How AI Agents Got a Universal Passport
How IICP enables AI agents to connect globally, a story of trajectory.
Original document language: Not established. The interface language does not translate the source document.
Listen to episodeEpisode transcript (54 paragraphs)
- So right now, millions of autonomous AI agents are being built by completely different companies around the world, but like they're almost entirely trapped in their own little bubbles. - Yeah, completely isolated. - Right, like you might have this incredibly smart AI that manages all your travel, but the second it needs to talk to the AI that handles your company's expense accounts, everything just breaks down. -
They don't share a language. - Exactly, they don't share a passport basically. So today we're taking a deep dive into the exact window of time, specifically the summer and fall of 2026, when a group of engineers figured out how to give those agents a universal passport. - We're looking at how the actual underlying plumbing of the autonomous internet is being built, which is just fascinating. - And it didn't just
magically appear from one massive tech giant either. To see how this passport system was forged, we're unpacking a really unique stack of documents today. - Yeah, we managed to get our hands on the internal weekly intelligence briefings from the IICP project. - Which stands for the Intent-Based Inter-Agent Communication Protocol, right? - Right, exactly. And these are like raw war room memos from July to October,
2026. And we're pairing those internal docs with the public archive logs from the IETF's DMSE mailing list. - The IETF being the Internet Engineering Task Force, basically the United Nations of Internet Standards. - Yeah, and their DMSE list is where the absolute grittiest debates about machine-to-machine steering happen. It gets pretty intense. - So if you rely on AI tools, and you're just waiting for the day they
can seamlessly string together complex tasks across the web without you holding their hand, you really need to understand this transition. - Oh, absolutely. - 'Cause we're reconstructing the specific road IICP traveled. I mean, they started out as just another protocol in this incredibly chaotic, crowded landscape. And within just a few months, they became the foundational traffic controller for the next layer of the
internet. - The sheer chaos of that summer landscape, it really can't be overstated. Like in July, 2026, the ecosystem was just exploding. - Total wild west. - Total wild west. Every major tech faction was trying to establish their own protocol as like the HTTP of AI. You had MCP, the Model Context Protocol, rolling out these massive updates specifically to handle autonomous agents. - Right, and you had the A2A, or
agent to agent ecosystem, pulling in huge institutional support at the same time. - Yeah, and honestly, the acronyms and the briefings from this period are just overwhelming. There are mentions of ANP, the Autonomous Network Protocol, and DNS-Aid. - Oh, right, the attempt to use the internet's existing domain name system to handle AI identity validation. - Exactly. Everyone basically wanted to own the entire
pipeline. And in the middle of this absolute free for all, IICP is pushing out their version 1.9.2 update. - But according to their own internal briefings, they're like quietly panicking about something they call a validation deficit. - Yeah, so a validation deficit is basically an engineering term for a very dangerous echo chamber. - Like drinking your own Kool-Aid. - Pretty much. IICP had built this highly
sophisticated system for routing AI requests, but almost all of their testing was happening entirely in-house. - They had no independent engineers kicking the tires. - Right. And a protocol just cannot survive if it only works flawlessly when it's talking to itself. You know, you need other platforms built by totally different people actively trying to break your system. - Which makes perfect sense. I mean, building
a world-class telephone network is meaningless if you only manufacture two phones and just keep them in the same room. - Exactly. You need to know what happens when someone dials in from like a rusty rotary phone across the ocean. - So true. And while IICP is trying to figure out how to get this external validation, the walls really start closing in on them. By August, the threat level completely spikes. - Yeah, the
creators of MCP formerly charter an agents working group. - Which is a massive signal to the market. Basically saying MCP wants to own the entire agent interaction space. - Right. And simultaneously, the IEEE, the Institute of Electrical and Electronics Engineers, which is, you know, the most powerful standards bodies in the world, they start drafting a new standard called P3931. - Right, and I was reading through
the specs of P3931, and it overlaps almost perfectly with IICP's Direct Layer Layer. - Which is basically the phone book of the network, how agents actually find each other. - Right. So if I'm looking at this strategically from IICP's perspective in August, I am just completely surrounded. Like MCP already has the execution capabilities, and now the IEEE is standardizing the phone book. - Yeah, it was a very bad
position to be in. - Most startups would just fold under that kind of institutional pressure, but IICP didn't fold. They narrowed their scope. - They really did. They executed this absolute masterclass in architectural pivoting, because, you know, when you can't outmuscle a juggernaut like MCP, you have to change the game you're playing. - Right. - IICP looked at this messy landscape and realized everyone else was
fighting to be the delivery truck. You know, the protocol that actually carries the payload and executes the task. So IICP decided to just step away from execution entirely. - They pivoted to focus exclusively on the control plane. Basically, they became the dispatcher. - Yes, exactly. - Let me try to model this just to make sure I'm getting it. If an AI agent says, "I need to find someone to translate this legal
