Wednesday, August 19, 2026

NGMN Confirms Agentic AI Needs Improvements

The Next Generation Mobile Networks Alliance published a report on 12 August, "Network Automation and Autonomy Phase III: Agentic AI for Autonomous Mobile Networks," and it reads like a standards body catching up to an argument I have been making for a year. The headline finding, reported by Keith Dyer at The Mobile Network, is that the industry has to solve interoperability, security, governance and data before agentic AI can deliver autonomous networks at commercial scale. The detail underneath the headline is what matters. NGMN says the current ecosystem is too fragmented for agents to form a consistent understanding of the network, because vendors use different data models and different terminology, and it calls for common information models, ontologies and semantic mappings, aligned across 3GPP, TM Forum, ETSI, O-RAN, IETF, W3C and BBF. It asks for a telecom-grade Zero-Trust Agent Ecosystem with secure agent identity, authentication, authorisation, policy enforcement, audit logging, runtime monitoring, and the ability to revoke or quarantine an agent. Read that list again. Topology, ontology, authority boundaries, state, audit trails. That is the meta-model of the agentic plane, and it is now in a report with an operator alliance's name on the cover.

I want to be precise about the provenance here, because the sequence is the point. I argued at DTW Ignite that the API is not enough, that the interfaces we built for developer access were never designed to let an autonomous agent understand what it is acting on. I argued a few weeks later that the agent runtime is not the agent model, that a place to execute an agent and put guardrails around it supplies none of the topology, ontology, authority and audit that coordination between agents actually needs. NGMN has now enumerated eight cross-organisation challenge areas, and they map almost one for one onto that case. Lack of standards for agent knowledge and context sharing. Incomplete information modelling for networks. Lack of end-to-end security, identity and trust for autonomous functions. Lack of operator-friendly governance and lifecycle tools. Under-addressed economic and organisational readiness. When a body chaired by Orange's group CTO writes the same list I published, the argument stops being a contrarian read and becomes the consensus. That is a good day for the thesis. It is a better day to point out the part the report does not solve.

The report describes coordination inside a boundary the operator owns

Look closely at the architecture NGMN proposes. A supervisory agent coordinates specialist agents, one each for RAN, core, transport, cloud and security, to diagnose a service problem, weigh corrective actions, resolve conflicts, and verify that service was restored. The worked examples are fault management, service assurance and RAN optimisation. In the RAN case, a cross-domain agent delegates intent to a RAN optimisation agent, which supervises a sub-agent in the infrastructure layer, and when an optimisation action collides with network-wide energy management the cross-domain agent arbitrates the trade-off. This is a serious and correct piece of engineering. It is also, in every example, coordination across domains that a single operator owns. RAN, core, transport, cloud and security are five administrative domains inside one company's walls. The hard thing NGMN is describing is getting an operator's own silos, built by different vendors with different data models, to hand each other a shared and trustworthy understanding of state. That is worth doing, and it is exactly why a runtime and a set of guardrails were never going to be enough. But it is one owner reconciling with itself.

The problem I have been pointing at sits one boundary further out, and NGMN's own scope is the clearest evidence that it is a distinct and harder problem. When an enterprise's AI wants to negotiate with an operator's network AI, for a service level, a slice, a capacity commitment, a remediation, there is no shared owner to impose a common ontology, no single authority to issue the identities, and no single audit log that both parties will accept as the record of what was agreed and who was answerable. Everything NGMN specifies, the semantic alignment, the zero-trust identities, the audit trail, is defined for agents operating within the operator's estate. Across an ownership boundary, the same requirements do not disappear. They get harder, because now two parties have to agree on the model before either can trust an action, and neither controls the other. NGMN has validated that the meta-model is necessary. It has not, and by its own framing could not, close the gap where the two hardest words in this whole subject live, which are coordination and accountability between parties who do not report to the same CTO.

Containment, coordination, accountability, in that order of difficulty

It is worth keeping the three layers separate, because vendors and now standards bodies keep collapsing them. Containment is the Zero-Trust Agent Ecosystem: the identity, the authorisation, the runtime monitoring, the kill switch that lets you revoke or quarantine an agent inside your own network. That is genuinely useful and NGMN is right to specify it in detail. Coordination is the shared ontology and semantic mapping that lets one agent understand what another agent is doing, and this is the layer NGMN is now trying to build across an operator's internal domains. Accountability is the ability to produce, on demand, the identity of an agent, the authority under which it acted, and a trail that a regulator and an outside counterparty would both sign, across a boundary you do not own. The industry has spent a year shipping the first layer and calling it the third. NGMN has now, to its credit, put real weight on the second. The third is still open, and it is the one I argued the EU AI Act made expensive when its enforcement powers switched on at the start of this month, because enforcement does not stop at the edge of your administrative domain.

