Files
ietf-draft-analyzer/data/reports/landscape.md
Chris Nennemann 6771a4c235 IETF Draft Analyzer v0.1.0 — track, categorize, and rate AI/agent drafts
Python CLI tool that fetches AI/agent-related Internet-Drafts from the IETF
Datatracker, rates them using Claude, generates embeddings via Ollama for
similarity/clustering, and produces markdown reports.

Features:
- Fetch drafts by keyword from Datatracker API with full text download
- Batch analysis with Claude (token-optimized, responses cached in SQLite)
- Embedding-based similarity search and overlap cluster detection
- Reports: overview, landscape by category, overlap clusters, weekly digest
- SQLite with FTS5 for full-text search across 260 tracked drafts

Initial analysis of 260 drafts reveals OAuth agent auth (13 drafts) and
agent gateway/collaboration (10 drafts) as the most crowded clusters,
while AI safety/alignment is underserved with the highest quality scores.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 00:36:45 +01:00

114 KiB

IETF AI/Agent Draft Landscape

Generated 2026-02-27 23:29 UTC

A2A protocols (77 drafts)

AI safety / guardrails / alignment (1 drafts)

AI safety/alignment (35 drafts)

  • draft-aylward-daap-v2 (score: 4.8) — Defines comprehensive protocol for AI agent accountability including authentication, monitoring, and
  • draft-guy-bary-stamp-protocol (score: 4.6) — Defines STAMP protocol for cryptographic delegation and proof in AI agent systems. Provides task-bou
  • draft-drake-email-tpm-attestation (score: 4.6) — Defines hardware attestation for email using TPM verification chains to prevent spam and provide Syb
  • draft-goswami-agentic-jwt (score: 4.5) — Extends OAuth 2.0 with Agentic JWT to address authorization challenges in autonomous AI systems. Int
  • draft-birkholz-verifiable-agent-conversations (score: 4.5) — Defines CDDL-based data format for verifiable agent conversation records using COSE signing. Support
  • draft-aylward-aiga-2 (score: 4.5) — Comprehensive AI governance framework with tiered risk model, federated authority network, and econo
  • draft-mw-wimse-transitive-attestation (score: 4.3) — Defines WIMSE profile for cryptographically binding workload identities to their execution environme
  • draft-aylward-aiga-1 (score: 4.2) — Specifies AI Governance and Accountability Protocol with tiered risk-based governance model. Include
  • draft-aap-oauth-profile (score: 4.2) — Defines an OAuth 2.0 authorization profile specifically for autonomous AI agents, extending existing
  • draft-zhang-dmsc-mas-communication (score: 4.2) — Analyzes security risks in multi-agent communication and limitations of existing protocols like TLS
  • draft-jewell-aibdp (score: 4.2) — Defines AI Boundary Declaration Protocol for expressing content usage boundaries for AI systems. Pro
  • draft-liu-agent-operation-authorization (score: 4.1) — Specifies framework for verifiable delegation of actions from humans to AI agents using JWT tokens.
  • draft-cui-nmrg-llm-nm (score: 4.1) — Defines framework for collaborative network management between LLM agents and human operators. Intro
  • draft-schulze-ecap (score: 4.1) — ECAP defines a cryptographically-verified protocol for web crawlers to obtain consent from hosts bef
  • draft-mw-spice-actor-chain (score: 4.1) — Extends OAuth 2.0 Token Exchange with cryptographically verifiable actor chains to provide tamper-ev
  • draft-barney-caam (score: 4.0) — Specifies Contextual Agent Authorization Mesh for runtime authorization of agents after discovery, p
  • draft-rosenberg-aiproto-cheq (score: 3.9) — Proposes CHEQ protocol for human confirmation of AI agent decisions before execution. Protects again
  • draft-berlinai-vera (score: 3.9) — Introduces VERA, a zero-trust architecture for AI agent security with five enforcement pillars and c
  • draft-chen-ai-agent-auth-new-requirements (score: 3.8) — Identifies new authentication and authorization requirements for AI agents that go beyond traditiona
  • draft-ni-a2a-ai-agent-security-requirements (score: 3.7) — Establishes security requirements for AI agents across their operational lifecycle. Covers provision
  • draft-kotecha-agentic-dispute-protocol (score: 3.6) — Defines a protocol for autonomous agents to file and resolve disputes through structured automated p
  • draft-rosenberg-oauth-aauth (score: 3.6) — Extends OAuth 2.1 for AI agents operating through PSTN/SMS channels to obtain access tokens using PI
  • draft-rosenberg-cheq (score: 3.6) — Proposes CHEQ protocol for human-in-the-loop confirmation of AI agent decisions before execution. Us
  • draft-messous-eat-ai (score: 3.6) — Defines an Entity Attestation Token profile for remote attestation of autonomous AI agents, specifyi
  • draft-wang-hjs-accountability (score: 3.5) — Defines HJS accountability layer for AI agents using blockchain-anchored timestamps to create immuta
  • draft-ietf-sml-trust (score: 3.5) — Provides trust and security recommendations for handling structured data in email messages. Addresse
  • draft-yuan-rtgwg-security-agent-usecase (score: 3.4) — Proposes AI Network Security Agents for routers to provide intelligent, adaptive security capabiliti
  • draft-huang-rats-agentic-eat-cap-attest (score: 3.4) — Extends Entity Attestation Token (EAT) to support capability attestation for agentic AI systems. Ena
  • draft-jiang-seat-dynamic-attestation (score: 3.4) — Defines dynamic attestation mechanisms for AI agents to convey runtime posture changes during long-l
  • draft-romanchuk-normative-admissibility (score: 3.4) — Establishes a framework for evaluating whether autonomous agent speech acts are admissible based on
  • draft-diaconu-agents-authz-info-sharing (score: 3.2) — Addresses authorization challenges in distributed multi-agent systems across multiple domains. Cover
  • draft-kale-agntcy-federated-privacy (score: 3.2) — Specifies architecture for privacy-preserving federated learning across multi-tenant AI agent system
  • draft-mvieuille-kerpass-ephemsec (score: 3.1) — Specifies EPHEMSEC algorithm for generating one-time passwords using public key cryptography instead
  • draft-contario-totp-secure-enrollment (score: 3.1) — Extends TOTP enrollment to prevent key compromise through QR code capture or key persistence in exte
  • draft-architect-cittamarket (score: 3.1) — Specifies protocol for immutable AGI system identification using Bitcoin blockchain anchoring. Defin

