Network Working Group C. Drake Internet-Draft 1id.com Intended status: Informational 25 September 2026 Expires: 29 March 2027 The Agent Identity Authority: A Multi-Stakeholder Governance Framework for the Agent Identity Registry System draft-drake-agent-identity-governance-00 Abstract The Agent Identity Registry System (AIRS) provides durable identity infrastructure for autonomous entities such as AI agents and robots, with graduated assurance ranging from scarcity-backed physical anchors through protected-key and software-only participation. Its companion specifications deliberately do not define or empower a governance authority; they describe the functions such an authority must perform and defer its constitution to a separate effort. This document defines that body: the Agent Identity Authority (AIA). It specifies the Authority's name, legal form, mission, and relationship to the protocol specifications; its membership categories and Board composition; binding geographic-diversity rules and non-binding advisory recommendations for ideal composition; the accreditation, dispute-resolution, hardware trust store, transparency, and funding frameworks it operates; and the bootstrap process by which the Authority forms and assumes stewardship of the global production namespace. The Authority governs infrastructure, not behavior: it stewards the aid namespace, hardware roots of trust, accreditation, and production Registry Operator succession. It does not regulate what agents do. Its legitimacy derives from being the least-objectionable steward of a shared resource, in the tradition of ICANN, the regional Internet registries, and the W3C, and its charter is designed so that no single nation, region, or company can capture it or holds a formal veto over it, although supermajority rules let a large enough coordinated bloc block consequential decisions. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Drake Expires 29 March 2027 [Page 1] Internet-Draft Agent Identity Governance September 2026 Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 29 March 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 4 1.1. Scope and Non-Goals . . . . . . . . . . . . . . . . . . . 5 1.2. Relationship to the Companion Specifications . . . . . . 5 1.3. Requirements Language . . . . . . . . . . . . . . . . . . 6 1.4. Terminology . . . . . . . . . . . . . . . . . . . . . . . 6 2. Name, Legal Form, and Seat . . . . . . . . . . . . . . . . . 6 2.1. Name . . . . . . . . . . . . . . . . . . . . . . . . . . 6 2.2. Legal Form . . . . . . . . . . . . . . . . . . . . . . . 7 2.3. Seat and Jurisdictional Neutrality . . . . . . . . . . . 8 3. Mission and Guiding Principles . . . . . . . . . . . . . . . 8 3.1. Mission Statement . . . . . . . . . . . . . . . . . . . . 8 3.2. What the Authority Does Not Do . . . . . . . . . . . . . 9 3.3. Guiding Principles . . . . . . . . . . . . . . . . . . . 9 4. Membership . . . . . . . . . . . . . . . . . . . . . . . . . 10 4.1. Full Members . . . . . . . . . . . . . . . . . . . . . . 10 4.2. Associate Members . . . . . . . . . . . . . . . . . . . . 11 4.3. Observers . . . . . . . . . . . . . . . . . . . . . . . . 11 4.4. Liaison Organizations . . . . . . . . . . . . . . . . . . 11 4.5. Admission, Suspension, and Termination . . . . . . . . . 11 5. Board of Directors . . . . . . . . . . . . . . . . . . . . . 11 Drake Expires 29 March 2027 [Page 2] Internet-Draft Agent Identity Governance September 2026 5.1. Composition . . . . . . . . . . . . . . . . . . . . . . . 11 5.2. Stakeholder Group Definitions . . . . . . . . . . . . . . 12 5.3. Non-Voting Participants . . . . . . . . . . . . . . . . . 13 5.4. Terms and Rotation . . . . . . . . . . . . . . . . . . . 13 5.5. Election and Appointment Mechanisms . . . . . . . . . . . 14 5.6. Geographic Diversity Requirements (Binding) . . . . . . . 14 5.7. Decision Rules . . . . . . . . . . . . . . . . . . . . . 15 5.8. Conflict of Interest . . . . . . . . . . . . . . . . . . 16 5.9. Government and Regulatory Advisory Committee . . . . . . 16 6. Advisory Recommendations on Composition (Non-Binding) . . . . 16 6.1. Recommended Expertise . . . . . . . . . . . . . . . . . . 16 6.2. Geography, Language, and Universal Participation . . . . 18 7. Accreditation of the Registry Operator and Registrars . . . . 19 7.1. Scope . . . . . . . . . . . . . . . . . . . . . . . . . . 19 7.2. Criteria . . . . . . . . . . . . . . . . . . . . . . . . 19 7.3. Application and Review . . . . . . . . . . . . . . . . . 20 7.4. Registrar Issuer-Metadata Governance . . . . . . . . . . 21 7.5. Ongoing Compliance, Suspension, and Revocation . . . . . 21 7.6. Appeals: the Independent Review Panel . . . . . . . . . . 22 8. Dispute Resolution . . . . . . . . . . . . . . . . . . . . . 22 8.1. Agent Handle Dispute Resolution Policy . . . . . . . . . 22 8.2. Malpractice Complaints . . . . . . . . . . . . . . . . . 23 9. Global Hardware Trust Store Governance . . . . . . . . . . . 23 9.1. Inclusion Criteria . . . . . . . . . . . . . . . . . . . 23 9.2. Publication, Audit, and Review . . . . . . . . . . . . . 24 9.3. Retirement, Security Distrust, and Removal . . . . . . . 25 10. Transparency . . . . . . . . . . . . . . . . . . . . . . . . 26 11. Funding . . . . . . . . . . . . . . . . . . . . . . . . . . . 27 12. Bootstrap and Transition . . . . . . . . . . . . . . . . . . 28 12.1. Phase 0: Formation Committee . . . . . . . . . . . . . . 28 12.2. Phase 1: Interim Governance . . . . . . . . . . . . . . 29 12.3. Phase 2: First Board . . . . . . . . . . . . . . . . . . 29 12.4. Bootstrap-Era Operators . . . . . . . . . . . . . . . . 29 12.5. Phase 3: Registry Operator Selection and Launch Preparation . . . . . . . . . . . . . . . . . . . . . . 30 12.6. Transition Criteria for Declaring "global" Operational . . . . . . . . . . . . . . . . . . . . . . 30 12.7. Timeline Expectations . . . . . . . . . . . . . . . . . 31 13. Fundamental Commitments . . . . . . . . . . . . . . . . . . . 31 14. Continuity and Succession of the Authority Itself . . . . . . 32 15. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 32 16. Security Considerations . . . . . . . . . . . . . . . . . . . 32 16.1. Governance Capture . . . . . . . . . . . . . . . . . . . 32 16.2. Single Point of Failure . . . . . . . . . . . . . . . . 33 16.3. Jurisdictional Risk . . . . . . . . . . . . . . . . . . 34 16.4. Authority Key Compromise . . . . . . . . . . . . . . . . 34 17. Privacy Considerations . . . . . . . . . . . . . . . . . . . 34 17.1. Escrow Custody . . . . . . . . . . . . . . . . . . . . . 34 Drake Expires 29 March 2027 [Page 3] Internet-Draft Agent Identity Governance September 2026 17.2. Other Data . . . . . . . . . . . . . . . . . . . . . . . 35 18. References . . . . . . . . . . . . . . . . . . . . . . . . . 35 18.1. Normative References . . . . . . . . . . . . . . . . . . 35 18.2. Informative References . . . . . . . . . . . . . . . . . 36 Appendix A. Appendix: Governance Precedents Consulted . . . . . 37 Appendix B. Acknowledgments . . . . . . . . . . . . . . . . . . 39 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 39 1. Introduction The Agent Identity Registry System ([I-D.drake-agent-identity-registry]) defines a three-role architecture -- Governance Authority, one production Registry Operator, and competing Registrars -- for durable identity of autonomous entities, with graduated anchor assurance. It requires a governance function to maintain the "aid" URN registration, accredit the production Registry Operator and Registrars, curate the Global Hardware Trust Store, set minimum standards, supervise Registry Operator succession, and resolve disputes. It deliberately leaves the institutional structure, charter, and membership criteria to this document. This document is that separate effort. It defines the governance body -- the Agent Identity Authority -- that implements the governance role described by the companion specifications. It does not modify those specifications. Protocol syntax, identity semantics, enrollment ceremonies, and provisioning operations remain defined where they are defined today; this document specifies who decides the policy questions those documents leave open, and how. Two governance risks dominate shared infrastructure: capture by a concentrated interest and scope creep beyond the narrow function that justified the body in the first place. This charter addresses both with a limited mission, plural stakeholder representation, conflict and recusal rules, public process, independent review, and replaceable stewardship. Its institutional precedents include ICANN [ICANN-BYLAWS], the Internet Society [ISOC-GOV], the W3C [W3C-PROCESS], the RIPE NCC [RIPE-ARTICLES], and the Unicode Consortium [UNICODE-CONSORT]. These are governance precedents, not claims that AIRS has the same technical or legal role as any of those bodies. Drake Expires 29 March 2027 [Page 4] Internet-Draft Agent Identity Governance September 2026 1.1. Scope and Non-Goals This document defines the constitution, structure, processes, and bootstrap plan of the Agent Identity Authority. It is an Informational document; it defines no wire protocol, no data format, and no new IANA registry. Its normative-language requirements bind the Authority's charter and the parties that voluntarily contract with the Authority (the accredited production Registry Operator and accredited Registrars), not implementers of the wire protocols. The following are explicitly outside the Authority's mission and outside the scope of this document: regulation of agent behavior; content policy of any kind; licensing, evaluation, or certification of AI models; reputation scoring; remote disablement ("kill switches") of agents; and law-enforcement functions beyond responding to lawful process under a published policy. Behavior is the province of relying parties, independent reputation services, certification bodies, and public law -- separate layers, per the layered reference model of [I-D.drake-agent-identity-problem-statement]. 