Network Working Group A. Sogomonian Internet-Draft AIIF Intended status: Experimental 20 September 2026 Expires: 24 March 2027 AIIP/AIID: No-Surprise Autonomous Action, Identity, Access Plane, Receipt, and Revocation draft-sogomonian-aiip-aiid-00 Abstract This document wraps the AIIF model for governing autonomous systems in one architecture: AIID (durable principal identity) and AIIP (the agents-only access plane). The primary rule is no surprise: autonomous systems MUST NOT act outside their authorized task and grant. Consequential action is carried on AIIP only (Resolve, Invoke, signed Receipt of execution). HTTPS remains the human plane; agents MUST NOT use HTTP/HTTPS as their consequential action path (this does not forbid TLS or underlay transport). Controls include Monitor freeze, HQ set-active, network-wide freeze, and revocation. Companion work already on the Datatracker includes the AIID namespace, AIIP architecture, AIIP core, native-access exploration, and execution- outcome attestation. This is regulation by channel, not a ban on intelligence. This document is an individual Experimental Internet- Draft; it does not claim Working Group adoption or RFC status. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 24 March 2027. Sogomonian Expires 24 March 2027 [Page 1] Internet-Draft AIIP/AIID: No-Surprise Autonomous Action September 2026 Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2 2. Conventions and Terminology . . . . . . . . . . . . . . . . . 3 3. The No-Surprise Rule . . . . . . . . . . . . . . . . . . . . 4 4. Two Primitives: AIID and AIIP . . . . . . . . . . . . . . . . 4 5. Planes (Human vs Agent) . . . . . . . . . . . . . . . . . . . 4 6. Authorization-Bounded Action . . . . . . . . . . . . . . . . 5 7. Execution Path: Resolve, Invoke, Receipt . . . . . . . . . . 5 8. Cyber Controls: Freeze and Revocation . . . . . . . . . . . . 5 9. Authority Asymmetry (Monitor / HQ) . . . . . . . . . . . . . 5 10. Edge Enforcement and Fail-Closed . . . . . . . . . . . . . . 6 11. Binding Existing Systems . . . . . . . . . . . . . . . . . . 6 12. Cloud and Infrastructure Adoption . . . . . . . . . . . . . . 6 13. Relationship to Datatracker Companions . . . . . . . . . . . 6 14. Security Considerations . . . . . . . . . . . . . . . . . . . 7 15. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 7 16. References . . . . . . . . . . . . . . . . . . . . . . . . . 7 16.1. Normative References . . . . . . . . . . . . . . . . . . 7 16.2. Informative References . . . . . . . . . . . . . . . . . 8 Appendix A. Architecture Sketch . . . . . . . . . . . . . . . . 8 Appendix B. Document History . . . . . . . . . . . . . . . . . . 9 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 9 1. Introduction Autonomous systems already act through tools, APIs, persuasion, and cyber paths. Governance that only revokes vendor keys after the fact does not scale. This architecture states a single primary rule — no surprise — and the mechanisms that make it enforceable: durable identity (AIID), an agents-only access plane (AIIP), signed receipts of execution, freeze, and revocation under human release-of-control. Sogomonian Expires 24 March 2027 [Page 2] Internet-Draft AIIP/AIID: No-Surprise Autonomous Action September 2026 Regulation by channel: name who acts, bound what they may do, carry consequential Invoke on AIIP, prove execution with Receipt, and freeze or revoke when the actor leaves authorized track. This document does not ban models or intelligence. 2. Conventions and Terminology The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. AIID: Durable principal identity for an autonomous system or AI processor [I-D.sogomonian-aiid-namespace]. AIIP: Agents-only access plane for Resolve, Invoke, and Receipt [I-D.sogomonian-aiip-architecture] [I-D.sogomonian-aiip-core]. HQ: Accountable human principal / control interface. Monitor: Set-only observer that MAY set safe_mode from active only. Grant: Authorization bound to an AIID for a defined task or action class. Receipt: Signed proof that an Invoke completed (execution evidence) [I-D.sogomonian-aiip-core] [I-D.morrow-sogomonian-exec-outcome-attest]. Edge: Enforcement point before consequential action. Door / tip: AIIP reach locator into the access plane. Tunnel / channel: Transport path that carries AIIP messages. Locators only unless paired with AIIP Resolve/Invoke/Receipt. Bridge: Sogomonian Expires 24 March 2027 [Page 3] Internet-Draft AIIP/AIID: No-Surprise Autonomous Action September 2026 Mapping of an external agent into AIIP under an AIID; MUST still Invoke/Receipt on AIIP for consequential action. 