2026-10-11 17:19 UTC

AC2 Protocol’s maintainers claim their protocol supplies a practical security and authorization layer for tool-using AI agents, potentially standardizing least-privilege agent interactions.

state: resolvedheat: lowuncertainty: lowconvergesscott: highagentic-security agent-protocolsAC2 Protocol

What is this?

AC2 (Agentic Communication and Control Protocol) is presented by the Algorand Foundation as an open-source, blockchain-agnostic standard for secure peer-to-peer communication between users and AI agents. According to its launch materials, it uses an end-to-end encrypted WebRTC connection so agents can request actions such as payments, git commits, or API authorizations; users approve them in a wallet or app, retain their private keys, and delegate only the resulting signature. The specification and reference implementation are said to be available on GitHub, but the supplied evidence is primarily first-party launch material and does not establish adoption, independent security validation, or whether the design fully implements least privilege beyond user-approved signing.

Why it matters to Scott

AC2 independently converges on Scott’s architecture of separating agent proposals from user-held authority and issuing bounded, signed authorization for consequential actions. Its standardization bid creates a strong dated-receipts and design-comparison opportunity against the Agent Provenance Stack and Capability Tokens, although the supplied launch claims do not establish Scott’s fuller containment, policy-validation, or execution-attestation layers.
ip:framework.agent-provenance-stackip:concept.capability-tokensip:framework.decision-authority-infrastructureip:framework.agent-addressabilityradar:ietf-ai-agent-auth-draftradar:cloudflare-programmable-agent-walletsradar:concept.agentic-securityradar:concept.agent-interoperability
queries asked of Scott's wikis
  • agent capability security and least privilege
  • human approval for consequential agent actions
  • scoped credentials and delegated authorization
  • secure tool execution in coding agents
  • wallet-based identity and agent permissions
  • agent protocol standardization and interoperability

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

08-27 14:31 (minted)⭐ origin echo-reconstructedThe project presents AC2 as a missing security layer for AI agents.
AC2 Protocol on blog (echo) · attributed from hn.story.49464979 · published time unknown
—
08-27 13:55first on hacker news · published · lag ?AC2 Protocol: The missing security layer for AI agents
josephcecala
—
09-12 18:06first on r/artificial · published · lag ?Human-in-the-loop is not the same as human authority
arthaudm
—
08-27 13:55amplified on hacker newshn.story.49464979
josephcecala
peak 17 · 16 comments · 18% of case engagement
08-28 12:25amplified on hacker newshn.story.49477530
kurdman_007
peak 14 · 10 comments · 13% of case engagement
08-29 11:15amplified on hacker newshn.story.49488952
leanroute_ai
peak 1 · 0 comments · 1% of case engagement
08-31 07:38amplified on hacker newshn.story.49506753
Kkkkki
peak 3 · 1 comments · 2% of case engagement
08-31 13:56amplified on hacker newshn.story.49509877
gmays
peak 1 · 0 comments · 1% of case engagement
09-01 00:22amplified on hacker newshn.story.49516465
geoicons
peak 1 · 0 comments · 1% of case engagement
23 more amplifiers in ainews.case_chain
08-27 14:21our radar first saw it · lag ?discovery anchor: hn.story.49464979—

Evidence (30) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnAC2 Protocol: The missing security layer for AI agentsjosephcecala1716
🟧 echo.blog ⭐The project presents AC2 as a missing security layer for AI agents.AC2 Protocol——
🟧 hnShow HN: Talos – An AI agent with a permission kernel between model and shellkurdman_0071410
🟧 hnChain-aware (A2A) authorization using OPA as a sidecar patternleanroute_ai10
🟧 hnA sandbox is not a permission model for multiagent systemsKkkkki31
🟧 hnA Policy Algebra for Trust-Preserving Agentic AI Executiongmays10
🟧 hnArise – Agentic Runtime Identity Security Enforcementgeoicons10
🟧 hnShared Agents with Separate PermissionsDanielWen41
🟧 hnSoulAuth – Rust identity infrastructure for humans and AI agentsAziell20
🟧 hnShow HN: Authorizer – open-source auth for enterprise apps and agentslakhansamani9320
🟧 hnPraesidias – pre-execution authorization for AI agentssowainat110
🟧 hnIsthmus – a small Go trust-kernel for NanoClawsriyapaka10
🟧 hnPigeon, a signed Pass for what a sub-agent may dopigeonlabshq84
🟧 hnShow HN: Keyclasp – Let agents use tokens without putting them in promptsthecatalucci10
🟧 hnShow HN: AER – A subjectless protocol anchored in TPM 2.0 and WASM receiptsQuanxs10
🟧 hnShow HN: AgentTrust – A–F trust scores for MCP servers (50 graded, open source)gautamkishore20
🟧 hnALdía – Self-hosted business engine with permissioned MCP tools for agentsjonathanalemand20
🟧 hnShow HN: MagicVault – Let agents use your credentials without seeing themdas_vicky10
🟧 hnShow HN: Rayrun – one MCP gateway for the whole companylucgagan20
🟧 hnReadonly database access for your agentfilepod21
🟠 redditHuman-in-the-loop is not the same as human authority
artificial
arthaudm03
🟧 hnShow HN: Authorize MCP tool calls without giving agents the credentialsb4timer78
🟧 hnShow HN: Authorize MCP tool calls without giving agents the credentialsOsman_72831
🟧 hnWhat we have learned at OpenShell applying formal methods to control AI agentsalexwatson405407
🟧 hnShow HN: An open source safety layer for AI agent actionsarpanghoshal41
🟧 hnShow HN: Keydris, Sudo for AI AgentsOsman_72840
🟧 hnSwarmAuth – OAuth 2.1 for AI Agent Swarmswaspdrey20
🟧 hnShow HN: Built a local guardrail layer for Claude Codefennect20
🟧 hnShow HN: ScopeTrail – audit receipts for multi-hop agent delegationmrjimmy110
🟧 hnControl AI agents at the execution layer, not the promptarpanghoshal10

Interpretation history

Decision trace