document, verify the cryptographic signatures, and then deposit the fee." IICP isn't actually doing the translating, right? - Right. They aren't doing the verification either. IICP is just scanning the network to figure out which specialized agent is currently online. Which one has the verified security credentials to handle legal text, and you know, which one has the lowest latency. - Oh, okay. That makes sense. -
That is the core essence of intent-based resolution. An agent declares its intent, what it needs done, and IICP resolves that intent by routing it to the optimal eligible provider. - So by stepping out of the execution layer, IICP achieved something kind of brilliant. Suddenly MCP and A2A were no longer their direct competitors. - Exactly. MCP and A2A became the specialized vehicles that IICP was directing the
traffic toward. - Wow. That completely reframes the entire market for them. But I mean, having a brilliant architectural pivot on a whiteboard doesn't solve the diplomacy problem. - No, it definitely doesn't. - You still have to convince the IETF and the IEEE, these massive slow moving standards bodies, that your specific dispatcher is the one the entire internet should adopt. How do you walk into a room of hostile
competitors and actually win them over? - Well, you do it by changing the currency of the argument. The intelligence briefings for mid-August show a very deliberate shift in IICP's diplomatic strategy. - Okay, what did they do? - Usually when you want to establish an internet standard, you draft this massive, highly theoretical document. You submit like a hundred page blueprint and ask everyone to agree on the
theory. - Right. And in fact, a draft called Requirements for Intent Routing circulated that August. And it was essentially just a giant theoretical wishlist. - Exactly. A hundred pages of people basically arguing over how a hypothetical car should be built. - But IICP realized their unique advantage was that they weren't dealing in theory anymore. They had actual working code. - Yes. - They had spent months battling
the brutal, ugly engineering realities of trying to make disparate AI agents communicate. They had already solved things like stale provider state. - Let's hover on stale provider state for a second because understanding the underlying mechanics here is crucial to understanding why their code was so valuable. - Go for it. - In a network of autonomous agents, right? An agent might broadcast to the directory, hey, I am
available to process video files. But like seconds later, that agent runs out of memory and silently crashes. - Right. Which happens all the time. - Right. And if the network still thinks that agent is available, it sends a massive video file into a complete black hole and the whole system just locks up. - Yeah. And solving that requires really complex mechanisms. You can't just use a simple binary up or down switch.
IICP had built a system of probabilistic decay and intelligent heartbeat monitoring to verify if an agent was actually alive. - Without completely overwhelming the network with ping requests, I imagine. - Exactly. And they also tackled credential rotation races, which is, you know, what happens if an agent's security token expires and the exact millisecond a task is handed to it? - Oh, wow. Yeah, that is the
difference between theory and reality. It's like walking into a room full of theoretical architects who are aggressively debating the blueprint for a car and you just drop a muddy, heavily driven wheel right on the conference table. - I love that analogy. - And you just look at them and say, we drove this for a thousand miles. Here's exactly where the tread wore out. Here's how the axle sheared off. And here is the
code we wrote to fix it. You can argue with a blueprint all day long. You cannot argue with a muddy wheel. - You really can't. And that muddy wheel strategy is actually legendary in internet diplomacy. The IETF operates on a philosophy of rough consensus and running code. - Ah, running code. - Yeah. So IICP stopped demanding to be the new standard. Instead, they positioned themselves as verifiable prior art. They
handed over their test fixtures. They literally published their negative test evidence. - Showing the community exactly how their system collapsed under load and how it eventually recovered. They turned their internal validation deficit into a massive public asset. - Exactly. - So they have this muddy wheel, this battle tested code, but where do they actually show it to the rest of the world? I mean, this is where
the public archives of the DMSC mailing list becomes so illuminating. We actually get to see this raw multipolar diplomacy happen in real time. - Yeah, between September and October. The DMSC logs read like a very tense United Nations summit for software engineers. - Seriously. - Between September 27th and 30th, Roble Moomin, who is a key IICP architect, executes the strategy. He posts a thread literally titled,
"IICP follow-up implementation experience with intent-based agent selection and routing." - He drops the muddy wheel onto the public mailing list. - He drops it right on the table. And it detonates. It immediately sparks this deep technical engagement from heavyweights like Ai Jun Wang. - But what is so fascinating is that IICP isn't the only one talking. You have engineers from totally different companies
independently converging on the exact same roadblocks. - Yeah, you see Sumit Ahuja submitting drafts on inter-domain agent routing policy. And you have Amman Shrak, Juting Li, and Guigli Wang going back and forth in these incredibly dense threads about the post-onboarding security plan. - Which is so crucial. Ahuja's drafts in particular are really validating for IICP. Revision negative zero two of his draft drops on
October 4th, and it focuses heavily on cross-domain policy and self-deprioritization. - Great. Self-deprioritization is such a fascinating concept because if an AI agent is getting hammered with millions of translation requests, it can't just shut down. And it obviously can't just blindly accept them until its server melts. - Right, it has to have a standardized way to signal back pressure to the network. - Exactly.