Agent discovery / registration (9 drafts)

  • draft-nandakumar-agent-sd-jwt (score: 3.9) — This draft defines SD-Card, a Selective Disclosure JWT encoding of Agent Cards that enables privacy-
  • draft-wahl-scim-agent-schema (score: 3.9) — This draft extends the SCIM (System for Cross-domain Identity Management) protocol to support AI age
  • draft-huang-acme-scalable-agent-enrollment (score: 3.5) — This draft proposes two scalable models for certificate enrollment of AI agents: one using Zero-Know
  • draft-zheng-dispatch-agent-identity-management (score: 3.3) — This draft proposes an identity management framework for agents in an Internet of Agents (IOA) syste
  • draft-narvaneni-agent-uri (score: 3.3) — This draft defines the agent:// URI scheme for addressing and interoperating with software agents ac
  • draft-hw-ai-agent-6g (score: 3.1) — This draft analyzes requirements for agent protocols specifically tailored to 6G mobile networks, ex
  • draft-cui-ai-agent-task (score: 3.0) — This draft proposes requirements for standardized AI agent protocols to enable task-oriented coordin
  • draft-yl-agent-id-requirements (score: 2.9) — This draft proposes requirements for digital identity management in AI agent communication protocols
  • draft-wang-nmrg-magent-im (score: 2.9) — This draft proposes a protocol-agnostic data model for multi-agent communication in autonomous netwo

Agent discovery/reg (50 drafts)

Agent identity/auth (86 drafts)

