Jurisdiction
Global: Agent Authority Ledger
Global carries 23 records on the Agent Authority Ledger as of September 2026: 17 verified at a primary source, 1 reported, 0 announced with no document yet, 1 searched and absent, and 4 open questions. By kind: standard or protocol 13, draft in progress 3, guidance 3, open question 4.
Standard or protocol
13 records
No international standard governs revoking an agent's authority
Global · verified 15 September 2026
The Model Context Protocol relies on short lived access tokens and audience validation rather than on any revocation mechanism for an agent.
ISO/IEC 42001, AI management system
Global · verified 15 September 2026
The standard states that it specifies the requirements and provides guidance for establishing, implementing, maintaining and continually improving an AI management system.
Mastercard Agent Pay
Global · verified 15 September 2026
A partner announcement states that Mastercard Agent Pay will integrate with PayPal's wallet to allow AI agents to simply and securely complete transactions on behalf of PayPal users.
Visa Trusted Agent Protocol
Global · verified 15 September 2026
Visa describes the specification as the official rulebook detailing the technical processes for recognizing a Visa approved agent, including the cryptographic standards in RFC 9421.
SPIFFE workload identity
Global · verified 15 September 2026
SPIFFE is described by its maintainers as a set of open source standards for securely identifying software systems in dynamic and heterogeneous environments.
A2A protocol, agent to agent authentication
Global · verified 15 September 2026
The documentation states that A2A protocol payloads, such as JSON-RPC messages, do not carry user or client identity information directly.
RFC 7591, OAuth 2.0 dynamic client registration
Global · verified 15 September 2026
The specification defines mechanisms for dynamically registering OAuth 2.0 clients with authorization servers.
RFC 8693, OAuth 2.0 token exchange
Global · verified 15 September 2026
The specification defines how to request and obtain security tokens from OAuth 2.0 authorization servers, including tokens employing impersonation and delegation.
RFC 9728, OAuth 2.0 protected resource metadata
Global · verified 15 September 2026
The specification defines a metadata format an OAuth client or authorization server can use to obtain the information needed to interact with a protected resource.
RFC 8707, resource indicators for OAuth 2.0
Global · verified 15 September 2026
The document defines request parameters that let a client signal to an authorization server the identity of the protected resources it is requesting access to.
RFC 6749, the OAuth 2.0 authorization framework
Global · verified 15 September 2026
The framework enables a third party application to obtain limited access to an HTTP service on behalf of a resource owner, or on its own behalf.
MCP 2026-07-28 authorization hardening
Global · verified 15 September 2026
The release post states that authorization servers should return the iss parameter per RFC 9207, and clients must validate it before redeeming a code.
Model Context Protocol authorization
Global · verified 15 September 2026
Authorization servers must implement OAuth 2.1 with appropriate security measures for both confidential and public clients.
Draft in progress
3 records
Web Bot Auth architecture, an IETF Internet-Draft
Global · verified 15 September 2026
The stated goal is to allow automated HTTP clients to cryptographically sign outbound requests, so servers can verify their identity with confidence.
Agent Passport System, an IETF Internet-Draft
Global · verified 15 September 2026
The draft defines Ed25519 agent passports and separately signed principal bindings.
The OAuth 2.1 Internet-Draft
Global · verified 15 September 2026
The draft states that it replaces and obsoletes the OAuth 2.0 Authorization Framework described in RFC 6749 and the Bearer Token Usage in RFC 6750.
Guidance
3 records
OWASP Top 10 for Agentic Applications 2026
Global · verified 15 September 2026
OWASP describes the list as providing practical, actionable guidance to help organisations secure AI agents that plan, act, and make decisions across complex workflows.
OWASP Top 10 for LLM Applications 2025
Global · verified 15 September 2026
LLM01:2025 is Prompt Injection, where user prompts alter the behaviour or output of the model in unintended ways.
Model Context Protocol security best practices
Global · verified 15 September 2026
Token passthrough is an anti pattern where a server accepts a token from a client without validating it was issued to that server, and the document forbids it.
Open question
4 records
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
Who is liable when a delegated agent exceeds its mandate
Global · verified 15 September 2026
The EU AI Act allocates duties to providers and deployers, and does not address an agent acting beyond its instructions.
Answers
What people ask about Global
What is settled in Global?
No international standard governs revoking an agent's authority (absent); ISO/IEC 42001, AI management system (verified); Mastercard Agent Pay (reported, primary not reached); Visa Trusted Agent Protocol (verified); SPIFFE workload identity (verified); A2A protocol, agent to agent authentication (verified); RFC 7591, OAuth 2.0 dynamic client registration (verified); RFC 8693, OAuth 2.0 token exchange (verified); RFC 9728, OAuth 2.0 protected resource metadata (verified); RFC 8707, resource indicators for OAuth 2.0 (verified); RFC 6749, the OAuth 2.0 authorization framework (verified); MCP 2026-07-28 authorization hardening (verified); Model Context Protocol authorization (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
What is being written in Global?
Web Bot Auth architecture, an IETF Internet-Draft (verified); Agent Passport System, an IETF Internet-Draft (verified); The OAuth 2.1 Internet-Draft (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
What do regulators and security bodies advise in Global?
OWASP Top 10 for Agentic Applications 2026 (verified); OWASP Top 10 for LLM Applications 2025 (verified); Model Context Protocol security best practices (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
What has nobody settled in Global?
Does a spending limit belong to the agent or to the principal (open question); How does a sub agent's authority attenuate (open question); Can an agent hold a credential of its own (open question); Who is liable when a delegated agent exceeds its mandate (open question). Each record page quotes the document and says what it changes for a team deploying an agent.
What has nobody settled in Global?
Does a spending limit belong to the agent or to the principal; How does a sub agent's authority attenuate; Can an agent hold a credential of its own; Who is liable when a delegated agent exceeds its mandate. The ledger poses these and does not answer them.
What does Global not have?
No international standard governs revoking an agent's authority. Each absent record says where the ledger looked and when, so the search can be repeated.
Every surface
Cut the ledger another way
By jurisdiction
By kind
Verdicts
Cite this page
Free to reuse under CC BY 4.0, with attribution.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), global on the agent authority ledger.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Global on the Agent Authority Ledger. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/jurisdictions/global
- MLA
- "Global on the Agent Authority Ledger." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/jurisdictions/global.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Global on the Agent Authority Ledger." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/jurisdictions/global.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/jurisdictions/global
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.