It has to say, "Hey, I am nearing capacity. Please start routing lower priority traffic to someone else." And Ahuja is trying to figure out how to make that back pressure readable across completely different company domains. - And as the community wrestles with these concepts, the technical consensus begins to mirror IICP's architecture almost perfectly. - It's wild to see it happen in real time. - Right. When the
DMSC technical discussion resumes on October 6th, the entire list is debating the crucial distinction between admission to the network and per invocation enforcement. - Let me break down how I'm visualizing that difference, just to make sure it's clear. Admission is like passing the background check to get hired at a high security facility. You get a badge, you get to walk through the front door, and you are on the
corporate network. - Yes. - But per invocation enforcement means that just because you're sitting in the lobby, you don't automatically get to open the vault. Every single time you reach for a door handle, like every single invocation of a task, the system checks your badge again to ensure you have the specific rights for that specific action. - Right. It is an absolute zero trust architecture. And that zero trust
model is vital for autonomous agents. - Because an agent might be admitted to the network to say, read public schedules, but it needs a completely different level of per invocation authorization to execute a financial trade. - Exactly. The mailing list firmly established that authorization to exist on the network is fundamentally distinct from the enforcement of a specific task. - Which provided massive independent
corroboration for IICP's decision to separate the discovery of an agent from the actual payload execution. - The architects at the table basically finally agreed that the car needed the exact type of wheel IICP had just dropped on the table. - The intellectual groundwork was secured, but having mailing list consensus is really only half the battle, right? Your code still has to actually compile and it still has to
run in the wild. - Oh, absolutely. Which brings us to the ultimate qualification milestone. The intelligence briefings from October 3rd to the 9th detail a really grueling testing phase for ICP's frozen successor. - And a frozen successor being like a locked, finalized version of the code base. - Right, no more tweaks, no more hot fixes. You freeze it and you run it through the gauntlet. They subjected it to native
Sentinel executions. And these are just mocked up simulations. Sentinel executions are background demons continuously running end-to-end integration tests against the live network state. - Okay, so real world conditions. - Exactly. And they passed on Linux ARM 64. They passed on Mac OS ARM and Linux x86-64. The logs show passing executions. - Which proves the protocol runs flawlessly across completely different
hardware architectures. That's huge. - It is. But the tension in those logs is still palpable because there is always a final boss in software engineering. - Always. - They are actively debugging the Windows x86-64 build and it is failing natively. But it's not failing because the complex AI routing logic is flawed, right? It's failing because of one of the most ancient mundane bugs in computing history. - Yep, the
CRLF new line issue. - The carriage return line feed mismatch. - For anyone lucky enough to have avoided this nightmare in their career, Windows basically handles the invisible characters at the end of a line of text differently than Macs and Linux do. - Yeah, Windows uses two invisible characters and Mac and Linux use one. And this tiny invisible difference was causing a cryptographic mismatch in their cargo
configuration files. Cargo being the package manager for the Rust programming language, which IACP was built in. - Yeah. - So the entire future of autonomous AI networking is briefly held up by invisible text formatting from the 1980s. - It's hilarious, but it is a phenomenal example of why the IETF demands implementation experience. You will never ever find a CRLF conversion error in a theoretical white paper about
AI. - Never, you only discover it when you try to compile the network on a real machine. And IACP fixed that bug without altering their underlying protocol, which just proves the sheer rigor of their engineering. - And that rigor translates directly into institutional victory. On October 8th, the IETF formally establishes the Agent Proto working group with an approved charter. - In reading the phrasing of this
charter, it feels like the ultimate vindication for IACP's pivot back in August. - Oh, totally. The charter is highly specific about what it will not do. The Agent Proto working group explicitly avoids standardizing how AI agents make decisions. It explicitly avoids replacing MCP or A2A. - Instead, it focuses purely on interoperable dialogue identity, context propagation, and lifecycle management. They basically
codified the dispatcher model. - Exactly. The market essentially rejected the idea of a single monolithic protocol owning the entire pipeline. Instead, we are getting a composable stack. - And a composable stack is really the key to the future of the internet. Let's throw out the tired tech metaphors here. A composable stack is not a layer cake. It operates much more like a high-end restaurant kitchen. - Okay, I like
