OpenID Foundation Warns That AI Agents Are Breaking Identity Management

OpenID Foundation: Identity Management for Agentic AI [pdf]

The OpenID Foundation's new whitepaper argues that today's OAuth 2.1 and OpenID Connect frameworks work for simple, single-domain AI agents but fail for cross-domain, asynchronous, or highly autonomous ones. It identifies urgent gaps: agent identity fragmentation, user impersonation, consent fatigue, recursive delegation, and browser agents bypassing API controls. The report calls for interoperable identity profiles, explicit on-behalf-of delegation, and new programmatic verification for trustworthy autonomy.

Agents controlling visual interfaces directly (or via MCP into browser orchestrators) bypass all traditional API-based authorization controls. Protecting the open web from lockdown will require robust authentication of web bots or web agents.

More from this day

2026-10-01