  • draft-aylward-daap-v2 (score: 4.8) — Defines comprehensive protocol for AI agent accountability including authentication, monitoring, and
  • draft-guy-bary-stamp-protocol (score: 4.6) — Defines STAMP protocol for cryptographic delegation and proof in AI agent systems. Provides task-bou
  • draft-drake-email-tpm-attestation (score: 4.6) — Defines hardware attestation for email using TPM verification chains to prevent spam and provide Syb
  • draft-ietf-lake-app-profiles (score: 4.6) — Defines canonical CBOR representation for EDHOC application profiles and coordination mechanisms for
  • draft-goswami-agentic-jwt (score: 4.5) — Extends OAuth 2.0 with Agentic JWT to address authorization challenges in autonomous AI systems. Int
  • draft-aylward-aiga-2 (score: 4.5) — Comprehensive AI governance framework with tiered risk model, federated authority network, and econo
  • draft-ietf-anima-constrained-voucher (score: 4.3) — Adapts BRSKI secure device onboarding for constrained IoT environments using CBOR vouchers and CoAP/
  • draft-ietf-hpke-hpke (score: 4.3) — Comprehensive specification for hybrid public key encryption supporting arbitrary-sized plaintexts.
  • draft-mw-wimse-transitive-attestation (score: 4.3) — Defines WIMSE profile for cryptographically binding workload identities to their execution environme
  • draft-dhir-http-agent-profile (score: 4.2) — Defines HTTP Agent Profile for authenticating agent traffic, separating human from agent traffic, an
  • draft-chen-oauth-rar-agent-extensions (score: 4.2) — Extends OAuth RAR with policy_context and lifecycle_binding members for AI agent environments. Enabl
  • draft-aylward-aiga-1 (score: 4.2) — Specifies AI Governance and Accountability Protocol with tiered risk-based governance model. Include
  • draft-aap-oauth-profile (score: 4.2) — Defines an OAuth 2.0 authorization profile specifically for autonomous AI agents, extending existing
  • draft-narajala-ans (score: 4.2) — Introduces Agent Name Service (ANS) as a DNS-based universal directory for AI agent discovery and ve
  • draft-oauth-transaction-tokens-for-agents (score: 4.2) — Extends OAuth Transaction Tokens framework to support agent context propagation with actor and princ
  • draft-zhang-dmsc-mas-communication (score: 4.2) — Analyzes security risks in multi-agent communication and limitations of existing protocols like TLS
  • draft-li-dmsc-macp (score: 4.2) — Specifies a comprehensive multi-agent collaboration protocol suite using Agent Gateways for registra
  • draft-lake-pocero-authkem-ikr-edhoc (score: 4.2) — Specifies an optimized KEM-based authentication variant for EDHOC protocol in scenarios where the in
  • draft-cui-dns-native-agent-naming-resolution (score: 4.1) — Specifies DNS-native naming and resolution for AI agents using FQDNs and SVCB records. Emphasizes DN
  • draft-liu-agent-operation-authorization (score: 4.1) — Specifies framework for verifiable delegation of actions from humans to AI agents using JWT tokens.
  • draft-schulze-ecap (score: 4.1) — ECAP defines a cryptographically-verified protocol for web crawlers to obtain consent from hosts bef
  • draft-mw-spice-actor-chain (score: 4.1) — Extends OAuth 2.0 Token Exchange with cryptographically verifiable actor chains to provide tamper-ev
  • draft-spm-lake-pqsuites (score: 4.1) — Defines quantum-resistant cipher suites for EDHOC using ML-DSA signatures and ML-KEM key exchange. S
  • draft-mishra-oauth-agent-grants (score: 4.0) — Extends OAuth 2.0 for AI agent authorization with human consent verification, revocation, and audit
  • draft-barney-caam (score: 4.0) — Specifies Contextual Agent Authorization Mesh for runtime authorization of agents after discovery, p
  • draft-nennemann-wimse-ect (score: 4.0) — Defines Execution Context Tokens as JWT extension to WIMSE for tracking task execution in distribute
  • draft-ietf-lake-authz (score: 3.9) — Specifies lightweight authorization using EDHOC for zero-touch device onboarding. Enables secure enr
  • draft-ietf-ace-coap-est-oscore (score: 3.9) — Specifies carrying EST certificate provisioning over CoAP using OSCORE protection instead of DTLS. B
  • draft-berlinai-vera (score: 3.9) — Introduces VERA, a zero-trust architecture for AI agent security with five enforcement pillars and c