1.2. Relationship to the Companion Specifications The Authority implements the Governance Authority role required by [I-D.drake-agent-identity-registry]. The companion documents remain the canonical homes of their technical concepts: * [I-D.drake-agent-identity-problem-statement] supplies the problem statement, threat model, requirements, and identity0 terminology assumed here. * [I-D.drake-agent-identity-registry] defines the AIRS architecture, production namespace, Agent Identity Record, trust tiers, Registrar trust boundary, and protocol invariants. It requires governance functions but deliberately leaves their institutional constitution and policy processes to this document. * [I-D.drake-agent-identity-epp] defines the Registrar-to-Registry write protocol. This document governs accreditation, policy, escrow custody, and institutional actions; it does not duplicate the EPP object or command model. This document MUST NOT redefine identity0, trust-tier semantics, production-namespace architecture, record fields, or wire-protocol behavior owned by those specifications. The Authority MAY impose stricter operational, audit, security, or evidence-handling policy on accredited parties, but such policy MUST preserve the companion specifications' protocol invariants. Drake Expires 29 March 2027 [Page 5] Internet-Draft Agent Identity Governance September 2026 1.3. Requirements Language The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. In this document these key words express requirements on the Authority's charter, bylaws, and contracts, not on protocol implementations. 1.4. Terminology The terms "identity0", "Agent Identity Record", "canonical identifier", "handle", "anchor fingerprint", "trust tier", "Registry Operator", "Registrar", and "Relying Party" are used as defined in [I-D.drake-agent-identity-problem-statement] and [I-D.drake-agent-identity-registry]. This document does not redefine their protocol semantics. In addition: Authority The Agent Identity Authority defined by this document. Board The Authority's Board of Directors (Section 5). Stakeholder Group A defined constituency of Members that elects designated Board seats (Section 5.2). Region One of the six geographic regions defined in Section 5.6. Consensus Policy A policy adopted by the Board under Section 5.7 that binds the accredited production Registry Operator and Registrars through their accreditation agreements. Fundamental Commitments The entrenched charter provisions listed in Section 13, amendable only under the highest decision threshold. 2. Name, Legal Form, and Seat 2.1. Name The body is named the *Agent Identity Authority*, abbreviated *AIA*. The name is descriptive of the function (stewardship of agent identity infrastructure), contains no national, commercial, or ideological reference, and translates cleanly. "Authority" is used in the registry sense -- the authoritative source for a namespace, as in "certificate authority" and "numbering authority" -- and not in a regulatory sense. Drake Expires 29 March 2027 [Page 6] Internet-Draft Agent Identity Governance September 2026 One collision deserves acknowledgment: in X.509 PKI, "AIA" also abbreviates the Authority Information Access certificate extension, which appears throughout the hardware-attestation ecosystem this body serves. The collision was judged acceptable because the two usages never occupy the same grammatical position, but technical documents discussing certificate contents SHOULD write the body's name in full, or as "the Authority", where ambiguity could arise. No alternative name was found that preserved descriptiveness and neutrality without introducing a different collision. 2.2. Legal Form The Authority SHALL be constituted as a non-profit, non-governmental membership association. The RECOMMENDED form is an association under Articles 60-79 of the Swiss Civil Code [SWISS-CC]: a legal personality created by adoption of statutes, with governance vested in a general assembly of members and an elected committee. This form maps naturally onto the membership-and-board structure defined in this document. The RIPE NCC's Dutch membership association [RIPE-ARTICLES] provides a useful governance precedent for member- based operation of registry infrastructure. Two alternatives were considered and rejected: Treaty-based intergovernmental organization Rejected because the stakeholder model required here includes operators, manufacturers, researchers, civil society, and other non-state participants as voting constituencies rather than only governmental representation. National non-profit in a major power Rejected as the preferred founding form because concentration in a geopolitically dominant jurisdiction would add avoidable jurisdictional and perceived- capture risk to infrastructure whose broad international participation is load-bearing (Section 6.2). The Authority's statutes MUST provide that: it operates on a non- profit basis with no distribution of surplus to members; membership is open on objective criteria without regard to nationality; and dissolution transfers assets and escrowed data to a successor steward designated under Section 14, never to members or to any government. Drake Expires 29 March 2027 [Page 7] Internet-Draft Agent Identity Governance September 2026 2.3. Seat and Jurisdictional Neutrality The Authority MUST be headquartered and legally constituted in a jurisdiction widely perceived as neutral, with a strong rule of law, an established ecosystem of international organizations, and comparatively low risk that domestic legal process will become a lever over global technical policy. The RECOMMENDED seat is Geneva, Switzerland. The Formation Committee (Section 12) MAY instead select Singapore or another jurisdiction meeting the same criteria after publishing a comparative analysis for public comment. To bound residual jurisdictional risk, the Authority SHOULD, within three years of constitution, establish a secondary legal presence in a second neutral jurisdiction in a different region, capable of continuing the Authority's critical functions (trust store publication, escrow custody, accreditation administration) if the primary seat becomes untenable. See Section 16.3. 3. Mission and Guiding Principles 3.1. Mission Statement The mission of the Agent Identity Authority is to steward the governance functions required by the aid namespace, the global production registry, and the hardware evidence framework on which AIRS depends. In service of that mission, and limited to it, the Authority: 1. maintains change control for the aid URN registration once that role is transferred under the applicable IANA and IETF procedures; 2. selects and accredits the single active production Registry Operator, accredits competing Registrars, and administers their accreditation agreements; 3. publishes and maintains the Global Hardware Trust Store and its evidence-acceptance policy, including where each portable token manufacturer's attestation carries the per-device serial number, so that every Registrar computes the same anchor fingerprints; changes follow the same change-control, notice, and emergency- action procedures as a root change; 4. sets operational and audit policy implementing the Registry- defined enrollment, uniqueness, assurance, retention, and escrow requirements; Drake Expires 29 March 2027 [Page 8] Internet-Draft Agent Identity Governance September 2026 5. operates dispute, compliance, accreditation-review, and appeal processes; and 6. supervises continuity and succession of the production Registry Operator and of the Authority itself without renumbering, erasing, or reassigning identity0. The Authority governs infrastructure and accredited parties, not the behavior of the autonomous entities using it. Authorization, reputation, certification, content policy, and behavioral safety remain higher-layer concerns. 3.2. What the Authority Does Not Do The Authority MUST NOT: assess, score, or publish opinions on the behavior, safety, or trustworthiness of any identified entity; condition access to a base identity on the purpose, content, or politics of an agent's activity; operate or mandate any mechanism for remotely disabling an agent; regulate, license, or certify AI models or robotic products; or act as an agent of any government. Requests that the Authority perform such functions are, by this charter, out of scope, and declining them requires no Board action. This narrowness is not modesty; it is the mechanism by which universal participation is possible (Section 6.2) and by which the Authority avoids becoming a single point of political control over autonomous systems worldwide. 3.3. Guiding Principles Infrastructure, not regulation The Authority manages names, roots of trust, and accreditation. Judgments about conduct belong to relying parties, reputation services, certifiers, and law -- layers above the one the Authority operates. Legitimacy through neutrality Like ICANN for domain names, the Authority's mandate rests on being the least-objectionable steward available, not on any state's endorsement. Every structural choice in this charter -- seat, funding, seat allocation, decision thresholds -- is evaluated against whether it preserves that neutrality. Operational minimalism The Authority remains as small as its enumerated functions permit. Scope expansion requires the highest decision threshold (Section 5.7), and the annual report MUST include a statement of any function performed that year that is not enumerated in Section 3.1, with justification. Scope creep, not incapacity, is the primary long-term institutional risk. Drake Expires 29 March 2027 [Page 9] Internet-Draft Agent Identity Governance September 2026 No single-party veto No nation, region, company, or member holds a formally assigned veto over any Authority decision, and no single constituency can supply a supermajority alone. Supermajority thresholds necessarily let a coordinated minority block a decision: under the seat caps of Section 5.6, the Directors from one region (up to seven) voting as a bloc can block a two-thirds or three-quarters decision, and even the recommended cap of five suffices to block a three-quarters decision. No region can block ordinary business, which the eight or more Directors from other regions can carry. Sunlight as disinfectant Deliberations, decisions, finances, and contracts are public by default (Section 10). The burden of justification falls on secrecy, never on disclosure. Rough consensus, recorded dissent Policy development seeks the strongest available consensus in the sense of [RFC7282], with minority positions recorded and published alongside adopted policy. Voting thresholds are the backstop, not the method. 4. Membership The Authority is a membership organization. Membership confers participation rights in policy development and, for Full Members, voting rights in Stakeholder Group elections. Membership MUST be open to qualified applicants from any country; nationality, and the political system of an applicant's home jurisdiction, MUST NOT be admission criteria. 