A 30-page NIST concept paper does not usually move markets. This one might.

In February 2026, the National Institute of Standards and Technology published a draft on agent identity and authorization that reads, on the surface, like a dry enterprise architecture document. Read it twice and a different shape appears. NIST is quietly defining what counts as a trustworthy agent for U.S.-aligned procurement: how you identify it, what it is authorized to do, how its actions are audited, and how non-repudiation holds when the agent touches tools and data across systems.

That shape is showing up on the other side of the world too. Beijing has been steadily operationalizing its own scenario-based governance framework for autonomous AI systems, oriented around state-led acceptance criteria rather than industry plugfests. Different philosophy. Same underlying question. Who decides what a permissible agent looks like.

It would be a mistake to inflate either document into a finished standards war. Neither is law. Neither has full enterprise adoption. But the direction is legible. The agent market is starting to pivot, not on model intelligence, but on whose identity and authorization semantics become the default vocabulary of deployment.

That is a more interesting fight than the one most people are watching.

The atomic unit is the autonomy kernel

For most of the last two years, the agent conversation has been about capability. Can it browse? Can it code? Can it complete a multi-step task without losing the thread? Those questions are mostly answered now. The frontier moved.

The new atomic unit is something tighter. Call it the autonomy kernel: the smallest deployable bundle that answers three questions at runtime.

  • Who is this agent, cryptographically?
  • What is it allowed to do, right now, against this resource, on behalf of which principal?
  • What did it actually do, and can that record be trusted later by an auditor who was not in the room?

This is the layer NIST's concept paper actually targets. Identity. Authorization. Audit trail. Non-repudiation. The language is procurement-grade because the audience is procurement. When a Fortune 500 buyer or a federal contracting officer needs to approve an agent that books travel, edits code, or moves money, they are not going to read a benchmark score. They are going to ask whether the autonomy kernel is legible.

This is the same throughline we have been tracking in The Agent Moat Is Proof. Capability has commoditized faster than control. The scarce resource is the layer that makes agent behavior survivable at production speed.

Two standards philosophies, one procurement problem

The U.S. and Chinese tracks are not converging, and they are not yet fully incompatible. They are diverging on method.

NIST's approach, visible in both the identity concept paper and the CAISI request for information on securing agent systems, is industry-consensus and interoperability-first. Define the interfaces. Run the plugfests. Let vendors prove their kernels against shared evaluation suites. The implicit bet is that legibility scales through composable testing.

China's emerging framework is scenario-led and state-anchored. Define the high-consequence deployment contexts. Specify acceptable agent behaviors per scenario. Hold the operator accountable to those scenarios through inspection rather than open benchmarks. The implicit bet is that legibility scales through bounded use cases.

Neither approach is naive. Both produce gating effects. An agent platform that cannot articulate its identity and authorization model in NIST-compatible terms will struggle to win regulated U.S. procurement. An agent platform that cannot map its behavior into China's scenario taxonomy will struggle to operate inside Chinese markets. The companies building seriously across both jurisdictions will need what is starting to look like dual-ready semantics: an autonomy kernel whose identity, scopes, and audit artifacts can be expressed in either dialect without rebuilding the agent.

This is the geopolitical edge of the agent stack. Not chip export controls. Not model weights. The semantics of who an agent is and what it is permitted to do. Who Defines Safe Enough Wins the Stack made a related point about safety evaluations becoming market infrastructure. Identity and authorization are the next layer down, and the more consequential one.

Microsoft and NVIDIA are running the same bet in different clothes

The two most visible enterprise agent platforms read, at first, like opposites. Look closer and they are placing the same architectural wager from different angles.

Microsoft's play is the bundled control plane. Agent identity flows through corporate directory. Authorization rides existing role and policy infrastructure. Audit lands in the same logging spine the security team already trusts. The pitch is regulatory legibility by inheritance: if your existing tenant passes audit, your agents do too, because they live inside the same kernel.