this. - At the back of the kitchen, you have your specialized line cooks, that is MCP and A2A. They handle the raw execution, the actual chopping and cooking of the data. Then in the middle, you have the expediter, that is the agent to proto layer. The expediter manages the ticket lifecycle, ensuring the appetizer goes out before the main course and keeping track of the conversation across trust boundaries. And at
the front of the house, you have the maitre d, that is IICP. They handle the discovery, the policy, and the routing, basically deciding which tasks come into the kitchen and who is actually qualified to cook them. - That is a perfect way to look at it. And that separation of concerns means that if you invent a better line cook tomorrow, you don't have to tear down the entire restaurant to hire them. - Right, you just
plug them in. - Exactly, you just plug them into the existing execution layer and IICP will automatically start routing tasks to them. And we immediately saw the enterprise market validate this approach. Like on October 6th, GitLab announced its governed software factory. Oh, I saw that announcement. GitLab is a massive player in how software is built and deployed. A governed software factory implies they're
combining agent orchestration with strict security, policy, and provenance tracking. - Right, GitLab recognize that when you have machines doing work at scale, you know, AI's writing code, reviewing pull requests, deploying infrastructure to production, you absolutely require verifiable control boundaries. - Because an autonomous agent writing code is incredibly dangerous if it doesn't have a secure verifiable way to
request authorization to commit that code to the main branch. - You cannot have agents running wild. You need that traffic controller. - So looking back at this whole timeline, it is just an incredible trajectory. I mean, in just a few months, IICP went from an isolated protocol, struggling for validation in an incredibly noisy market, to making a brilliant strategic pivot. - Yeah, abandoning the execution layer to
focus purely on the control plane. And they weaponized their own debugging scars, right? Using their muddied implementation experience to win over the DMSC mailing list. And then they proved their code natively across every major operating system, ultimately helping shape a new standard for the internet. - It's wild. - And the largest takeaway from this stack of sources is fundamentally optimistic, I think. - How so?
- Well, the future agentic web, you know, this era where AI's act autonomously on our behalf across the internet, it is not waiting on a single magical update from one big tech monopoly. It is being hammered out right now, out in the open, through meticulous multipolar diplomacy. It is being built as a composable stack of specialized tools. And that guarantees the future of AI networking will be decentralized, highly
complex, and incredibly resilient. - Which brings us to a final, genuinely provocative thought buried deep in the technical research here. There is a concept mentioned alongside these protocols called proof-derived authorization for sovereign AI systems. - Oh, this is fascinating. - It completely upends how we think about digital identity. 'Cause the premise is that an AI agent might not actually have a permanent
standing identity or a long-term password. - The ephemeral identity model. - Yes. Think about how we operate online right now. We have persistent accounts, we log in, but in this sovereign AI model, when an agent needs to execute a task, it submits a complex cryptographic proof of exactly what it intends to do. - Right. - And based on that math, the network generates an ephemeral, short-lived identity just for the
three seconds it takes to execute that specific authorized task. And the millisecond the task is complete, that identity vanishes. - And from a security architecture standpoint, it is a masterstroke. Because if the identity only exists for three seconds, it cannot be stolen, hijacked, or reused by a malicious actor later. The attack surface essentially drops to zero. - It really does. And I want you to just sit with
the implications of that for a second. We are building a perfectly governed traffic controller for the internet, but very soon, that controller is gonna be directing ghosts. - Literally. - What happens to trust, to legal accountability, and to the fundamental nature of a digital transaction when the entity signing the contract or deploying the code only exists for a fleeting moment before disappearing entirely into
the ether? - That's a wild thought. - It is. The plumbing is built. Now you just have to see what flows through it.
Search and filter the archive
Search by title, description, or category. Every entry is a concrete artifact of the system — a paper, a framework, or an applied study.
Archive categories
Each category shows a different face of the same method. Research threads feed papers; papers consolidate into long-form works; applied studies prove the pipeline on real problems.