AC2 (Agentic Communication and Control Protocol) is presented by the Algorand Foundation as an open-source, blockchain-agnostic standard for secure peer-to-peer communication between users and AI agents. According to its launch materials, it uses an end-to-end encrypted WebRTC connection so agents can request actions such as payments, git commits, or API authorizations; users approve them in a wallet or app, retain their private keys, and delegate only the resulting signature. The specification and reference implementation are said to be available on GitHub, but the supplied evidence is primarily first-party launch material and does not establish adoption, independent security validation, or whether the design fully implements least privilege beyond user-approved signing.
2026-09-24T19:23:22Z
The last trigger is arpanghoshal's 1-point, 0-comment companion post to his earlier safety-layer Show HN — adjacent category activity with no AC2 connection, confirming the case now only accumulates category noise. With zero adoption, validation, or follow-on engagement in the month since launch while the niche it targeted filled with independent purpose-built alternatives (Keydris, Pigeon, SwarmAuth, OpenShell, Talos, et al.), AC2's standardization window is closed; resolve superseded rather than reprice the same verdict a fourth time.
2026-09-24T18:29:04Z
evidence attached: hn.story.49834720 — shared external link with case evidence
2026-09-23T23:16:48Z
ScopeTrail, like SwarmAuth, Mati, and Keydris before it, is adjacent category activity — a concrete audit-receipts artifact for multi-hop delegation, but with no connection to AC2. The case's meaning has settled: AC2 itself has been stalled at first-party launch claims since its debut thread, and the accumulated evidence now functions as a ledger of a crowded, fast-moving agent-authorization category in which AC2 shows no adoption, validation, or follow-on engagement. Topic-level heat stays hot; this case stays cold.
2026-09-22T13:23:24Z
evidence attached: hn.story.49800563 — ScopeTrail provides a concrete artifact for auditing authorization across multi-hop agent and subagent delegation.
2026-09-19T17:24:22Z
Mati adds another adjacent coding-agent constraint project, but its announcement supplies neither enforcement details nor any connection to AC2. The surrounding security category continues expanding; AC2 itself still lacks evidence of implementation uptake or validated authorization guarantees.
2026-09-19T17:23:18Z
evidence attached: hn.story.49767823 — A released local guardrail layer for Claude Code and Codex is practical corroborating evidence for agent authorization and constraint controls.
2026-09-19T10:22:35Z
SwarmAuth adds a headline-level OAuth alternative to the surrounding authorization landscape, not evidence that AC2 works or is becoming a standard. The broader topic remains active, but there is no demonstrated expansion of AC2 implementations, adoption, or independent validation to warrant more attention.
2026-09-19T10:21:52Z
evidence attached: hn.story.49764838 — A released OAuth 2.1 artifact for agent swarms is relevant corroborating evidence for emerging standardized agent authorization layers.
2026-09-18T18:41:29Z
The latest Keydris listing repeats an already-known adjacent project without adding technical detail or implementation results. It does not change AC2’s standing: credential isolation and user-approved signing remain proposed building blocks, not demonstrated least-privilege enforcement or a standard gaining adoption.
2026-09-18T18:22:40Z
evidence attached: hn.story.49757543 — Keydris is a competing practical authorization or privilege-control approach for agents and materially contextualizes the emerging agent-security layer.
2026-09-15T16:33:01Z
The new action-safety project adds another adjacent announcement, but its headline and maker comment supply no enforcement design or implementation results that change AC2’s assessment. Activity around agent security is not independent corroboration of AC2’s practical least-privilege or standardization claims.
2026-09-15T16:23:37Z
evidence attached: hn.story.49714619 — The released action-safety layer materially bears on whether practical authorization and guardrails can constrain tool-using agents.
2026-09-15T15:33:15Z
The OpenShell attachment points toward formal verification as an adjacent design comparison, but the supplied evidence is only a headline, not the technical report or its results. It neither validates AC2 nor advances its standardization claim; broader agent-security activity should not substitute for AC2-specific evidence.
2026-09-15T15:22:44Z
evidence attached: hn.story.49713261 — NVIDIA's first-party report provides independent technical context on applying formal policy verification to agent control, materially bearing on practical agent authorization layers.
2026-09-14T12:37:01Z
The Keydris MCP demo announcement adds a concrete comparison for server-held credentials and policy-gated execution, not validation of AC2; its duplicate listing is not independent corroboration. AC2’s practical least-privilege and standardization claims remain untested by the supplied evidence.
2026-09-14T12:21:57Z
evidence attached: hn.story.49695517 — Duplicate coverage of the MCP authorization artifact, whose credential-isolation design bears directly on practical agent security boundaries.
2026-09-14T12:21:57Z
evidence attached: hn.story.49695295 — A concrete MCP artifact demonstrates server-side credential retention and policy-gated tool execution, materially contextualizing practical least-privilege agent authorization.
2026-09-12T18:22:05Z
The new discussion distinguishes scoped authority from habitual approval, but supplies no AC2 implementation result or independent validation. It sharpens the existing question—whether AC2 enforces bounded authority beyond user-approved signing—without advancing the protocol’s adoption or standardization case.
