News Brief

Uber details identity and provenance for AI agents

Historical record This story connects to a documented entry in the Agentic History timeline. MCP emerged as a common way to connect models and tools; this is an example of enterprises adapting identity and access controls around MCP-enabled agent tool calls.

Uber said it built an internal agent platform in early 2025 to compose, deploy, and operate production-grade agents at scale. Uber said it made its microservices “AI-ready” with MCP support over existing service APIs.

Uber said increasing agent autonomy created accountability gaps, including loss of originating user context across agent-to-agent handoffs. Uber said this complicates auditing, incident response, and policy enforcement.

Uber outlined extensions to its Zero Trust approach, including agent registration, cryptographic identity, and short-lived scoped tokens for each hop within an “AI Agent Mesh.”

Source: Uber


← All news · Timeline · Research blog