AI agents can perform weeks of engineering work in a single day, according to a new proof-of-concept from Deutsche Telekom and Vodafone. But both the rival telecom giants and the National Institute of Standards and Technology (NIST) converge on one warning: without a solid identity foundation, agentic AI collapses into a security nightmare.
Karsten Thon, senior business architect at Deutsche Telekom, calls identity questions “existential” as network infrastructure increasingly underpins critical public services. Who does an agent represent? What authority does it carry? How do organizations govern its actions? These identity access management concerns now function as the control plane for autonomous systems.
The two European competitors joined forces on a TM Forum Catalyst project focused on trusted agentic AI for access management. Their goal: demonstrate that AI can interpret contractual obligations continuously and convert them into enforceable network access policies automatically. Steffen Krippner, senior manager for OSS fulfillment at Vodafone, reports that a process normally requiring weeks of multi-vendor coordination now completes within one day.
The Catalyst solution draws on multiple large language models from Anthropic and Mistral to process documentation and decode complex legal texts into operational actions. Tallence, a telecom transformation specialist, built the digital identity management layer.
Yet Krippner emphasizes “governed intelligence” rather than unchecked autonomy. Four zero trust safeguards gate every AI-generated policy: a dry-run simulation, mandatory human approval for high-risk identity changes, controlled rollout, and negative testing that injects flawed data to expose decision-making weaknesses.
Meanwhile, NIST’s new paper strikes a cautionary tone about the broader ecosystem. Early agentic deployments repeat an old pattern: features ship first, security follows later. Model-only guardrails cannot yet solve these challenges. The agency warns that reverting to credential sharing, static tokens, or overly broad access grants resurrects vulnerabilities the IAM community spent decades eliminating.
NIST’s National Cybersecurity Center of Excellence plans to release resources supporting IAM adoption for software and AI agents, framing today’s standards as the foundation for tomorrow’s agentic protocols.