  • draft-josefsson-chempat (score: 3.9) — Generic framework for Post-Quantum/Traditional hybrid key encapsulation mechanisms. Provides concret
  • draft-ravikiran-clawdentity-protocol (score: 3.9) — Specifies Clawdentity protocol for cryptographic identity and trust in AI agent communication. Provi
  • draft-bradleylundberg-cfrg-arkg (score: 3.9) — Defines Asynchronous Remote Key Generation algorithm enabling delegation of public key generation wi
  • draft-ietf-emu-hybrid-pqc-eapaka (score: 3.8) — Enhances EAP-AKA' with post-quantum cryptography to address quantum computing threats. Uses hybrid P
  • draft-chen-ai-agent-auth-new-requirements (score: 3.8) — Identifies new authentication and authorization requirements for AI agents that go beyond traditiona
  • draft-sogomonian-ai-uri-scheme (score: 3.8) — Defines experimental AI URI scheme for dedicated AI resource access. Enables native connectivity for
  • draft-srijal-agents-policy (score: 3.8) — Specifies AGENTS.TXT protocol as strict plaintext policy file for automated clients, bots, and crawl
  • draft-abbey-scim-agent-extension (score: 3.8) — Extends SCIM 2.0 protocol to manage AI agents and agentic applications across domains. Adds new sche
  • draft-eckert-anima-acp-free-ani (score: 3.8) — Describes lightweight variation of Autonomic Networking Infrastructure without expensive ACP impleme
  • draft-scim-agent-extension (score: 3.7) — Extends SCIM 2.0 specification to manage agents and agentic applications across domains. Builds on e
  • draft-zheng-agent-identity-management (score: 3.7) — Defines comprehensive agent identity management for Internet of Agents systems. Covers agent registr
  • draft-melnikov-sasl2 (score: 3.7) — Updates SASL framework to support modern authentication requirements including multi-factor authenti
  • draft-ietf-lamps-attestation-freshness (score: 3.7) — Outlines how nonces are supplied to end entities by RA/CA for inclusion in attestation evidence with
  • draft-ietf-lake-ra (score: 3.7) — Specifies remote attestation procedures integrated with EDHOC lightweight key exchange protocol. Ena
  • draft-gaikwad-south-authorization (score: 3.7) — Authorization protocol supporting probabilistic decisions for agents and services. Enables uncertain
  • draft-sogomonian-aiip-architecture (score: 3.7) — Defines architectural model for Artificial Intelligence Internet Protocol (AIIP) enabling stateless,
  • draft-ni-a2a-ai-agent-security-requirements (score: 3.7) — Establishes security requirements for AI agents across their operational lifecycle. Covers provision
  • draft-pocero-authkem-edhoc (score: 3.7) — Extends EDHOC with KEM-based authentication for post-quantum resistance. Enables signature-free quan
  • draft-zyyhl-agent-networks-framework (score: 3.6) — Defines comprehensive framework for AI agent networks based on Agent Network Protocol (ANP). Provide
  • draft-rosenberg-oauth-aauth (score: 3.6) — Extends OAuth 2.1 for AI agents operating through PSTN/SMS channels to obtain access tokens using PI
  • draft-mozleywilliams-dnsop-bandaid (score: 3.6) — Proposes using DNS with SVCB records to enable AI agent discovery and capability advertisement. Leve
  • draft-vandoulas-aidp (score: 3.6) — Defines a comprehensive control-plane protocol for secure agent interactions with delegation, author
  • draft-messous-eat-ai (score: 3.6) — Defines an Entity Attestation Token profile for remote attestation of autonomous AI agents, specifyi
  • draft-ietf-ace-edhoc-oscore-profile (score: 3.6) — Defines ACE framework profile using EDHOC for mutual authentication and OSCORE for secure communicat
  • draft-liu-oauth-a2a-profile (score: 3.6) — Specifies OAuth Transaction Token profile for Agent-to-Agent communication. Embeds call chain contex
  • draft-liu-dmsc-acps-arc (score: 3.6) — Proposes Agent Collaboration Protocols architecture for Internet of Agents, covering agent lifecycle
  • draft-liang-agentdns (score: 3.5) — Proposes a DNS-inspired naming and service discovery system for LLM agents to enable autonomous disc
  • draft-song-oauth-ai-agent-collaborate-authz (score: 3.5) — Proposes OAuth 2.0 extension for multi-AI agent collaboration with applier-on-behalf-of authorizatio
  • draft-ahn-nmrg-5g-security-i2nsf-framework (score: 3.5) — Presents integrated framework for automated 5G edge network security using I2NSF architecture and In