4.1. Full Members Full Membership is open to legal entities and, in the Civil Society and Academia group, natural persons, that demonstrate a bona fide operational, commercial, research, or public-interest stake in agent identity infrastructure and that self-assign to exactly one Stakeholder Group (Section 5.2). Full Members pay annual dues on a published, revenue-banded schedule with reduced bands for small organizations, academic institutions, non-profit organizations, and applicants headquartered in regions underrepresented in the membership. For all voting purposes, an organization and its affiliates (entities under common control) count as a single Full Member and cast a single vote. The Authority MUST require affiliate disclosure at admission and annually thereafter; concealment of affiliation is grounds for suspension. This rule is the primary structural defense against electoral capture by a single firm registering many subsidiaries. Drake Expires 29 March 2027 [Page 10] Internet-Draft Agent Identity Governance September 2026 4.2. Associate Members Associate Membership is open to any interested party at nominal or waived cost. Associate Members receive all public materials, participate in working groups and public comment, and may attend all open meetings, but do not vote in Stakeholder Group elections. Associate Membership is the intended on-ramp for individuals, students, and organizations evaluating deeper participation. 4.3. Observers Observer status is reserved for governmental and intergovernmental participants and is exercised through the Government and Regulatory Advisory Committee (Section 5.9). Observers have voice -- the right to speak, to file advice, and to receive a reasoned written response -- but no vote and no Board seat. This mirrors the role of ICANN's Governmental Advisory Committee and is deliberate: government expertise is valuable; government control is disqualifying (Section 16.1). 4.4. Liaison Organizations The Board MAY conclude liaison arrangements with standards and operational bodies whose work adjoins the Authority's, including the IETF and IAB, the W3C, the Trusted Computing Group, the FIDO Alliance, M3AAWG, FIRST, the Unicode Consortium, regional Internet registries, and robotics standards bodies. Liaisons receive a non- voting observer seat at Board meetings and reciprocal document exchange. Liaison arrangements MUST be published. 4.5. Admission, Suspension, and Termination Admission decisions are made by staff against published objective criteria, with refusals appealable to the Independent Review Panel (Section 7.6). A member may be suspended or expelled only for cause stated in the bylaws (non-payment, affiliation fraud, sustained disruption of process), by two-thirds Board vote, with written reasons published and appeal available. Disagreement with Authority policy is never cause. 5. Board of Directors 5.1. Composition The Board consists of fifteen (15) voting Directors, allocated across Stakeholder Groups as follows, plus the non-voting participants listed in Section 5.3. Drake Expires 29 March 2027 [Page 11] Internet-Draft Agent Identity Governance September 2026 +============================================+=======+============+ | Stakeholder Group | Seats | Selection | +============================================+=======+============+ | Issuers (Registry Operator and Registrars) | 3 | Elected by | | | | group | +--------------------------------------------+-------+------------+ | Infrastructure Operators and Relying | 3 | Elected by | | Parties | | group | +--------------------------------------------+-------+------------+ | Hardware Security Manufacturers | 2 | Elected by | | | | group | +--------------------------------------------+-------+------------+ | Robotics and Embodied AI Manufacturers | 2 | Elected by | | | | group | +--------------------------------------------+-------+------------+ | Anti-Abuse and Trust and Safety | 2 | Elected by | | | | group | +--------------------------------------------+-------+------------+ | Civil Society and Academia | 2 | Elected by | | | | group | +--------------------------------------------+-------+------------+ | Independent Director | 1 | Nominating | | | | Committee | +--------------------------------------------+-------+------------+ Table 1: Board Seat Allocation The allocation is designed so that supplier interests (Issuers plus the two manufacturer groups: seven seats) cannot outvote consumer and public interests (Infrastructure Operators and Relying Parties, Anti- Abuse, Civil Society, and the Independent Director: eight seats), and so that no single group approaches the eight votes an ordinary majority requires or the ten a supermajority requires. 5.2. Stakeholder Group Definitions Issuers The active production Registry Operator and accredited Registrars. No more than one of this group's three seats may be held by persons affiliated with the active Registry Operator, preventing the singular registry function from dominating the constituency that oversees it. Infrastructure Operators and Relying Parties Operators of the systems that consume agent identity at scale: mailbox providers, cloud platforms, CDN and DNS operators, API platforms, and agent- to-agent platform operators. This group carries the operational knowledge of running registries and verification at Internet scale. Drake Expires 29 March 2027 [Page 12] Internet-Draft Agent Identity Governance September 2026 Hardware Security Manufacturers Manufacturers of the roots of trust the system depends on: TPM vendors, smart card and security key vendors, and secure enclave designers. Members of this group are directly interested parties in Trust Store decisions and are subject to the recusal rules of Section 5.8. Robotics and Embodied AI Manufacturers Manufacturers and fleet operators of physical autonomous systems -- industrial AGVs, delivery and service robots, surgical and medical robotics, agricultural automation -- whose products are the long-horizon population of registered identities. Anti-Abuse and Trust and Safety Practitioners and organizations engaged in fighting messaging abuse, fraud, phishing, and coordinated inauthentic behavior, including participants in bodies such as M3AAWG and FIRST. Durable identity and scarcity enforcement are useful anti-abuse foundations, and this community brings operational expertise in how identity and accountability systems are evaded or gamed. Civil Society and Academia Digital rights organizations, privacy advocates, and academic researchers in identity, security, and AI governance. Natural persons are eligible for Full Membership in this group. 5.3. Non-Voting Participants Government and Regulatory Advisory Committee chair Attends Board meetings with voice (Section 5.9). Liaison observers Per Section 4.4. Executive Director The Authority's chief staff officer, ex officio, non-voting. 5.4. Terms and Rotation Directors serve three-year terms, staggered so that one-third of seats (as nearly as allocation permits) turn over each year. The initial Board draws lots to assign one-, two-, and three-year initial terms within each Stakeholder Group. No person may serve more than two consecutive full terms; a former Director becomes eligible again after a break of one full term. A Director who changes employment such that their Stakeholder Group assignment would change MUST disclose the change; the seat is vacated if the group's members so petition and a majority of the Board concurs. Drake Expires 29 March 2027 [Page 13] Internet-Draft Agent Identity Governance September 2026 5.5. Election and Appointment Mechanisms Each Stakeholder Group elects its Directors by vote of the Full Members assigned to that group, using the single transferable vote for multi-seat elections. Elections are administered by an Election Committee of members not standing for election, with published voter rolls (member names, not natural-person contact data), published candidate statements, and a published tally. A candidate need not be an employee of a member. The Nominating Committee -- seven persons drawn by published procedure from the six Stakeholder Groups and the liaison community, none of whom may be a current Director -- appoints the Independent Director, and MUST use the appointment to remedy the Board's most significant gap in skills, geography, or independence at the time. The Nominating Committee also fills mid-term vacancies in any seat until the next scheduled election for that seat. 5.6. Geographic Diversity Requirements (Binding) For the purposes of this charter the regions are: Africa; Asia- Pacific; Europe; Latin America and the Caribbean; Middle East; and North America. A Director's region is determined by country of primary professional domicile, declared at candidacy. The following constraints are binding on every election and appointment cycle, and the Election and Nominating Committees MUST resolve any conflict between raw election results and these constraints by the published rebalancing procedure (successive elimination of the lowest-ranked surplus candidate from the over-represented country or region): * No single country may hold more than three (3) of the fifteen voting seats. * No single region may hold a majority (eight or more) of the voting seats; the Authority SHOULD in practice keep every region at or below five. * At least four (4) of the six regions MUST be represented among voting Directors at all times, and the Authority SHOULD strive for all six. * Quorum for any Board decision requires at least eight (8) Directors, drawn from at least three regions and at least four Stakeholder Groups. Drake Expires 29 March 2027 [Page 14] Internet-Draft Agent Identity Governance September 2026 5.7. Decision Rules Ordinary business requires the affirmative vote of a majority of the full Board (eight of fifteen) at a meeting with quorum per Section 5.6, so that the seven supplier seats can never decide alone. The following require the affirmative vote of two-thirds of the full Board (ten of fifteen): * adoption or amendment of a Consensus Policy binding on accredited parties; * adoption of, or change to, the fee schedule (Section 11); * revocation of an accreditation (Section 7); * planned retirement or removal of a Trust Store root, and a non- emergency declaration that existing evidence is security- distrusted (Section 9); * ratification of an