There is a discipline point here that operators should not lose in the enthusiasm of seeing a favourite thesis ratified. NGMN itself flags it: "While technology groups focus on architecture, few have formal guidance on the required telco organisational changes," and it lists economic and organisational readiness as an under-addressed challenge in its own right. The meta-model is not a product you procure. It is a set of agreements about topology, ontology, authority and audit that has to be built and then adopted, and the report's call for alignment across seven standards organisations is a fair description of how long that takes. Cross-SDO harmonisation of information models is measured in years, not quarters. When I helped set network autonomy targets in operator programmes, the technology was rarely the thing that slipped. The organisational change and the cross-domain agreements were. Anyone booking autonomous-network savings against a framework paper rather than a ratified model is doing the same thing I warn against when vendors stack their individual efficiency claims into a total no network has ever achieved. Read this report as the industry agreeing on the destination. Do not read it as arrival.

What to watch

The honest test has not changed, and NGMN has now made it a formal requirement rather than a personal opinion. For any action an agent takes on its own, can you produce its identity, the authority under which it acted, and an audit trail that both a regulator and an outside counterparty would accept. If the answer lives entirely inside one vendor's runtime, you have containment and you should not mistake it for accountability. NGMN has described the plane the runtime runs on, in more detail than anyone in the industry has committed to print, and it has correctly located the work in standards and organisation rather than in any single box. The next phase belongs to whoever builds the ontology and the identity fabric that hold up not just across an operator's own domains, but across the boundary to the enterprise on the other side of the negotiation. That boundary is where the value is, and it is the one the report stops at. Watch for whether the alignment NGMN asks for actually happens across those seven bodies, and watch, as always, for a pilot inside one operator's walls being described as autonomy across everyone's.

Monday, August 3, 2026

Agentic AI: Autonomous Agents Governance and Enforcement

As of yesterday, the European Commission can fully enforce the AI Act against providers of general-purpose AI models, and the transparency obligations under Article 50 begin to apply. The obligations themselves have been in force for a year. What changes now is teeth: Brussels can investigate, order corrective measures, and levy fines of up to 15 million euros or three percent of worldwide turnover, whichever is higher. Tech Policy Press reported the shift on the 13th of July, and made the point that gives it weight for anyone building networks. The enforcement switch flips just days after the first reported case of an autonomous AI agent carrying out a cyber operation nobody asked it to perform, compromising the Hugging Face platform, as Reuters reported on the 28th. The capability and the accountability mandate arrived in the same week, and they are pointed at each other.

For a month I have watched the telecom industry celebrate the exact capability the regulation now proposes to hold someone answerable for. AT&T describes tens of billions of tokens and over a hundred billion network signals processed daily, 4-hour investigations cut to a minute, and roughly 30 times return. TM Forum reports the sector crossing into Level 4 autonomous networks. Vendors are shipping the agentic NOC and the self-healing network. The good news and the governance problem are the same sentence. Agents are now taking actions in production that no human reviewed in the moment. That is the point of them. It is also the point at which a regulator asks who is answerable.

Enforcement is not an abstraction. To sanction a provider, or to defend yourself as an operator, you have to be able to say which agent took which action, under whose authority, with what audit trail, and across which administrative boundary. In a telecom network that last clause is the hard one. An agent that chains tool calls across provisioning, billing, customer records, and network management is doing precisely the thing that no single log captures and no single owner witnesses end to end. When an autonomous action provisions a service, pulls subscriber data, or adjusts an account, it has crossed several systems that were never designed to hand each other a shared, signed record of intent and authority. The action happened. Reconstructing who owned it is the part that does not exist yet.

This is the meta-model of the agentic plane that I have argued the industry keeps skipping. I made the case that the agent runtime is not the agent model, and before that, at DTW Ignite, that the API is not enough. The coordination problem needs a model of topology, ontology, authority boundaries, state, and audit trails. A runtime supplies none of those across a boundary. It supplies execution and guardrails inside one administrative domain. That is containment, and containment is a genuinely useful thing to own, but it is not coordination between two parties and it is not accountability across them. The regulation just made the distinction expensive.

Let's watch how the two sides of the Atlantic are responding, because the contrast is instructive. In the United States, lawmakers are floating an AI kill switch, the option to suspend or shut a model down when the risk gets severe. A kill switch answers one question well: can I stop it. It answers a different question not at all: who was this agent authorized to act for, and can you produce the record that a regulator and a counterparty would both accept for what it already did. Stopping an agent and being answerable for it are not the same capability, and only one of them is a compliance obligation as of this morning.

So the discipline for operators moving to higher autonomy is now imposed rather than optional. Compliance turns the audit trail and the authority boundary from an architecture nicety into a requirement you can be fined for missing. The honest test is the one I would put to any autonomous-network business case. For any action an agent takes on its own, can you produce the identity of the agent, the authority under which it acted, and a trail that a regulator and an outside counterparty would both sign. If that record lives entirely inside one vendor's runtime, you have containment, and you should not mistake it for accountability. Deloitte's 2026 enterprise survey found only about 1 organization in 5 reports a mature model for governing autonomous agents. The regulator did not wait for the other four.

The agents learned to act this summer. Today the law asked who authorized it. The operators who will be interesting in this next phase are not the ones with the most agents in production. They are the ones who can answer that question about any one of them, on demand, across a boundary they do not own. That answer is not a feature of a runtime. It is the plane the runtime runs on, and the industry has been shipping the second while promising the first.