2026-09-12T18:21:53Z
evidence attached: reddit.post.1wejlur — It materially reinforces the open least-privilege hypothesis by framing scoped, expiring, evidence-bound authority as preferable to habitual approval prompts.
2026-09-10T13:33:10Z
The read-only database-access listing adds a narrow tooling comparison, but its title alone establishes neither enforcement properties nor practical least privilege. It provides no AC2-specific validation or adoption evidence; adjacent project announcements continue to expand the comparison set rather than advance this protocol’s standardization case.
2026-09-10T13:23:27Z
evidence attached: hn.story.49643099 — A concrete read-only database interface provides practical evidence for least-privilege authorization of agent tool access.
2026-09-10T01:27:18Z
Rayrun adds a maker-announced company-wide MCP gateway to the comparison set, not evidence of AC2 adoption or interoperable authorization. The supplied excerpt does not establish its enforcement properties, leaving AC2’s practical security and standardization claims unvalidated.
2026-09-10T01:22:25Z
evidence attached: hn.story.49636609 — An MCP gateway addressing credential leakage, tool visibility, data controls, and context bloat materially contextualizes the need for standardized agent authorization and governance.
2026-09-09T14:34:42Z
ALdía and MagicVault add comparison leads for permissioned MCP tools and credential isolation, but their title-only announcements establish neither least-privilege enforcement nor any AC2 integration. The adjacent tooling landscape continues to expand without corroborating AC2’s practical security or standardization prospects.
2026-09-09T14:24:00Z
evidence attached: hn.story.49626874 — Credential brokering that hides secrets from agents is a concrete implementation point for least-privilege agent authorization.
2026-09-09T13:23:23Z
evidence attached: hn.story.49625809 — A released self-hosted business engine with permissioned MCP tools is a concrete implementation datapoint for least-privilege agent authorization.
2026-09-09T10:26:50Z
AgentTrust adds a lead on MCP server trust assessment, which is distinct from enforcing scoped authorization; its title-only announcement supplies neither an evaluable grading methodology nor validation of AC2. The expanding adjacent-tool comparison set should not advance AC2’s security or standardization claims.
2026-09-09T10:22:41Z
evidence attached: hn.story.49624070 — An open MCP trust-scoring artifact provides independent practical context for whether agent-tool security and authorization layers can become usable.
2026-09-09T08:30:14Z
AER adds a title-level lead on hardware-backed identity and execution receipts, not evidence that those mechanisms deliver practical authorization or that AC2 is gaining adoption. The growing comparison set remains useful context but does not corroborate AC2’s security or standardization claims.
2026-09-09T08:22:20Z
evidence attached: hn.story.49622818 — A TPM- and WASM-receipt-based agent protocol is relevant independent evidence for emerging hardware-backed authorization and accountability layers.
2026-09-07T22:33:54Z
Keyclasp adds a practical credential-handling comparison, but keeping tokens out of model context is not equivalent to enforcing least-privilege execution. It supplies no independent validation of AC2’s security or standardization prospects; the growing comparison set should not be mistaken for AC2 adoption.
2026-09-07T22:22:56Z
evidence attached: hn.story.49603278 — Keyclasp is a concrete credential-isolation artifact that gives agents named secret access without exposing tokens in prompts or outputs.
2026-09-06T12:23:36Z
Pigeon’s refreshed discussion clarifies its credential-inheritance motivation and surfaces concrete questions about its custom credential format and key handling, making it a more inspectable comparison lead rather than validated security infrastructure. None of this independently supports AC2’s practical security or standardization claims.
2026-09-06T11:27:46Z
Pigeon adds a directly relevant signed-permission design for sub-agents to Scott’s comparison set, but the supplied title does not establish scope semantics or enforcement properties. This strengthens the broader design-pattern context without independently validating AC2’s security or standardization prospects.
2026-09-06T11:22:14Z
evidence attached: hn.story.49585209 — Pigeon is an independent first-party artifact applying signed, scoped authorization to sub-agents, directly bearing on practical agent permission protocols.
2026-09-06T08:23:41Z
Isthmus adds a named Go trust-kernel project to the comparison set, but the supplied title alone establishes neither its enforcement mechanisms nor security properties. This is another lead on the broader authorization-boundary pattern, not independent corroboration of AC2’s practicality or standardization prospects.
2026-09-06T08:22:08Z
evidence attached: hn.story.49584352 — A released trust-kernel implementation provides concrete evidence relevant to practical authorization and containment for tool-using agents.
2026-09-05T16:27:20Z
Praesidias adds another claimed pre-execution authorization tool, but the supplied title-only evidence offers no evaluable mechanism or security result. It expands the comparison set without corroborating AC2’s practical security or standardization prospects.
2026-09-05T16:22:43Z
evidence attached: hn.story.49577893 — This released pre-execution authorization tool is a concrete artifact bearing on practical least-privilege controls for tool-using agents.
2026-09-04T15:50:40Z
No fresh implementation, audit, adoption, or interoperability evidence has emerged for AC2; meanwhile, the broader authorization-boundary pattern is increasingly established through competing approaches. AC2 remains a specific, unvalidated standardization bid rather than the leading embodiment of that pattern.