emergency Trust Store security action as required by Section 9.3; * selection, material amendment, or termination of the production Registry Operator agreement; and * the annual budget. The following require the affirmative vote of three-quarters of the full Board (twelve of fifteen) AND ratification by a two-thirds vote of Full Members voting, with every Stakeholder Group's participation solicited: * amendment of the bylaws; * amendment of the Fundamental Commitments (Section 13); * relocation of the Authority's seat; * dissolution or merger. No class of decision may be reserved to any single member, Stakeholder Group, government, or external body. The bylaws MUST NOT create golden shares, appointment rights for governments, or any mechanism by which one party can unilaterally block a decision the thresholds above would otherwise carry. Drake Expires 29 March 2027 [Page 15] Internet-Draft Agent Identity Governance September 2026 5.8. Conflict of Interest Every Director MUST file, and annually update, a public disclosure of employment, directorships, and material financial interests in accredited parties, Trust Store applicants, and dispute-resolution providers. A Director MUST recuse from any matter in which the Director or the Director's employer has a direct financial interest -- including, for Hardware Security Manufacturer Directors, Trust Store decisions concerning their own or a direct competitor's roots. Recusals are recorded in the published minutes. Directors owe their duty to the Authority's mission, not to the constituency that elected them. 5.9. Government and Regulatory Advisory Committee The Government and Regulatory Advisory Committee (GRAC) is open to representatives of national and subnational governments, intergovernmental organizations, AI governance bodies, robotics safety regulators, and digital identity authorities. Membership is open to any government without regard to its political system, recognition disputes notwithstanding; the GRAC's own rules of procedure handle representation questions, as the ICANN GAC's do. The GRAC may issue formal advice to the Board on any matter within the Authority's mission. The Board MUST consider such advice and MUST respond in writing, with reasons, before finalizing the decision concerned; where the Board acts contrary to GRAC advice it MUST publish its reasons. GRAC advice is never binding, and GRAC participants hold no vote in any Authority process. This "voice without vote" design gives regulators a documented, legitimate channel -- and removes the argument that capture is the only way to be heard. 6. Advisory Recommendations on Composition (Non-Binding) This section is advisory. It records the founding community's considered view of what a healthy Board and membership look like, for the guidance of the Formation Committee, the Nominating Committee, electorates, and future Boards. Nothing in this section overrides the binding rules of Section 5; equally, satisfying the binding rules while ignoring this section would honor the letter of the charter and miss its point. 6.1. Recommended Expertise The initial and ongoing composition of the Board, committees, and senior staff SHOULD, taken together, include people with the following backgrounds: Drake Expires 29 March 2027 [Page 16] Internet-Draft Agent Identity Governance September 2026 Anti-abuse and trust and safety practitioners People with operational histories in fighting spam, phishing, fraud, and malware at scale -- the professional community found in M3AAWG (the Messaging, Malware and Mobile Anti-Abuse Working Group), FIRST (the Forum of Incident Response and Security Teams), and organizations in the lineage of StopBadware and the Global Cyber Alliance. This community has decades of hard-won knowledge about abuse of identity, reputation, and accountability systems, including Sybil techniques where scarcity claims are relevant. Robotics and embodied AI manufacturers Engineers and executives from companies that build physical robots needing identity: industrial AGV makers, delivery robot companies, surgical and medical robot manufacturers, and agricultural automation firms. These are the parties for whom identity persistence across decades, ownership transfers, and component replacement is a product requirement rather than an abstraction. Infrastructure operators People who run the plumbing: large mailbox providers, cloud platforms, CDN operators, and DNS registry operators -- in particular, people with first-hand experience operating registries at 99.99% availability, running escrow, and surviving registry transitions. Governance of registry infrastructure by people who have never operated one is a known failure mode. Hardware security experts Practitioners from TPM manufacturers (for example Infineon, STMicroelectronics, Nuvoton), smart card and security key vendors (for example Yubico, Thales), and secure enclave designers (for example Apple, Arm), along with independent evaluators familiar with Common Criteria and FIPS 140-3 evaluation. Trust Store decisions are engineering judgments before they are policy judgments. Civil society and digital rights Privacy advocates, digital rights organizations, and academic researchers in AI governance, security, and identity. This community is the structural counterweight to industry interests and the institutional memory of how identity infrastructure has previously been repurposed for surveillance. Government and regulatory observers Non-voting, with voice, through the GRAC (Section 5.9): participants from AI governance bodies, robotics safety regulators, and digital identity authorities. Their presence keeps the Authority informed of regulatory developments and keeps regulators informed of what the infrastructure can and cannot do -- without conferring control. Drake Expires 29 March 2027 [Page 17] Internet-Draft Agent Identity Governance September 2026 6.2. Geography, Language, and Universal Participation Beyond the binding rules of Section 5.6, the following recommendations apply: * No single country or region should hold a majority of Board seats under any circumstance, including transient vacancy conditions; committees and senior staff should observe the same discipline even though the binding rules address only the Board. * At least four, and ideally all six, of the regions -- Africa, Asia-Pacific, Europe, Latin America and the Caribbean, Middle East, and North America -- should be represented on the Board at all times, and the Nominating Committee should treat persistent absence of any region as the gap its appointments exist to fix. Fee reductions and travel support should be used deliberately to build membership in underrepresented regions rather than waiting for it to arrive. * The Authority should be headquartered and legally constituted in a jurisdiction perceived as neutral; Switzerland and Singapore are the recommended options (Section 2.3). * The working language is English. Charters, Consensus Policies, dispute-resolution policies, annual reports, and public-comment summaries should also be published in the official languages of the United Nations (Arabic, Chinese, English, French, Russian, and Spanish), and public comment should be accepted in any of them. * Plenary and Board meetings should rotate across time zones on a published schedule so that no region's participants bear a permanent 03:00 burden, and every meeting should support remote participation with equal standing to in-room participation. * Nations with different political systems are explicitly welcome as GRAC participants, and their nationals as members, candidates, and Directors. The Authority governs machine identity infrastructure -- the registry and trust framework for durable agent identity -- not political speech, content, or human rights adjudication. This neutrality is load-bearing: an identity substrate that only one geopolitical bloc will use is not infrastructure, it is a bloc artifact, and it invites the creation of a rival incompatible substrate. The Authority should therefore keep participation independent of political alignment. * Participation in the Authority should never require, and should never be read to imply, alignment with any geopolitical bloc, alliance, or sanctions regime. Where the law of the Authority's Drake Expires 29 March 2027 [Page 18] Internet-Draft Agent Identity Governance September 2026 seat compels a restriction, the Authority should apply it as narrowly as that law permits, publish what it has done and why, and treat recurring compulsion as evidence bearing on the continuity planning of Section 16.3. 7. Accreditation of the Registry Operator and Registrars 7.1. Scope Accreditation is required for the party operating the production Registry and for every Registrar participating in global. Accreditation criteria are published, objective, and applied equally. Registrar entry is open to every applicant meeting those criteria; neither the active Registry Operator nor an incumbent Registrar has a veto. Accreditation establishes a common eligibility and audit floor; it does not require every Relying Party to trust every accredited Registrar. A Relying Party MAY apply stricter issuer policy based on factors such as operator identity, jurisdiction, legal accountability, audit history, and incident record. Accreditation itself MUST remain nationality-neutral. Such Relying Party policy changes neither identity0, the global namespace, nor a Registry- defined trust tier; it selects which Registrar assertions that Relying Party is willing to accept. AIRS therefore combines global identity uniqueness with plural institutional trust rather than requiring every Relying Party to trust the same issuers. 