At the AI for Good Global Summit in Geneva today, the International Telecommunication Union, the UN's agency for digital technologies, announced a new Focus Group on Trust and Identity for Humans and Agentic AI. Nothing about the group's structure is unusual for a standards body: a slate of technical, policy, and legal experts, a first meeting in Paris in November, a second in Geneva in January, a reporting line up into ITU's existing security standards study group. What is unusual is the sentence its co-chair used to describe the charter. "Identity tells us who is acting," said Amir Banifatemi, "and trustworthiness tells us how that actor can be expected to behave."

Two words, assigned deliberately to two different questions, are meant to anchor everything the group builds from here. That distinction is worth pausing on, because most of what has passed for AI trust infrastructure this year has quietly treated those two questions as one. Signed binaries, software bills of materials, certified dependencies, audit trails: all of it answers the identity question well. It tells an organization what a system is, where it came from, and who vouched for it. None of it, on its own, answers whether that system's behavior can be trusted going forward, or gives the person relying on it any way to act if the answer turns out to be no. A great deal of recent trust-building has been identity work wearing trustworthiness's name.

"Identity tells us who is acting, and trustworthiness tells us how that actor can be expected to behave."

The ITU's founding language does not make that substitution. Alongside identity and trustworthiness, the group names a third explicit goal: keeping AI agents subject to meaningful human control, particularly where the stakes are highest, in financial transactions and critical infrastructure. Control is a different kind of word than monitor, or verify, or audit. It points at an ongoing capacity for a person to act, not an account produced after the fact of what already happened.

Why the Sequencing Matters

A comparative study I ran on two interfaces for AI-assisted detection work found something relevant here: giving people a clearer explanation of how a system reached its output did less to align trust with actual understanding than giving them a way to act on the system directly. Explanation, however thorough, is still a form of identity: an account of what the system is and did. What closed the gap was agency: a lever, not just a window. Seeing that same distinction, unprompted, written into the founding charter of an international standards effort is a genuinely encouraging sign, and not a small one.

It is encouraging in part because standards bodies tend to build toward whatever they name at the outset. A group that opens by defining trust as a monitoring and verification problem will spend its first years producing better monitoring and verification. A group that opens by naming control as a first-class, co-equal deliverable, standing alongside identity rather than folded into it, has given itself a real chance of landing somewhere those earlier efforts didn't. Nothing has been built yet. The Focus Group's first meeting is four months away. But the direction a standards process points at the start tends to be the direction it arrives at, and this one is pointed at the right place.

There is reason for patience alongside the optimism. "Meaningful human control" is a phrase easy to state and hard to operationalize, and it would not be the first time a promising charter resolved, two years later, into a sign-off checkbox indistinguishable from the audit logs it was meant to improve on. Co-chair Debora Comparin's framing, that AI agents will soon negotiate, transact, and make decisions on our behalf, is itself a reminder of how much is riding on getting the operational definition right rather than just the founding language.

But founding language is where every framework starts, and this one started by refusing to let three different questions collapse into one. Paris in November, Geneva in January: two cities, two meetings, and a working group that will spend them arguing over what who, how, and control actually mean before anyone tries to build the thing. That is a slower start than a press release promising an already-shipped solution. It is also, for once, the right order to do the work in.

DH

Debra Hogue, PhD

Computer Scientist · Human-AI Collaboration Researcher · Oklahoma