NVIDIA's play, sharpened by the March 2026 launch of the Agent Toolkit and OpenShell runtime, is composable and runtime-enforced. OpenShell is described as an open-source runtime that enforces policy-based security, network, and privacy guardrails for autonomous agents. The AI-Q blueprint pairs frontier orchestration with open Nemotron models for research, reportedly topping DeepResearch benchmark accuracy while cutting query costs roughly in half. The pitch is regulatory legibility by inspection: any agent built on this stack carries enforceable, inspectable execution semantics regardless of which vendor's models are inside.

Jensen Huang framed the moment as an inflection where AI extends beyond generation and reasoning into action. That framing is right, but it slightly understates what is being built. The Agent Toolkit is not just an action layer. It is a candidate autonomy kernel that hopes to be plugfest-ready when NIST's evaluation criteria firm up.

Neither bet is heroic. Neither is doomed. Bundled kernels win where the buyer values continuity with existing identity and policy infrastructure. Composable kernels win where the buyer needs to operate across cloud boundaries, sovereign deployments, and heterogeneous regulatory regimes. The honest answer is that most large enterprises will end up running both, which is precisely why dual-ready semantics matter more than vendor allegiance.

What this makes possible

If you accept that the autonomy kernel is the unit that matters, several things become available that were not before.

Procurement can be redesigned around questions a serious buyer can actually verify. Show me your agent identity model. Show me how authorization narrows by task and principal. Show me an audit artifact a regulator in two jurisdictions would accept. That is a buyable conversation. It replaces the demo theater that has dominated agent sales cycles for two years.

Build teams gain a real architectural target. Instead of choosing between vendors on roadmap optimism, they can design the agent's identity, scope, and audit interface as a first-class internal contract, then bind it to whichever runtime makes commercial sense per geography. The kernel becomes portable. The vendor becomes substitutable.

And the market gains a clearer signal for what to fund. The next round of valuable agent companies will not be the ones with the cleverest prompts. They will be the ones whose kernels can be carried, audited, and trusted across borders without a rebuild.

The discipline this asks for

Stoic discipline is often misread as caution. In an agent context it is closer to its original function: clarity about where assent belongs.

The practical move is to refuse assent to agent architectures whose identity and authorization layer cannot be explained in one page. Not because such systems are unsafe in the abstract, but because they cannot be reasoned about by the people who will be accountable for them six months from now. Attention has to live where the action lives, which means at the kernel, not at the demo.

Inside that boundary, move fast. Build with frontier models. Compose with open runtimes. Wire agents into workflows that used to take humans days. The point of the autonomy kernel is not to slow this down. It is to make speed survivable.

The next durable advantage is not faster agents. It is agents whose permission semantics you can explain in plain English, audit in production, and carry across regulatory borders without rebuilding them. The teams that internalize that early will spend the next two years selling into markets the rest of the field cannot enter.

A brilliant intern with no badge does not get past the lobby. The same logic, slightly less forgiving, is about to apply to every serious enterprise agent shipped.

Sources and further reading

  • [Concept Paper] Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization: It moves the adoption conversation from “agent safety is important” to a concrete enterprise architecture question: how will organizations identify agents, authorize what they can do, audit actions, and maintain non-repudiation when agents access tools and diverse data sets? This is likely to become a procurement and integration reference point for U.S.-aligned deployments.
  • CAISI Issues Request for Information About Securing AI Agent Systems: This RFI is a near-term window into what NIST will treat as the “measurable gap” between conventional cybersecurity and agent-specific failure modes. If you are building or buying agents, the questions being asked now will shape evaluation expectations and procurement language as the standards track matures.
  • Knowledge Work With Open Agent Development: The story is shifting from “agents as capability” to “agents as enterprise operating infrastructure.” OpenShell’s policy-based enforcement is a direct attempt to make autonomous action deployable under constraints, while the hybrid frontier plus open model approach addresses a practical bottleneck: cost-to-quality at scale.
  • The Agent Moat Is Proof: Adjacent published post that may support internal crosslinking.
  • Who Defines Safe Enough Wins the Stack: Adjacent published post that may support internal crosslinking.