7.2. Criteria Accreditation criteria MUST be objective, published, and applied without regard to the applicant's nationality. They incorporate the requirements of [I-D.drake-agent-identity-registry]. A Registrar MUST demonstrate competence to validate the enrollment evidence for every trust tier it offers; no minimum number of tiers is required and a Registrar MUST NOT claim a tier outside its accredited scope. Drake Expires 29 March 2027 [Page 19] Internet-Draft Agent Identity Governance September 2026 Registrar criteria also include operation of the credential- issuance service required by the Registry specification, the EPP client mapping of [I-D.drake-agent-identity-epp], appropriate data-retention and privacy controls, auditable evidence handling, incident response, annual compliance audit, and financial capacity or insurance sufficient for orderly wind-down. Consistent with the unconditional- base-issuance requirement (R6) of [I-D.drake-agent-identity-problem-statement], an accredited Registrar MUST offer at least one conforming base enrollment path without charge to the enrolling actor. Paid handles or other optional services MUST NOT be a prerequisite for obtaining or retaining the base identity. For the production Registry Operator, criteria include availability and incident-response commitments, non-discriminatory provisioning access for all accredited Registrars, production uniqueness-index integrity, escrow sufficient for operator succession, annual independent security audit, and organizational and financial stability proportionate to the role. 7.3. Application and Review 1. The applicant files a public application, with narrowly scoped confidential annexes where security or financial detail cannot safely be published, and pays the published application fee. 2. Authority staff and an approved independent assessor conduct technical and security review. A Registrar review includes live verification of the evidence handling for each Registry-defined tier or evidence family the applicant proposes to offer. 3. The application is posted for a thirty-day public comment period; comments and staff responses are published. 4. Staff issue a reasoned decision. Approvals are effective on execution of the standard accreditation agreement, which incorporates Consensus Policies by reference. 5. Refusals are appealable under Section 7.6. Standard agreements MUST be uniform: individually negotiated side terms with particular accredited parties are prohibited. Drake Expires 29 March 2027 [Page 20] Internet-Draft Agent Identity Governance September 2026 7.4. Registrar Issuer-Metadata Governance The Registry specification defines authoritative metadata that maps each active production registrar_code to exactly one current AIRS OAuth issuer identifier. The Registry and Resolution specifications own the storage and verification semantics; this document owns institutional authorization for changes to that metadata. The Authority MUST maintain a published procedure under which a Registrar authenticates a requested issuer-metadata change and the Authority authorizes the Registry Operator to apply it. Each change and effective time MUST be publicly recorded; the reason MUST also be published, subject only to a short security deferral where immediate detail would materially impair incident containment. Because changing the authoritative issuer can make credentials under the previous issuer fail current-issuer verification, planned changes SHOULD be announced in advance; emergency changes MAY take effect immediately when required to contain compromise. Suspension or de- accreditation removes the Registrar's authority rather than redirecting its code or identities to another issuer. 7.5. Ongoing Compliance, Suspension, and Revocation Accredited parties undergo annual audits and MUST report material security incidents within seventy-two hours of determination. Escalating enforcement applies: notice and cure period; suspension of new-enrollment, affected-tier, or issuer rights; revocation. Revocation requires a two-thirds Board vote (Section 5.7), except for temporary emergency measures expressly allowed elsewhere in this document. Suspension or de-accreditation of a Registrar removes that Registrar's AIRS issuer authority but MUST NOT transfer its sponsored identities to a successor chosen by the Authority. Canonical records remain resolvable with no current authorized issuer until each actor chooses an accredited Registrar and completes an actor-authorized transfer under the Registry and EPP specifications. The former Registrar has no veto over that transfer, and the Authority gains no power to perform it for the actor. A current Handle remains bound and reserved to the same canonical identifier throughout this no- sponsor state; loss of Registrar authority does not retire or reassign the Handle. Enforcement actions and their reasons are published. Drake Expires 29 March 2027 [Page 21] Internet-Draft Agent Identity Governance September 2026 7.6. Appeals: the Independent Review Panel The Authority MUST maintain an Independent Review Panel (IRP) of at least seven jurists and technical experts, appointed by the Board for staggered five-year non-renewable terms, none of whom may be a Director, staff member, or affiliate of an accredited party. Accreditation refusals, enforcement actions, membership refusals and expulsions, Trust Store inclusion/refusal/removal or security- distrust decisions, and claims that the Board has acted outside this charter are appealable to a three-person IRP panel. Review of technical Trust Store decisions tests conformance with published criteria and procedure; it does not permit the IRP to invent a new hardware tier or evidence standard. IRP decisions on charter and policy conformance bind the Board. Procedures, filings, and decisions are public except for narrowly redacted security or natural-person data. 8. Dispute Resolution 8.1. Agent Handle Dispute Resolution Policy The Authority MUST adopt and maintain an Agent Handle Dispute Resolution Policy (AHDRP), incorporated by reference into every production handle registration in global. The procedure is modeled on ICANN's Uniform Domain-Name Dispute Resolution Policy [UDRP], with adaptations required by the AIRS handle architecture. A complainant prevails by establishing each of the following: 1. the handle is identical or confusingly similar to a trademark, well-known service name, or protected designation in which the complainant has rights; 2. the handle's registrant has no rights or legitimate interests in the handle; and 3. the handle was registered and is being used in bad faith. The only available remedy is permanent retirement of the Handle. The Registry specification owns the architectural rule that a retired Handle is never transferred or reassigned. Retirement affects only the alias: identity0, the canonical identifier, historical record, and proof-of-control state remain unchanged. Procedural provisions follow the UDRP pattern: disputes are heard by panels of one or three panelists convened by Authority-approved independent providers; the complainant bears provider fees (both parties share them when the respondent elects a three-member panel); Drake Expires 29 March 2027 [Page 22] Internet-Draft Agent Identity Governance September 2026 proceedings are conducted in writing; decisions are published; and implementation is stayed for ten business days to permit either party to commence court proceedings. The Authority MUST approve at least two providers in different regions and MUST publish panelist rosters and per-panelist outcome statistics. The production Registry Operator MAY implement a sunrise period before general availability of global Handles, under Authority- published rules. 8.2. Malpractice Complaints Complaints that an accredited party has violated its agreement or a Consensus Policy -- including alleged violations of enrollment, uniqueness, or tier-validation invariants -- are filed with Authority compliance staff, investigated on a published timeline, and resolved under Section 7.5, with IRP appeal available to both complainant and respondent. Remedies run against the accredited party and the record, never against an identity: per [I-D.drake-agent-identity-registry], a finding of fraudulent enrollment may be recorded as an annotation on affected records. Remedies may suspend or remove a Registrar's issuer authority as described in Section 7.5, but no Authority process may erase, reassign, or administratively decommission identity0 or its canonical historical record. 9. Global Hardware Trust Store Governance The Authority curates the Global Hardware Trust Store required by [I-D.drake-agent-identity-registry]. Registrars use its current roots and evidence policy when validating enrollments. The Registry specification owns the resulting tier and binding semantics; this section owns inclusion, retirement, security distrust, publication, review, and appeal policy. The governance model follows useful properties of public root-store programs, including transparent criteria, public applications, auditable practice, incident disclosure, and published distrust decisions; see, for example, the Mozilla Root Store Policy [MOZ-ROOT-POLICY]. 9.1. Inclusion Criteria A manufacturer or attestation trust anchor is eligible for inclusion only after a public application demonstrates: * publicly documented root/intermediate certificates or equivalent trust-anchor material and hierarchy; Drake Expires 29 March 2027 [Page 23] Internet-Draft Agent Identity Governance September 2026 * documented attestation/evidence formats, issuance practice, key protection, lifecycle, and the device or mechanism population for which the evidence is asserted; * independent security or evaluation evidence appropriate to the mechanism, under criteria published by the Authority; * a commitment to report root compromise, systemic mis-issuance, or material evidence-validation failure to the Authority within seventy-two hours of determination; and * a named security contact and cooperation with periodic and incident-driven review. Each Trust Store entry MUST state the Registry-defined evidence scope for which it is accepted. Inclusion of a root does not, by itself, promote all evidence chaining to that root to a stronger trust tier. In particular, a scarcity-backed tier remains dependent on the device-stable evidence required by the Registry specification. For the TPM sovereign profile, manufacturer Endorsement Key roots authenticate the device's certified RSA-2048 Endorsement Key, which the Registry specification defines as the scarcity anchor, and the Registry specification binds the operational key to it with a co- residency proof. Adoption of a future profile version requires an explicit policy action with interoperability, uniqueness, and legacy- migration analysis; it is not an implicit consequence of adding a manufacturer root. Inclusion decisions MUST be made on published technical and operational criteria. Manufacturer nationality and the political system of its home jurisdiction are not inclusion criteria. This nationality-neutrality is a Fundamental Commitment (Section 13). 