
A2A Extensions Need Governance, Not Just Names
Extensions preserve interoperability only when their semantics, ownership, and failure behavior remain understandable.
News
Product updates, research, and original films. Follow what we build and what we learn about systems of agents.

Extensions preserve interoperability only when their semantics, ownership, and failure behavior remain understandable.

Backward compatibility can preserve connectivity while removing the controls a newer relationship expected.

Agent interoperability and tool access solve different problems, so combining them does not create end-to-end trust automatically.

Knowing which runtime sent a request does not reveal who authorized it, who benefits, or who is accountable.

A short-lived user instruction can become durable authority when agents delegate work recursively.

Agents that plan dynamically should not receive every permission their workflow might eventually need.

Cryptographic workload identity helps answer which process is acting, but not whether its plan is legitimate.

An agent with access to several tenants can misuse valid authority when resource and principal context are mixed.

The final API sees a credential, but often loses the human request and delegation history that justified it.

Cancelling a credential is not enough when agents have cached plans, artifacts, and delegated work already in motion.