2026-09-02T14:41:24Z
Authorizer adds a concrete, testable implementation of scope-attenuated agent delegation using established OAuth, JWT, and SPIFFE mechanisms, strengthening the broader least-privilege authorization pattern. It also further weakens AC2’s distinctiveness without validating AC2’s security, adoption, or standardization prospects.
2026-09-02T14:23:08Z
evidence attached: hn.story.49536219 — Authorizer’s released delegation and agent-authorization work materially supports the case that practical least-privilege identity layers are emerging for tool-using agents.
2026-09-02T10:30:42Z
SoulAuth adds another independent entrant around agent identity, further establishing the broader authorization-boundary design space while reducing AC2’s distinctiveness. Title-only evidence still does not validate AC2’s security, implementation quality, adoption, or standardization prospects.
2026-09-02T10:22:05Z
evidence attached: hn.story.49534146 — An independent agent-identity infrastructure project materially contextualizes whether practical authorization layers are emerging around agent interactions.
2026-09-01T10:31:44Z
AgentConnect adds another independent example of permission separation for shared agents, reinforcing the broader authorization-boundary pattern but not validating AC2’s implementation, security claims, or standardization prospects. The new evidence is too thin to advance the AC2-specific case.
2026-09-01T10:23:16Z
evidence attached: hn.story.49519923 — AgentConnect independently illustrates demand for shared agents with separate permissions, materially contextualising least-privilege authorization for multi-user agent systems.
2026-09-01T01:28:46Z
Arise adds only title-level thematic convergence around runtime identity and enforcement; it provides no inspectable implementation, result, adoption signal, or validation of AC2. Refreshed discussion remains repetitive, leaving AC2 an unvalidated protocol proposal within a broader authorization-boundary pattern.
2026-09-01T01:22:36Z
evidence attached: hn.story.49516465 — Arise adds a related runtime identity and enforcement perspective to the open question of practical least-privilege security for tool-using agents.
2026-08-31T14:53:34Z
The policy-algebra paper remains title-only evidence, adding thematic convergence around formal agent authorization but no evaluable result, implementation, adoption, or validation of AC2. AC2 therefore remains an unvalidated protocol proposal within a broader permission-boundary pattern.
2026-08-31T14:24:47Z
evidence attached: hn.story.49509877 — A policy-algebra paper materially contextualizes the open question of whether formal authorization layers can make tool-using agent execution safer and more composable.
2026-08-31T08:31:23Z
The new sandbox-vs-permission-model post is a generic argumentative piece with negligible engagement, reinforcing the same open question already established rather than adding new evidence about AC2 or competing architectures. The case remains a watched, unvalidated first-party design claim within a hot but undifferentiated agentic-security topic space.
2026-08-31T08:23:35Z
evidence attached: hn.story.49506753 — The artifact directly reinforces the open question of whether agent security requires explicit permission and authorization models beyond sandboxing.
2026-08-29T11:33:13Z
The OPA sidecar proposal adds another independent architecture for enforcing authorization between agents and tools, strengthening the broader permission-boundary pattern while making AC2’s specific standardization bid less distinctive. It still provides no independent validation of AC2’s security, implementation quality, or adoption.
2026-08-29T11:23:23Z
evidence attached: hn.story.49488952 — The proposed OPA sidecar pattern materially contextualizes practical chain-aware authorization for tool-using agents, albeit from a vendor perspective.
2026-08-28T23:24:18Z
The refreshed discussion adds only an anecdotal claim that some models may self-check risky shell operations; it neither validates AC2 nor strengthens the case for protocol-level authorization or adoption. AC2 remains an unvalidated implementation of a broader, independently converging permission-boundary pattern.
2026-08-28T17:36:11Z
The refreshed Talos discussion adds no technical analysis, implementation evidence, or adoption signal. It continues to support the broader permission-boundary pattern without validating AC2’s security or standardization claims.
2026-08-28T13:30:23Z
Talos provides independent convergence on placing a permission boundary between models and tools, making AC2 part of an emerging design pattern rather than an isolated proposal. It does not validate AC2’s cryptography, implementation quality, adoption, or standardization claim.
2026-08-28T13:24:43Z
evidence attached: hn.story.49477530 — A permission kernel between an agent model and shell is independent evidence for practical least-privilege controls on tool-using agents.
2026-08-27T15:45:10Z
The refreshed comments remain repetitive reactions to AC2’s blockchain framing, adding neither technical scrutiny nor evidence of implementation or adoption. The protocol remains a relevant but unvalidated first-party design claim.
2026-08-27T14:39:32Z
The refreshed discussion adds skepticism about AC2’s crypto and Algorand framing but no technical evaluation, implementation evidence, or independent adoption. The case remains a potentially relevant protocol artifact whose practical security claims are still unvalidated.
2026-08-27T14:33:12Z
grounded: converges/high — AC2 independently converges on Scott’s architecture of separating agent proposals from user-held authority and issuing bounded, signed authorization for consequ
2026-08-27T14:31:40Z
case created — This is a concrete first-party protocol artifact addressing agent authorization rather than general security commentary.