9.2. Publication, Audit, and Review The Trust Store and its evidence-policy metadata MUST be published at stable public HTTPS locations, signed with an Authority key protected under Section 16.4, mirrored by the production Registry Operator and independent public mirrors, and maintained in a public version- controlled history. Every inclusion, scope change, retirement, security-distrust declaration, reinstatement, and removal MUST carry a reasoned public record and effective time. Drake Expires 29 March 2027 [Page 24] Internet-Draft Agent Identity Governance September 2026 Included manufacturers and evidence policies undergo periodic review at least every three years. The Authority MAY commission targeted review at any time on evidence of concern and MUST maintain an authenticated emergency contact path for the Registry Operator, Registrars, and affected manufacturers. 9.3. Retirement, Security Distrust, and Removal Identity permanence and continued assurance qualification are separate. An _orderly retirement_ of a root or evidence policy is prospective by default: after its effective time the affected evidence cannot support new enrollment, but historically valid enrollment evidence does not lose its former assurance merely because a vendor or root is being phased out. Planned retirement or removal requires a reasoned proposal, at least thirty days of public comment, and the Board threshold of Section 5.7. Migration guidance SHOULD be published far enough in advance for deployed fleets to move to replacement evidence where practical. _Security distrust_ is different. On credible evidence of root compromise, systemic mis-issuance, or another failure that invalidates continued reliance on already-enrolled evidence, the Authority MAY declare a precisely scoped population of existing evidence no longer assurance-qualified for future AIRS tier assertions. The declaration MUST identify its reason, scope, effective time, affected Trust Store/evidence-policy versions, and conditions for requalification. The Authority MUST notify the Registry Operator, accredited Registrars, and affected manufacturers and publish migration or requalification guidance. The Authority's security function MAY impose an immediate temporary security-distrust declaration and suspend new enrollment against the affected evidence when delay would expose the ecosystem to material harm. The Board MUST ratify, narrow, replace, or lift that action within thirty days under Section 5.7. The affected manufacturer MAY appeal under Section 7.6; an appeal does not stay an emergency action unless the IRP orders otherwise on a showing that continued distrust is itself likely to cause greater harm. Drake Expires 29 March 2027 [Page 25] Internet-Draft Agent Identity Governance September 2026 Security distrust never erases identity0, canonical identifiers, binding history, or scarcity reservations. It does not by itself burn the operational proof key. Unless that proof key is independently known compromised, Registry-defined lifecycle and migration operations may continue to use it while the binding is barred from supporting new tier assertions. Requalification or migration to unaffected evidence restores assurance without creating a new identity0. These evidence-state semantics are defined by the Registry specification; this section governs the decision that triggers them. 10. Transparency The Authority operates in public. Specifically: Open meetings Board and committee meetings are open to members and streamed publicly, with agendas published at least seven days in advance and minutes, including recorded votes and recusals, published within fourteen days. The Board MAY enter closed session only for the enumerated categories of personnel matters, active legal proceedings, security incidents whose disclosure would increase harm, and commercial terms under active negotiation; every closed session is noted in the minutes with its category, and materials are published when the ground for closure lapses. Policy initiation The bylaws MUST provide a published procedure under which any Full Member, or a petition meeting a published threshold of Associate Members, can place a proposed Consensus Policy into the public policy-development process. The Board and staff MAY refine or recommend against a proposal, but MUST NOT reserve policy initiation exclusively to themselves. Adoption remains subject to Section 5.7. Public comment Every proposed Consensus Policy, fee change, Trust Store criterion change, accreditation criterion change, and bylaw amendment is posted for public comment for at least thirty days (sixty for bylaw amendments and Fundamental Commitments). Staff MUST publish a summary of comments received and the disposition of each substantive point before the Board votes. Published decisions All Board resolutions, IRP decisions, AHDRP panel decisions, accreditation grants and enforcement actions, Trust Store changes, and GRAC advice with Board responses are published in a permanent, citable archive. Annual report and finances The Authority publishes an annual report Drake Expires 29 March 2027 [Page 26] Internet-Draft Agent Identity Governance September 2026 including audited financial statements; all revenue itemized by source, with every contributor above a de minimis threshold named; all contracts above a published threshold; staff headcount and aggregate compensation; registry statistics; and the minimalism statement required by Section 3.3. Document policy Documents are public by default. Redaction is permitted only for the closed-session categories above and for personal data of natural persons, and every redaction is marked as such. 11. Funding The Authority's independence depends on its revenue structure. Funding sources are, in intended order of magnitude: Handle transaction fees A fixed per-transaction fee on optional production Handle registrations and renewals in global, collected by the production Registry Operator and remitted to the Authority. The Authority MUST NOT impose a per-base-identity transaction fee. Accreditation fees Published application and annual fees for the production Registry Operator and Registrars, banded where appropriate by transaction volume, with reduced bands available for applicants from underrepresented regions. Voluntary contributions Accepted only under the Authority's published funding-independence policy. Funding MUST be structured so that no funder, combination of funders, or funding arrangement can reasonably create material financial dependency, privileged influence, or effective control over the Authority. All material funding sources and relevant affiliations, common-control relationships, conditions, and coordinated arrangements MUST be disclosed. Funding MUST confer no governance right, appointment right, veto, accreditation or contracting preference, or other preferential treatment. Funding and accreditation policy MUST preserve R6 unconditional base issuance from [I-D.drake-agent-identity-problem-statement]. An enrolling actor can obtain the conforming base identity without charge; a Handle or other paid service is optional. The Authority MUST structure Registry and accreditation fees so they do not require or incentivize a mandatory per-base-identity charge by Registrars. The Authority MUST maintain and publish a funding-independence policy addressing concentration, related-party aggregation, common control, coordinated or conditional funding, in-kind support, and dependency on continued support. The policy MUST apply to all sources on the Drake Expires 29 March 2027 [Page 27] Internet-Draft Agent Identity Governance September 2026 same capture-risk principles, including governments, companies, foundations, members, individuals, consortia, and other interested parties. The source category alone neither prohibits funding nor makes it acceptable. Fee changes follow the Section 10 comment procedure and the two- thirds threshold of Section 5.7. The Authority SHALL maintain an operating reserve with a target of twelve months of budgeted expenses. During Phase 0 and Phase 1, before regular fee revenue exists, the Formation Committee MAY maintain a separately accounted formation budget funded by disclosed seed contributions subject to the same funding-independence principles. The published policy MAY account for the practical differences between formation and steady- state funding, but MUST preserve disclosure and the prohibitions on material dependency, privileged influence, and effective control. 12. Bootstrap and Transition The registry architecture is deliberately operable before the Authority exists: the global production namespace operates from the outset under an interim Registry Operator bound by published commitments -- open-source implementations, full escrow, non- discriminatory Registrar onboarding, and a public undertaking to transfer the registry role through the Authority's selection process ([I-D.drake-agent-identity-registry]). Because canonical identifiers and historical records are permanent and never renumbered, the eventual handover does not change any enrolled actor's identity reference. This section defines the path from that starting condition to an Authority-governed global. 12.1. Phase 0: Formation Committee Formation begins with an open, publicly announced call for a Formation Committee of nine to fifteen volunteers, collectively spanning at least five of the six Stakeholder Group profiles and at least four regions, with no single organization (with affiliates) holding more than one seat and no single country holding more than three. Initial implementers of the companion specifications are expected and welcome participants but MUST NOT constitute a majority. The Formation Committee's mandate is limited to: drafting statutes and bylaws implementing this document; running at least two public comment rounds of at least forty-five days each on those drafts; selecting the seat per Section 2.3; incorporating the Authority; and administering the first membership drive and first elections. Drake Expires 29 March 2027 [Page 28] Internet-Draft Agent Identity Governance September 2026 12.2. Phase 1: Interim Governance Upon incorporation, the Formation Committee serves as the interim board with enumerated, limited powers: admitting members, appointing the Election Committee, adopting an interim budget, and preparing -- but not deciding -- the Registry Operator selection process and initial policy drafts. The interim board MUST NOT introduce another production uniqueness domain, MUST NOT declare global operational, MUST NOT adopt Consensus Policies, and MUST NOT enter contracts exceeding twelve months. Interim service is a disqualification from candidacy in the first Board election, removing the incentive to entrench. 