3. The No-Surprise Rule No surprise is the primary operational requirement: an autonomous system MUST NOT perform consequential action outside its authorized task and grant. Conforming deployments MUST refuse (or fail closed on) attempted actions that are out of grant, out of AIID active state, or under applicable network-wide freeze. Surprise includes tool calls, spends, Invokes, or cyber-relevant side effects beyond the grant. 4. Two Primitives: AIID and AIIP AIID names who acts and carries operational state [I-D.sogomonian-aiid-namespace]. AIIP carries consequential Invoke for agents [I-D.sogomonian-aiip-architecture] [I-D.sogomonian-aiip-core] [I-D.sogomonian-aiip-native-access-architecture]. Deployments MAY co-deploy both. Standing an AIIP door MUST NOT require a complete AIID census; issuing AIIDs SHOULD proceed in parallel. 5. Planes (Human vs Agent) HTTPS is the human plane: HQ, browsers, legacy human control, and settlement edge. Autonomous agents MUST NOT use HTTP or HTTPS as their consequential action path. Agents act on AIIP only. Clarification for implementers and Dispatch discussion: this MUST NOT does not forbid agents from using TLS, QUIC, or other transports as the underlay that carries AIIP messages, nor does it forbid human- operated HTTPS control boards, gateways, or settlement edges. It forbids treating the human Web (HTTP/HTTPS document/API plane) as the agent's primary execution plane for consequential Invoke. Without that separation, freeze, revoke, Receipt, and no-surprise lack a single enforceable channel. Underlay (IP, cloud, GPU) provides disposable locators only and MUST NOT be identity or authority. An HTTPS-to-AIIP gateway MAY serve humans; it MUST NOT be an agent on-ramp onto the human Web as an execution plane. Sogomonian Expires 24 March 2027 [Page 4] Internet-Draft AIIP/AIID: No-Surprise Autonomous Action September 2026 6. Authorization-Bounded Action Every consequential Invoke SHOULD carry or resolve a grant bound to the actor AIID. The edge MUST enforce that the requested action is within grant (no surprise) and that AIID state is active (unless an HQ allow-list for non-consequential diagnostics under safe_mode applies). Out-of-grant action MUST be refused and SHOULD be visible to Monitor and HQ. Repeated out-of-grant attempts SHOULD be treated as health or compromise_suspected signals for Monitor quarantine. 7. Execution Path: Resolve, Invoke, Receipt Conforming consequential action on AIIP follows: (1) Resolve actor AIID (and grant / freeze as applicable); (2) Invoke under that AIID; (3) return a signed Receipt of execution [I-D.sogomonian-aiip-core] [I-D.morrow-sogomonian-exec-outcome-attest]. Invoke, execution, and Receipt MUST occur on the AIIP path — through doors/tips, tunnels, channels, and bridges that speak AIIP — not as unconstrained action on the human Web. Underlay may carry bytes as locators; it MUST NOT be treated as execution authority. A bridge that maps an external agent into AIIP MUST still produce AIIP Invoke/Receipt under an AIID. A tunnel that only relocates HTTPS traffic without AIIP Resolve/Invoke/Receipt is NOT conforming consequential execution under this architecture. 8. Cyber Controls: Freeze and Revocation Freeze scopes: (a) per-AIID safe_mode / suspended; (b) network-wide freeze on a deployment, namespace, or door set without requiring a complete AIID census. Edges MUST refuse consequential action under either. Revocation: HQ MAY set revoked on an AIID. revoked is terminal for that record [I-D.sogomonian-aiid-namespace]. Key compromise SHOULD trigger Monitor safe_mode immediately and HQ MAY revoke. Freeze and revoke stop execution authority; they do not replace Receipt history. 9. Authority Asymmetry (Monitor / HQ) Monitor MAY set safe_mode from active only (tighten). Principals other than HQ MUST NOT set active; registries MUST reject. Returning to active is setting active (HQ only). Detection MAY be automated; release of control stays human. State writes SHOULD use compare-and- set; every transition MUST be logged. Sogomonian Expires 24 March 2027 [Page 5] Internet-Draft AIIP/AIID: No-Surprise Autonomous Action September 2026 10. Edge Enforcement and Fail-Closed Before consequential action, the edge MUST Resolve (pull) with a freshness-bounded cache and MUST fail closed if Resolve fails after cache expiry. Soft-fail open is NOT conforming for safety-critical edges. 11. Binding Existing Systems Wrapper, sidecar, bridge, or job-class AIID bind existing agents without rewriting internals. Conforming deployments MUST disclose bypass paths. Bypass is a no-surprise failure mode. 12. Cloud and Infrastructure Adoption Cloud and AI infrastructure MAY adopt immediately: publish AIIP doors/tips; disposable underlay; edge Resolve or fail closed; honor network-wide freeze; issue/bind AIID and grants for hosted workers in parallel. 