%% You should probably cite draft-shang-agent-network-admission-01 instead of this revision. @techreport{shang-agent-network-admission-00, number = {draft-shang-agent-network-admission-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-shang-agent-network-admission/00/}, author = {Chao Shang and weiyu Jiang and Liang Xia}, title = {{Use Cases and Requirements for Network Admission of AI Agent Instances}}, pagetotal = 14, year = , month = , day = , abstract = {Artificial intelligence (AI) agents increasingly access enterprise resources, external models, tools, and other agents through managed networks. Application-layer authentication can authenticate an agent to a cooperating service, but it cannot by itself provide complete network admission control. In particular, application proofs are normally verified only after network reachability exists, cannot be consumed consistently by heterogeneous or legacy services, and do not reliably identify which Agent Instance originated traffic when multiple Agents share one host, IP address, or egress gateway. This document describes operational use cases, the resulting problem statement, and requirements for network admission of AI Agent Instances. It focuses on establishing a verifiable and time-bounded binding among an Agent Instance, its credential key, optional runtime evidence, and a Network Context on which the network can enforce reachability policy. This document does not define a new Agent-ID format, authentication protocol, OAuth grant, or routing extension.}, }