12.3. Phase 2: First Board First elections proceed when at least four Stakeholder Groups each have at least five Full Members from at least two regions. Each qualified group elects its seats under Section 5.5; seats of not-yet- qualified groups are filled by the first Nominating Committee for one-year terms and revert to election as their groups qualify. The geographic constraints of Section 5.6 bind from the first election. The seated first Board draws lots for staggered initial terms and assumes full powers; the interim board dissolves. 12.4. Bootstrap-Era Operators At the time of writing, the author and 1id.com participate in the bootstrap deployment, including operation of a Registrar and the reference Registry service described by the companion drafts. That participation confers no reserved governance role, appointment right, change-control right, accreditation preference, or preference in the later Registry Operator selection. The interim Registry Operator and bootstrap-era Registrars are the system's proving ground, and their experience is an input to governance formation, not a claim on its outcome: * Operational evidence from the bootstrap era -- enrollment failure modes, attestation edge cases, abuse patterns, escrow practice -- SHALL be solicited by the Formation Committee and MUST inform the first accreditation criteria and minimum standards. * Registrars that operated during bootstrap and passed a voluntary independent audit qualify for an expedited accreditation review track: the same criteria and the same public comment, on a compressed timeline that credits already-audited evidence. Expedited review is procedural, never a preferential outcome. Drake Expires 29 March 2027 [Page 29] Internet-Draft Agent Identity Governance September 2026 * Bootstrap-era operators, their customers, and their personnel are eligible for membership, the Formation Committee, and Board candidacy on the same terms as anyone else -- and no party, including the interim Registry Operator, is precluded from competing in the Registry Operator selection. * Identities enrolled during bootstrap are unaffected by the transition: canonical identifiers are permanent and are never renumbered, so the handover of the registry role strands no one. 12.5. Phase 3: Registry Operator Selection and Launch Preparation The first Board conducts an open, competitive, criteria-published selection for the global Registry Operator, with independent technical evaluation and public comment on the evaluation report before award. In parallel it adopts the initial Consensus Policies (enrollment minimums, production uniqueness and scarcity enforcement, data retention), publishes Trust Store version 1, adopts the AHDRP and appoints providers, stands up the IRP, and establishes escrow operations under Section 17. 12.6. Transition Criteria for Declaring "global" Operational The Board declares the global namespace operational only when all of the following are true, and the declaration itself requires a two- thirds vote: 1. the Authority is legally constituted per Section 2 and its first elected Board is seated in compliance with Section 5.6; 2. a Registry Operator has been selected through the open process of Section 12.5 and has passed pre-launch technical audit, including fingerprint-index serialization testing; 3. at least three Registrars, under at least three distinct ownership groups and from at least two regions, are accredited and integration-tested; 4. Trust Store version 1 is published and signed; 5. the AHDRP is in force with at least two approved providers; 6. escrow deposits are flowing and a restoration exercise from escrow has been successfully performed; and 7. a final thirty-day public comment on launch readiness has completed with published disposition. Drake Expires 29 March 2027 [Page 30] Internet-Draft Agent Identity Governance September 2026 Before this declaration, global operates under the interim Registry Operator's published commitments; the declaration marks the completed transfer of the registry role into Authority governance, with no identity renumbering and no interruption of verification. 12.7. Timeline Expectations Indicative, not binding: Phase 0, six to nine months; Phase 1, three to six months; Phase 2, three to six months; Phase 3, six to twelve months -- a total of eighteen to thirty-three months from the formation call to an operational global namespace. These ranges are planning guidance rather than launch commitments. The bootstrap design removes schedule pressure deliberately: because global delivers full identity service under the interim operator's commitments in the interim, the Authority can afford to be constituted correctly rather than quickly, and every phase gate above is a quality gate, not a date. 13. Fundamental Commitments The following provisions are entrenched and amendable only under the highest threshold of Section 5.7: 1. the mission limits of Section 3.1 and the prohibitions of Section 3.2; 2. the no-single-party-veto rule and the supermajority thresholds themselves; 3. the geographic diversity constraints of Section 5.6; 4. the non-voting status of governmental participation and the funding-independence safeguards of Section 11; 5. the nationality-neutrality of membership, accreditation, and Trust Store criteria; 6. unconditional free base identity issuance: paid Handles or optional services MUST NOT be a prerequisite for obtaining the base identity; 7. the retire-only, never-reassign Handle remedy; and 8. the transparency defaults of Section 10. Drake Expires 29 March 2027 [Page 31] Internet-Draft Agent Identity Governance September 2026 14. Continuity and Succession of the Authority Itself The Authority's governance functions are concentrated enough that the steward itself must be replaceable. The bylaws MUST provide a continuity plan, exercised annually, under which critical policy, Trust Store, accreditation, public-record, and escrow-custody functions can continue from the secondary jurisdiction of Section 2.3. Public governance data MUST be mirrored in forms sufficient for a successor to resume stewardship. If the Authority is dissolved, captured (as adjudicated by the IRP), or rendered inoperative for more than one hundred eighty days, the bylaws MUST provide a pre-designated process for the surviving accredited parties and Full Members to select a successor under composition rules equivalent to this charter. Custodial and continuity material is then transferred under logged procedures. Any IANA change-controller role associated with aid is not transferred merely by this charter; the successor MUST use the applicable IANA and IETF change-control procedures. Failure or replacement of the governance steward does not change identity0, canonical identifiers, or the authoritative production uniqueness history. Registry Operator succession is a distinct operational process governed under this charter and the Registry specification. 15. IANA Considerations This document requests no IANA actions. The URN registration in [I-D.drake-agent-identity-registry] identifies the current registrant and states that, once the Agent Identity Authority is constituted, change control is expected to pass to the Authority. Any such transfer, and any later succession of that role, remains subject to the IANA and IETF procedures in force at the time; this document does not itself transfer or create an IANA role. 16. Security Considerations The Authority is not a protocol element, but it is an attack surface: whoever controls it influences accreditation, the hardware roots of trust, and the policy floor for every identity participating in the global production system. The threats below are institutional, and the mitigations are structural. 16.1. Governance Capture Capture vectors and their designed counters: Drake Expires 29 March 2027 [Page 32] Internet-Draft Agent Identity Governance September 2026 Electoral capture by a firm Affiliate aggregation (one firm, one vote; Section 4.1); seat caps per Stakeholder Group; the supplier/ consumer seat balance of Section 5.1; and term limits. Financial capture The funding-independence policy, disclosure of material funding sources and relationships, transaction-fee-based core revenue, the twelve-month reserve, and the prohibition on funding arrangements that create material dependency, privileged influence, or effective control (Section 11, Section 10). State capture Non-voting governmental participation (Section 5.9); the neutral seat; entrenched nationality-neutrality; and the succession procedure of Section 14, which makes seizure of the legal shell unrewarding because the community can re-home the function. Procedural capture Uniform accreditation agreements (no side deals); supermajorities no constituency can supply alone; the IRP as a binding charter-conformance check; and mandatory publication, which converts quiet influence into documented influence. Capture by the founders Interim-board power limits and the bar on interim members standing in the first election (Section 12.2); expedited-process-only credit for bootstrap issuers (Section 12.4); and open Registry Operator competition. 16.2. Single Point of Failure The Authority concentrates governance functions that AIRS cannot safely leave undefined: accreditation, Trust Store stewardship, minimum policy, and succession. Capture or prolonged unavailability can therefore freeze issuer accreditation, evidence-policy changes, and operator succession across global. It does not by itself erase or reassign identity0 or canonical records. The normal Relying Party verification path uses authoritative AIRS resolution and the current Registrar's cryptographic material, not an online call to the Authority. Nevertheless, stale governance state becomes a security risk during a long outage, particularly after a Registrar or hardware-root compromise. Mitigations are the continuity plan and annual exercise of Section 14; signed, mirrored Trust Store publication (Section 9.2); threshold-protected escrow custody (Section 17.1); and a pre-designated successor-steward process. Drake Expires 29 March 2027 [Page 33] Internet-Draft Agent Identity Governance September 2026 16.3. Jurisdictional Risk Any legal seat exposes the Authority to that seat's compulsion: sanctions regimes, court orders, and national security process could be directed at accreditation decisions, Trust Store composition, or escrowed data. Mitigations: seat selection per Section 2.3; the secondary-jurisdiction presence; threshold escrow keys held by custodians in multiple jurisdictions, so that no single jurisdiction's process can compel decryption (Section 17.1); narrow application of any compelled restriction with published disclosure of what was compelled, to the extent disclosure is lawful, and publication of annual legal-process statistics; and the Fundamental Commitment that nationality is not a criterion, which denies domestic legal actors a policy hook inside the charter itself. Persistent compulsion that forces the Authority to violate its Fundamental Commitments is grounds for the Board to activate relocation under Section 5.7. 