Algorand Launches AC2 To Keep AI Agents Off Users’ Keys
0
0

Algorand Foundation has launched AC2, an open protocol designed to let AI agents request sensitive actions without holding a user’s private keys or API credentials. The project, formally called the Agentic Communication and Control Protocol, went live on August 25 and is available as an open-source specification and reference implementation.
Algorand’s pitch is straightforward. Handing an AI agent your credentials is like giving a contractor a copy of your house key: convenient until it ends up somewhere it should not. AC2 is meant to work more like a doorbell. The agent asks for access, the user approves on their own device, and the key never leaves the owner’s control.
As AI agents begin to send payments, sign code, authorize APIs and manage digital operations, most existing chat-based approval flows offer little cryptographic proof of intent. Credentials often sit inside the agent’s runtime, creating a theft risk if that environment is compromised.
AC2 is built to close those gaps. When an agent needs to perform a signing operation, it sends a request to the user over a direct, end-to-end encrypted connection. The user reviews the action in a wallet or app and approves it with a hardware-bound FIDO2 passkey signature. The agent receives authorized proof of intent, not the credential itself.
The protocol combines three open standards: DIDComm v2.0 for message formatting, WebAuthn/FIDO2 for phishing-resistant authentication, and WebRTC DataChannels for peer-to-peer transport after the initial handshake.
It does not require a central message relay and does not need a blockchain to operate, though it can support on-chain use cases such as x402 payments.
Algorand says a basic implementation can be added with a plugin rather than a full stack rewrite. Potential uses include approving payments, signing git commits, authorizing API access and setting bounded delegation so agents can act only within signed limits.
The specification and GitHub repository are live, along with wallet pairing tools and a reference plugin for agent frameworks. Foundation executives have framed AC2 as an attempt to give agents enough authority to be useful without giving them the authority to act against a user’s interests.
For developers building agentic commerce and automation tools, the launch adds a new option for human-in-the-loop control that emphasizes credential isolation and verifiable intent. Adoption will depend on whether agent platforms treat hardware-bound approvals as a practical upgrade rather than an extra step.
Discover DailyCoin’s hottest crypto scoops right now:
Franklin Templeton Brings Tokenized US Treasuries to Asia via HashKey
Grayscale Zcash ETF (ZCSH) Set for NYSE Arca as ZEC Hits 8-Year High
0
0
Conecte com segurança o portfólio que você está usando para começar.