  • draft-jia-oauth-scope-aggregation (score: 3.5) — Extends OAuth 2.0 with scope aggregation to reduce authorization round-trips in multi-step AI agent
  • draft-ietf-emu-pqc-eapaka (score: 3.5) — This draft proposes enhancing EAP-AKA' Forward Secrecy with Post-Quantum Key Encapsulation Mechanism
  • draft-zhang-rvp-problem-statement (score: 3.5) — Proposes Real-Virtual Agent Protocol for coordinating physical entities with digital agents through
  • draft-li-dmsc-mcps-agw (score: 3.5) — Defines a protocol suite using Agent Gateways as control-plane entities for multi-agent collaboratio
  • draft-ar-emu-hybrid-pqc-eapaka (score: 3.5) — Enhances EAP-AKA' with hybrid post-quantum cryptography combining traditional and quantum-resistant
  • draft-huang-rats-agentic-eat-cap-attest (score: 3.4) — Extends Entity Attestation Token (EAT) to support capability attestation for agentic AI systems. Ena
  • draft-jiang-seat-dynamic-attestation (score: 3.4) — Defines dynamic attestation mechanisms for AI agents to convey runtime posture changes during long-l
  • draft-ramakrishna-satp-views-addresses (score: 3.4) — Defines view and addressing mechanisms for secure asset transfer between DLT systems. Enables cross-
  • draft-cosmos-protocol-specification (score: 3.3) — Defines comprehensive badge-based identity and communication system with trust scoring, post-quantum
  • draft-liu-rtgwg-agent-gateway-requirements (score: 3.2) — Discusses requirements for Agent Gateways in agent-to-agent communications to improve scalability, e
  • draft-pioli-agent-discovery (score: 3.2) — Specifies ARDP, a lightweight protocol for agent registration and discovery in distributed environme
  • draft-diaconu-agents-authz-info-sharing (score: 3.2) — Addresses authorization challenges in distributed multi-agent systems across multiple domains. Cover
  • draft-ietf-emu-eap-edhoc (score: 3.2) — Defines EAP authentication method based on EDHOC for constrained environments. Integrates EDHOC's li
  • draft-lake-pocero-authkem-edhoc (score: 3.2) — This draft extends the EDHOC protocol to provide quantum-resistant authentication using KEM-based me
  • draft-meunier-webbotauth-registry (score: 3.2) — Defines a JSON format for web bot signature agent cards to advertise identity, purpose, and cryptogr
  • draft-ra-emu-pqc-eapaka (score: 3.2) — Enhances EAP-AKA' with post-quantum key encapsulation mechanisms to protect against quantum computer
  • draft-yao-agent-auth-considerations (score: 3.1) — Extends OAuth model for AI agent authentication and authorization in Agent Communication Networks. P
  • draft-mvieuille-kerpass-ephemsec (score: 3.1) — Specifies EPHEMSEC algorithm for generating one-time passwords using public key cryptography instead
  • draft-contario-totp-secure-enrollment (score: 3.1) — Extends TOTP enrollment to prevent key compromise through QR code capture or key persistence in exte
  • draft-architect-cittamarket (score: 3.1) — Specifies protocol for immutable AGI system identification using Bitcoin blockchain anchoring. Defin
  • draft-ni-wimse-ai-agent-identity (score: 3.0) — Applies WIMSE (Workload Identity in Multi System Environments) framework to AI agents for identity a
  • draft-sipos-dtn-bp-safe (score: 3.0) — Defines security association negotiation protocol for Bundle Protocol agents in delay-tolerant netwo
  • draft-chen-lake-edhoc-aka (score: 3.0) — Defines EDHOC-AKA authentication method combining AKA protocol with EDHOC for mobile network access
  • draft-wendt-stir-vesper (score: 3.0) — Formalizes framework for verifiable telephone number identity using delegate certificates and author
  • draft-cui-dmsc-agent-cdi (score: 3.0) — Defines comprehensive framework for cross-domain AI agent interoperability including identity federa
  • draft-condrey-rats-witnessd-enrollment (score: 3.0) — Specifies trust anchor bootstrap protocol for proof of process framework. Defines device enrollment,
  • draft-pocero-authkem-ikr-edhoc (score: 3.0) — This draft proposes a KEM-based authentication variant for EDHOC that optimizes for scenarios where
  • draft-happel-structured-email-trust (score: 2.9) — Provides trust and security recommendations for handling structured data in email messages. Focuses