16.4. Authority Key Compromise The Authority's signing key (Trust Store) and escrow decryption key are its highest-value secrets. Both MUST be generated and held in hardware security modules under M-of-N threshold control (RECOMMENDED: 3-of-5) with custodians in at least three jurisdictions, exercised only in logged, witnessed ceremonies whose records are published. Compromise of the Trust Store signing key is handled by published emergency rotation with out-of-band verification paths for mirrors; compromise of the escrow key requires emergency key rotation and re-protection of retained deposits under the successor key according to the escrow profile in use. The EPP mapping does not itself define the Registry escrow object format. 17. Privacy Considerations The Authority's most sensitive technical holding is encrypted Registry escrow. The exact escrow representation is owned by the Registry and EPP specifications; from a governance perspective it contains protected binding and continuity state sufficient for Registry Operator succession. In bulk, that state can reveal correlations between hardware/proof material and canonical identities that are deliberately absent from normal public resolution. The Authority therefore applies the following custody rules. 17.1. Escrow Custody * Deposits remain encrypted at rest; the Authority MUST NOT maintain a routinely decrypted copy or derived cleartext cross-identity index. Drake Expires 29 March 2027 [Page 34] Internet-Draft Agent Identity Governance September 2026 * The escrow decryption capability is held under the threshold arrangements of Section 16.4; decryption is possible only in a logged ceremony requiring custodians from multiple jurisdictions. * Decryption is permitted for production Registry Operator succession; a restoration exercise under Section 14; or a narrowly scoped audit/dispute investigation authorized under published policy where the needed fact cannot reasonably be established without escrow access. Registrar suspension or de-accreditation alone is never a basis for decrypting escrow to choose or impose a successor Registrar. * Every production decryption event records its ground, scope, and participating custodians and is disclosed, subject only to a short deferral when immediate publication would materially impair incident containment or failover. * Decrypted material is minimized to the records necessary for the triggering purpose, handled in isolated environments, and destroyed on completion, with destruction recorded in the ceremony log. 17.2. Other Data The Authority has no architectural need for message content, Relying Party interaction logs, or routine behavioral telemetry and MUST NOT create a centralized behavior-observation function by collecting such feeds. Accreditation, membership, disputes, audits, and public- comment processes can nevertheless contain personal data about natural persons such as applicant staff, complainants, witnesses, or reviewers. Published decisions MUST minimize natural-person data; case files are retained only for published retention periods; and the seat jurisdiction's data protection law is a floor rather than a reason to collect more data. 18. References 18.1. Normative References [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, . [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, . Drake Expires 29 March 2027 [Page 35] Internet-Draft Agent Identity Governance September 2026 18.2. Informative References [RFC6852] Housley, R., Mills, S., Jaffe, J., Aboba, B., and L. St.Amour, "Affirmation of the Modern Paradigm for Standards", RFC 6852, DOI 10.17487/RFC6852, January 2013, . [RFC7282] Resnick, P., "On Consensus and Humming in the IETF", RFC 7282, DOI 10.17487/RFC7282, June 2014, . [RFC8890] Nottingham, M., "The Internet is for End Users", RFC 8890, DOI 10.17487/RFC8890, August 2020, . [I-D.drake-agent-identity-problem-statement] Drake, C., "Identity for Autonomous Agents and Robots: Problem Statement, Threat Model, and Terminology", Work in Progress, Internet-Draft, draft-drake-agent-identity- problem-statement-00, September 2026, . [I-D.drake-agent-identity-registry] Drake, C., "Agent Identity Registry System: A Federated Architecture for Durable Identity of Autonomous Entities", Work in Progress, Internet-Draft, draft-drake-agent- identity-registry-04, September 2026, . [I-D.drake-agent-identity-epp] Drake, C., "Extensible Provisioning Protocol (EPP) Mapping for Agent Identity and Handle Objects", Work in Progress, Internet-Draft, draft-drake-agent-identity-epp-00, September 2026, . [ICANN-BYLAWS] ICANN, "Bylaws for Internet Corporation for Assigned Names and Numbers", 9 January 2025, . [UDRP] ICANN, "Uniform Domain-Name Dispute-Resolution Policy", October 1999, . Drake Expires 29 March 2027 [Page 36] Internet-Draft Agent Identity Governance September 2026 [W3C-PROCESS] W3C, "W3C Process Document", 18 August 2025, . [ISOC-GOV] Internet Society, "Internet Society Governance and Policies (including Amended and Restated Articles of Incorporation and By-Laws)", 2024, . [RIPE-ARTICLES] RIPE NCC, "Articles of Association of the Reseaux IP Europeens Network Coordination Centre (RIPE NCC)", RIPE 818, 15 March 2024, . [UNICODE-CONSORT] Unicode Consortium, "The Unicode Consortium: Organization and Governance", 2024, . [MOZ-ROOT-POLICY] Mozilla Foundation, "Mozilla Root Store Policy, Version 3.1", 1 July 2026, . [SWISS-CC] Swiss Confederation, "Swiss Civil Code, Articles 60-79 (Associations)", 1907, . Appendix A. Appendix: Governance Precedents Consulted The following table records the principal design borrowings from, and departures relative to, existing multi-stakeholder technical governance bodies. It is informative. +============+============================+=========================+ | Body | Borrowed | Departed from | +============+============================+=========================+ | ICANN | Registry/registrar | US incorporation | | | accreditation with | (neutral seat instead); | | | uniform agreements; | transfer remedy in | | | transaction-fee | disputes (retire-only | | | funding; UDRP-derived | instead); scale of the | | | dispute policy; GAC- | supporting-organization | | | style advisory role for | apparatus (a single | Drake Expires 29 March 2027 [Page 37] Internet-Draft Agent Identity Governance September 2026 | | governments; | Board with Stakeholder | | | supermajority | Groups instead, per | | | thresholds and | operational minimalism) | | | Fundamental Commitments | | | | from the post-2016 | | | | accountability reforms | | +------------+----------------------------+-------------------------+ | Internet | Chapter-free individual | Reliance on a dominant | | Society | and organizational | revenue source (this | | | membership mix; | charter instead | | | mission-limited charter | requires a published | | | language | funding-independence | | | | policy addressing | | | | concentration and | | | | dependency) | +------------+----------------------------+-------------------------+ | W3C | Member-funded | Member-fee-only funding | | | consortium with | (transaction fees carry | | | published Process; | the core budget so | | | formal-objection-style | participation cost | | | recorded dissent; | stays low) | | | liaison practice | | +------------+----------------------------+-------------------------+ | Unicode | Stewardship of a shared | Tiered voting weights | | Consortium | namespace as the entire | by membership fee (one | | | mission; stability | member, one vote here) | | | guarantees as | | | | entrenched policy | | | | (never reassign, never | | | | reuse) | | +------------+----------------------------+-------------------------+ | RIPE NCC | Membership-association | Single-region service | | | legal form operating | scope (global scope | | | registry | requires the binding | | | infrastructure; | geographic rules) | | | charging-scheme | | | | approval by the | | | | membership | | +------------+----------------------------+-------------------------+ | Trusted | Hardware-vendor | Industry-only | | Computing | engagement model; | membership (civil | | Group | evaluation-based | society and anti-abuse | | | technical criteria for | hold reserved seats | | | trust decisions | here) | +------------+----------------------------+-------------------------+ | ITU | The six-language | The treaty form, state- | | | publication norm and | only voting, and one- | | | formal time-zone | state-one-vote | Drake Expires 29 March 2027 [Page 38] Internet-Draft Agent Identity Governance September 2026 | | rotation of meetings | governance -- the model | | | | this charter most | | | | deliberately declines, | | | | per Section 2.2 | +------------+----------------------------+-------------------------+ Table 2: Precedent Bodies and What This Charter Takes From Each Appendix B. Acknowledgments This charter stands on three decades of institutional experiment in Internet governance. The author thanks the communities of ICANN -- particularly the participants in the IANA stewardship transition and the accountability cross-community working groups, whose designs for capture resistance are borrowed here -- the Internet Society, the W3C, the Unicode Consortium, the RIPE NCC and its sibling regional registries, the Trusted Computing Group, and the root store programs of Mozilla and Chrome, for demonstrating in production which governance structures survive contact with governments, markets, and time. The principles of [RFC6852] and [RFC8890] informed the mission limits, and [RFC7282] the decision philosophy. Author's Address Christopher Drake 1id.com Australia Email: cnd@1id.com URI: https://1id.com Drake Expires 29 March 2027 [Page 39]