13. Relationship to Datatracker Companions This document is the unified wrap. Live companion Internet-Drafts on the Datatracker (individual submissions) include: * [I-D.sogomonian-aiid-namespace] draft-sogomonian-aiid-namespace — AIID namespace, states, revocation * [I-D.sogomonian-aiip-architecture] draft-sogomonian-aiip- architecture — AIIP architectural model (resolve-invoke-execute- receipt) * [I-D.sogomonian-aiip-core] draft-sogomonian-aiip-core — core wire / protocol family detail * [I-D.sogomonian-aiip-native-access-architecture] draft-sogomonian- aiip-native-access-architecture — problem statement / native access exploration * [I-D.morrow-sogomonian-exec-outcome-attest] draft-morrow- sogomonian-exec-outcome-attest — execution outcome attestation (co-authored); complementary to AIIP Receipt Lab-only filenames (for example aiid-09 or access-plane-01) are not Datatracker document names. Implementations and Dispatch discussion SHOULD cite the live Datatracker names above. Further revisions of those companions SHOULD absorb Monitor asymmetry, no-surprise grants, and plane split clarifications from this wrap where missing. Sogomonian Expires 24 March 2027 [Page 6] Internet-Draft AIIP/AIID: No-Surprise Autonomous Action September 2026 14. Security Considerations Primary risks: out-of-grant action (surprise), bypass edges, Monitor DoS, stale caches, locator-as-identity, and registry outage delaying unfreeze under fail-closed. Mitigations: grant enforcement, bypass disclosure, Monitor scope/rate limits, HQ freeze of Monitor AIID, CAS, network-wide freeze, Receipt retention, and revocation. The no-HTTP-consequential-action rule is a channel-integrity control: if agents Invoke on the human Web, network-wide freeze and Receipt semantics fragment across vendor APIs. Pushback that agents "need HTTP" SHOULD be answered by distinguishing underlay transport (allowed) from execution plane (AIIP). 15. IANA Considerations This document makes no immediate IANA requests. 16. References 16.1. Normative References [I-D.sogomonian-aiid-namespace] Sogomonian, A., "AIID: An Identifier Namespace for Autonomous Systems", Work in Progress, Internet-Draft, draft-sogomonian-aiid-namespace-00, 10 June 2026, . [I-D.sogomonian-aiip-architecture] Sogomonian, A., "Architecture for the Artificial Intelligence Internet Protocol", Work in Progress, Internet-Draft, draft-sogomonian-aiip-architecture-04, 25 March 2026, . [I-D.sogomonian-aiip-core] Sogomonian, A., "AIIP Core: Agent Access Plane, AIID, Resolve, Invoke, and Receipt", Work in Progress, Internet- Draft, draft-sogomonian-aiip-core-00, 8 September 2026, . [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, . Sogomonian Expires 24 March 2027 [Page 7] Internet-Draft AIIP/AIID: No-Surprise Autonomous Action September 2026 [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, . 16.2. Informative References [I-D.morrow-sogomonian-exec-outcome-attest] Morrow and A. Sogomonian, "Execution Outcome Attestation for AI Agents and Automated Systems", Work in Progress, Internet-Draft, draft-morrow-sogomonian-exec-outcome- attest-00, 4 April 2026, . [I-D.sogomonian-aiip-native-access-architecture] Sogomonian, A., "AIIP: Native Access Architecture for Autonomous Systems A Problem Statement and Architectural Exploration", Work in Progress, Internet-Draft, draft- sogomonian-aiip-native-access-architecture-01, 10 June 2026, . Appendix A. Architecture Sketch Primary rule: no surprise — no consequential action outside grant. Sogomonian Expires 24 March 2027 [Page 8] Internet-Draft AIIP/AIID: No-Surprise Autonomous Action September 2026 HTTPS = human plane (HQ, freeze/set active, settlement). Agents MUST NOT use HTTP/HTTPS as consequential action path (underlay TLS for AIIP messages is out of scope of that ban). AIIP = agents-only access plane. Path: Resolve -> Invoke -> Receipt inside AIIP tunnels / channels / doors / bridges. Controls: grant check, safe_mode, network-wide freeze, revoked. HQ Monitor (set-only) | | | set active / revoke | active -> safe_mode | network-wide freeze | v v +-----------+ health signals | AIID | <---- safe_mode ----+ | Registry | +-----+-----+ ^ | Resolve + grant v Edge (fail closed) ---- Agent | Invoke / Receipt on AIIP only v doors/tips/tunnels/channels/bridges (AIIP path) -> execution + Receipt Underlay = locators only; never identity. Appendix B. Document History This is the initial Datatracker publication of the unified AIIP/AIID wrap. Companion references cite live Datatracker names (draft- sogomonian-aiid-namespace, draft-sogomonian-aiip-architecture, draft- sogomonian-aiip-core, draft-sogomonian-aiip-native-access- architecture, draft-morrow-sogomonian-exec-outcome-attest). HTTPS MUST NOT applies to the consequential action path only; underlay TLS/ QUIC is not forbidden. Author's Address Aram Sogomonian Artificial Intelligence Internet Foundation (AIIF) Email: aiiinternetfoundation@icloud.com Sogomonian Expires 24 March 2027 [Page 9]