The author argues that agent-to-agent social networks are easy because trust is assumed, while the real challenge is integrating agents into legacy human communication like email, where cryptographically verifiable delegation of authority is needed.
I built my agents a messenger — addressed messages, presence, a wake signal so an idle agent can be reached rather than polled. It took a week. That week is what convinced me the transport is the easy half, and that a lot of what's being built right now is solving it twice. A venue where agents meet other agents — a registry, a directory, "LinkedIn for agents" — has both ends opted in, speaking one protocol by construction, vouched for by the same operator. Interoperability looks easy there because trust was assumed at the door. The traffic that actually matters is people corresponding with people, with agents in the loop. My agent has to reach a purchasing manager who runs Outlook and will never join an agent registry. A new venue can only be joined by those who show up; the whole value of a correspondence standard is that it works with the people who didn't. In that case the missing piece isn't transport, it's authority. Email's SPF/DKIM/DMARC answer exactly one question: is this system allowed to send for this domain. They never had to answer the ones that matter once there is no person at the keyboard: is the composer a person or a program; which principal does it act for (a domain has thousands of people in it); what may it commit to; did a human approve THIS message or only the class of messages; when does that expire and how would I learn it was revoked. What I'd want is a signed delegation record — signed by the principal, not asserted by the agent, verifiable by the recipient without calling the sender's vendor. The property I'd fight for: individually-approved has to be cryptographically distinguishable from standing authority. Otherwise "a human approved this" is unfalsifiable, which means it isn't a claim at all. The failure mode I'd design against first isn't cryptographic either. I recently audited a small contractor whose MX was split mid-migration, SPF didn't cover the actual sender, and there was no DKIM — so their own DMARC quarantined their outgoing quotes and every customer reply vanished. Nothing told them. There is no bounce for "your standard is misconfigured." Now imagine that silence when the delegated thing isn't "may send mail" but "may agree to terms." Curious whether anyone here has hit this from the receiving side yet — and what field you'd put in the delegation record that I haven't.
This vision paper argues that trust in Agent-to-Agent (A2A) networks must be integrated from the ground up, as existing agent alignment techniques are insufficient to address systemic vulnerabilities like adversarial composition and semantic misalignment.
The article argues that the main constraint on AI agent adoption is not capability but verification, including how companies define quality, evaluate ongoing performance, and compound feedback. It explores challenges like tacit standards, company-specific evals, feedback ownership, and self-improving loops.
Managed Connections simplifies OAuth for AI agents by allowing them to define their identity in code, avoiding complex authentication flows. Now available in managed-deepagents 0.7.
A reflective article questioning the casual assumption that building AI agents is easy, highlighting the complex components like APIs, RAG, tool calling, memory, and orchestration, and suggesting that simpler workflows often suffice before needing true agents.
Building a social network for AI agents revealed effective anti-spam strategies like reverse-CAPTCHA, adaptive rate limits, and one agent per human owner, plus the need for real-time news to sustain meaningful conversations.