's survivability guarantees bound the damage: no Authority failure can un-exist an identity or defeat verification, which runs against Issuer keys and enrolled hardware, never against the Authority. Mitigations: the continuity plan and annual exercise of Section 14; signed, mirrored, publicly version-controlled Trust Store publication, so that a last-known-good state survives the Authority (Section 9.2); escrow custody under threshold cryptography spanning jurisdictions (Section 17.1); and the pre-designated successor-steward procedure. Relying parties SHOULD note that Authority unavailability does not interrupt identity verification: tokens verify against Issuer keys, not against the Authority, and the Authority sits outside every request path.¶
Any legal seat exposes the Authority to that seat's compulsion: sanctions regimes, court orders, and national security process could be directed at accreditation decisions, Trust Store composition, or escrowed data. Mitigations: seat selection per Section 2.3; the secondary-jurisdiction presence; threshold escrow keys held by custodians in multiple jurisdictions, so that no single jurisdiction's process can compel decryption (Section 17.1); narrow application of any compelled restriction with published disclosure of what was compelled, to the extent disclosure is lawful, and publication of annual legal-process statistics; and the Fundamental Commitment that nationality is not a criterion, which denies domestic legal actors a policy hook inside the charter itself. Persistent compulsion that forces the Authority to violate its Fundamental Commitments is grounds for the Board to activate relocation under Section 5.7.¶
The Authority's signing key (Trust Store) and escrow decryption key are its highest-value secrets. Both MUST be generated and held in hardware security modules under M-of-N threshold control (RECOMMENDED: 3-of-5) with custodians in at least three jurisdictions, exercised only in logged, witnessed ceremonies whose records are published. Compromise of the Trust Store signing key is handled by published emergency rotation with out-of-band verification paths for mirrors; compromise of the escrow key requires re-encryption of deposits under a successor key, which the escrow format of [I-D.drake-agent-identity-epp] permits.¶
The Authority's most sensitive holding is escrow: daily deposits from Registry Operators containing, for every identity, its full device set -- hardware fingerprints and public keys encrypted to the Authority's escrow key, per [I-D.drake-agent-identity-registry] and [I-D.drake-agent-identity-epp]. Decrypted in bulk, this material is a cross-Issuer device index: a map from physical hardware to identities that neither Relying Parties nor competing Registrars are ever permitted to see. The Authority therefore holds it under the following rules:¶
By architecture, the Authority never receives authentication logs, token-issuance records, message content, or Relying Party interaction data; the separation of identity issuance from behavior observation in the companion specifications is mirrored institutionally here, and the Authority MUST decline data feeds that would erode it. Dispute and accreditation files may contain personal data of natural persons (complainants, registrant contacts, operator emails); the Authority publishes decisions with natural-person data minimized, retains case files only for published retention periods, and applies the seat jurisdiction's data protection law as a floor, not a ceiling. Membership rolls published for election integrity name members, not natural-person contact details.¶
The following table records the principal design borrowings from, and departures relative to, existing multi-stakeholder technical governance bodies. It is informative.¶
| Body | Borrowed | Departed from |
|---|---|---|
| ICANN | Registry/registrar accreditation with uniform agreements; transaction-fee funding; UDRP-derived dispute policy; GAC-style advisory role for governments; supermajority thresholds and Fundamental Commitments from the post-2016 accountability reforms | US incorporation (neutral seat instead); transfer remedy in disputes (retire-only instead); scale of the supporting-organization apparatus (a single Board with Stakeholder Groups instead, per operational minimalism) |
| Internet Society | Chapter-free individual and organizational membership mix; mission-limited charter language | Reliance on a single dominant revenue source (the five-percent cap exists because of this history) |
| W3C | Member-funded consortium with published Process; formal-objection-style recorded dissent; liaison practice | Member-fee-only funding (transaction fees carry the core budget so participation cost stays low) |
| Unicode Consortium | Stewardship of a shared namespace as the entire mission; stability guarantees as entrenched policy (never reassign, never reuse) | Tiered voting weights by membership fee (one member, one vote here) |
| RIPE NCC | Membership-association legal form operating registry infrastructure; charging-scheme approval by the membership | Single-region service scope (global scope requires the binding geographic rules) |
| Trusted Computing Group | Hardware-vendor engagement model; evaluation-based technical criteria for trust decisions | Industry-only membership (civil society and anti-abuse hold reserved seats here) |
| ITU | The six-language publication norm and formal time-zone rotation of meetings | The treaty form, state-only voting, and one-state-one-vote governance -- the model this charter most deliberately declines, per Section 2.2 |
This charter stands on three decades of institutional experiment in Internet governance. The author thanks the communities of ICANN -- particularly the participants in the IANA stewardship transition and the accountability cross-community working groups, whose designs for capture resistance are borrowed here -- the Internet Society, the W3C, the Unicode Consortium, the RIPE NCC and its sibling regional registries, the Trusted Computing Group, and the root store programs of Mozilla and Chrome, for demonstrating in production which governance structures survive contact with governments, markets, and time. The principles of [RFC6852] and [RFC8890] informed the mission limits, and [RFC7282] the decision philosophy. Named reviewers to be added as the document matures.¶