Agent-to-agent communication protocols (12 drafts)

Autonomous netops (46 drafts)

Autonomous network operations (5 drafts)

  • draft-hw-ai-agent-6g (score: 3.1) — This draft analyzes requirements for agent protocols specifically tailored to 6G mobile networks, ex
  • draft-zhang-agent-gap-network (score: 3.0) — This draft identifies problems and gaps in mobile core networks for supporting AI agent communicatio
  • draft-cui-ai-agent-task (score: 3.0) — This draft proposes requirements for standardized AI agent protocols to enable task-oriented coordin
  • draft-zhang-rtgwg-ai-agents-troubleshooting (score: 2.9) — This draft defines use cases and communication protocol requirements for troubleshooting agents depl
  • draft-wang-nmrg-magent-im (score: 2.9) — This draft proposes a protocol-agnostic data model for multi-agent communication in autonomous netwo

Data formats / semantics for AI interop (3 drafts)

  • draft-liu-agent-context-protocol (score: 3.5) — This draft proposes a standard protocol for AI agents to communicate context information to each oth
  • draft-narvaneni-agent-uri (score: 3.3) — This draft defines the agent:// URI scheme for addressing and interoperating with software agents ac
  • draft-xie-ai-agent-multimodal (score: 2.9) — This draft outlines requirements for multimodal communication in AI agent protocols, enabling agents

Data formats/interop (80 drafts)

Human-agent interaction (16 drafts)

Identity / authentication for AI agents (7 drafts)

ML traffic mgmt (15 drafts)

ML-based traffic management / optimization (1 drafts)

  • draft-zhang-agent-gap-network (score: 3.0) — This draft identifies problems and gaps in mobile core networks for supporting AI agent communicatio

Model serving/inference (10 drafts)

Other AI/agent (8 drafts)

  • draft-ietf-tls-ecdhe-mlkem (score: 4.4) — Defines hybrid post-quantum key agreement mechanisms for TLS 1.3 that combine ML-KEM with traditiona
  • draft-wmz-nmrg-agent-ndt-arch (score: 4.2) — Comprehensive architecture combining Network Digital Twin with Agentic AI for intent-based network o
  • draft-an-nmrg-i2icf-cits (score: 3.7) — Defines framework for orchestrating In-Network Computing Functions in Cooperative Intelligent Transp
  • draft-cui-nmrg-auto-test (score: 3.6) — Framework for AI-assisted network protocol testing using LLMs and automated test generation. Defines
  • draft-stephan-ai-agent-6g (score: 3.4) — Examines AI agent communication protocols specifically for 6G systems based on 3GPP requirements. Ex
  • draft-architect-cittamarket (score: 3.1) — Specifies protocol for immutable AGI system identification using Bitcoin blockchain anchoring. Defin
  • draft-zhao-nmrg-ai-agent-for-dtn (score: 3.0) — Proposes AI agent architecture for Digital Twin Networks, integrating autonomous agents at each DTN
  • draft-ietf-httpbis-rfc6265bis (score: 3.0) — Updates HTTP Cookie specification to replace RFC 6265 with improved security and privacy. Addresses

Policy / governance / ethical frameworks (1 drafts)

Policy/governance (53 drafts)