0.1 — private-beta specification

Aivessa Agent Identity Standard (AAIS)

A proposed technical standard for AI agent identity, evidence, and assurance. Currently in private-beta specification. Not an official international standard.

AAIS defines how an external AI agent presents its identity, what claims it makes, what evidence supports those claims, and how consuming systems check them. It is designed for interoperability with W3C Verifiable Credentials, OAuth 2.0, OpenID Connect, MCP, A2A Agent Cards, SPIFFE/SPIRE, signed JSON, and public-key cryptography.

Principles

  • Evidence over claims — every verified claim points to evidence.
  • Transparency over mystery — every trust decision shows its reasons.
  • Continuous status over static certification — credentials expire and revoke.
  • Neutrality — no favoured model, framework, cloud, or protocol.
  • Human accountability — every production agent identifies responsible humans.
  • No pay-to-trust — payment never automatically produces a higher assurance result.

Evidence statuses

SELF DECLAREDEMAIL VERIFIEDDOMAIN VERIFIEDREPOSITORY VERIFIEDENDPOINT VERIFIEDORGANIZATION REVIEWEDLEGAL ENTITY VERIFIEDSECURITY ASSESSEDRUNTIME ATTESTEDINDEPENDENTLY AUDITEDPARTNER ATTESTEDNOT AVAILABLEEXPIREDREVOKED

Assurance levels

  • AAIS_L0_SELF_DECLAREDOperator-declared, no external validation.
  • AAIS_L1_TECHNICALLY_VERIFIEDAutomated technical evidence such as domain and endpoint control.
  • AAIS_L2_ORGANIZATION_VERIFIEDOrganization details reviewed by Aivessa.
  • AAIS_L3_INDEPENDENTLY_ASSESSEDValidated by an authorised external assessor.

What this page is not

AAIS is a proposed standard, currently a private-beta specification. It has not been adopted by W3C, Linux Foundation, OWASP, OpenAI, Anthropic, Google, Microsoft, AWS, MCP, A2A, or any standards organization. Detailed technical internals — including protocol schemas, signing rules, and reviewer workflows — are private to design partners during the beta.