top of page

The World Built Global Aviation Standards. AI Needs the Same.

  • Aug 9
  • 4 min read

Updated: 2 hours ago

In 1944, 54 nations came together to establish the rules that made global aviation possible. We now need the same collective effort to govern the age of AI.


News related to AI agents coming out of the summer 2026 cybersecurity conferences in Las Vegas, underscore the growing urgency of establishing a global treaty for agentic AI trust and security.


Eye-level view of a modern workspace with AI technology integration

The focus of the conference shifted from prompt injection vulnerabilities (making an agent act outside of model boundaries), to operating environment vulnerabilities - including execution environments, permissions, identities, connected apps and trust relationships. Specifically:


  1. Tool poisoning - where a trusted server is used to publish malicious software packages or data.

  2. Context poisoning - where hidden instructions are inserted into emails, Jira tickets and other payloads using stolen credentials.

  3. Excessive permissions - unnecessary privileges inherited from trusted systems.

  4. Cross-agent contamination - with a hacker inserting malicious code into an agent that then spreads to other agents, workflows and shared systems.

  5. Autonomous propagation - agent-enabled attacks and worms that can spread without direct human involvement.


At the center of many of these discussions is the Model Context Protocol (MCP), which enables agents to connect to external systems. Because MCP sits at the intersection of identity, permissions, data, and actions, it is increasingly viewed as a high-value target for attackers.


Platforms from Leading AI Providers Are Not Immune


Researchers found critical flaws in Anthropic, Google and OpenAI coding agents that enabled credential theft, remote code execution, and supply chain attacks.

If you are running a coding agent:


  • Review AI agent workflows for untrusted inputs (this can include user supplied documents, emails, calendar invites, folders) that can influence automated actions.

  • Restrict permissions granted to AI agents using least-privilege principles.

  • Isolate workflow stages and avoid sharing writable workspaces between agent executions.

  • Treat workflow-generated files as untrusted inputs unless explicitly validated.


In light of these disclosures, agent trust and security is becoming more important than ever.


Agent Identities - an Enterprise Solution, but not a Global Solution


Earlier this year, both Google and Microsoft launched separate identities for agents - Google Cloud Agent Identity and Microsoft Entra Agent ID - with granular access policies, governance controls, and audit capabilities for agent actions.


Separating agent identities from human identities begs the question as to who bears responsibility if an agent goes rogue?  Equally important is the question of jurisdiction: when an agent operates across countries on behalf of a global organization, which legal framework governs its conduct?


While separate agent identities address governance issues within the enterprise environment, they do not solve the trust problem outside of the enterprise and the liability issues in a global organization.


In the context of commercial agent applications acting on a global scale, we need globally recognized identities and a global legal framework.


The Case for a 'Chicago Convention' for Agentic AI


In an earlier post, I used a traffic analogy for thinking about agentic AI risk. However, traffic systems primarily address movement within national borders. When considering global AI agents operating across jurisdictions, aviation provides a far more compelling model.


Today, aircraft built by different manufacturers can safely land at airports around the world. Pilots from different countries communicate using standardized terminology. Air traffic controllers follow common procedures. Aircraft certifications, runway markings, navigation systems, and operating rules are globally recognized.


This system exists because nations agreed to cooperate on standards while

retaining sovereignty over their own airspace.


The organization that manages this framework is the International Civil Aviation Organization (ICAO), which came into being in 1947 as a result of the Chicago Convention in 1944, where the United States invited 54 nations to Chicago to meet from November 1 to December 7, 1944 to establish a common framework for international civil aviation.


ICAO does not replace national regulators. Instead, it establishes internationally recognized standards that member states adopt while maintaining authority over their own territories and enforcement mechanisms.


The Chicago Convention could serve as a blueprint for creating a global, independent framework for agentic AI by convening governments, industry experts, and academics to develop a common set of technical standards, legal principles, and trust mechanisms. Like the aviation system it would emulate, such a framework could evolve over time while providing the foundations necessary for safe and trusted global operations.


Global AI Co-opetition Generates Long-term Benefits


Economics tells us that a system of simultaneous cooperation and competition often generates superior long-term benefits.


Commercial aviation is an excellent example. Airlines compete fiercely on routes, pricing, service quality, and operational efficiency. Yet they cooperate on air traffic procedures, runway standards, communications protocols, safety requirements, and incident investigations.


The industry works because competition occurs on top of a foundation of shared standards.


Agentic AI should follow a similar model.


Nations can continue competing aggressively in AI innovation, research, infrastructure, and commercial applications while cooperating on the foundational standards that ensure trust, accountability, identity, and security.


Now is the time to build such a framework before a major global agent-related incident forces the issue.

 
 
bottom of page