CHINA IS STANDARDISING THE AGENT LAYER

CHINA IS STANDARDISING THE AGENT LAYER. Identity, Discovery, Tool Invocation, and the Politics of Interoperability

Martin Novak
Synthocracy Institute
Research status: 4 September 2026

Evidence Boundary

This article distinguishes documented developments from analytical interpretation. [A] Empirical claims refer to official Chinese standards records, Chinese government and ministry materials, NIST publications, open-protocol governance records, and international standards activity available by 4 September 2026. [B] Analytical claims develop the Synthocracy Institute’s interpretation of what these developments may mean for institutional and geopolitical power.

Several qualifications are important. China’s GB/Z 185-2026 documents are national standardization guiding technical documents, not mandatory national standards. Chinese rules governing GB/Z documents state that they should not be made compulsory or administratively binding merely by being cited as standards. (SAMR) The series was nevertheless approved and published through China’s national standardization system, developed under Ministry of Industry and Information Technology guidance with participation from more than 70 key enterprises, and explicitly presented as infrastructure for large-scale industrial agent deployment. (SAMR)

The contrast drawn below between China and the United States is also analytical rather than absolute. Chinese standards are not produced by the state in isolation: Huawei, Alibaba, Ant Group, Xiaomi, China Mobile, Kuaishou, Lenovo, ZTE and many other companies participated in the work. (std.samr.gov.cn) Nor is the American approach purely private: NIST is explicitly coordinating federal activity, encouraging U.S. leadership in international standards bodies and researching identity and security infrastructure. (NIST)

The more defensible distinction is one of institutional sequencing and architecture.

The central question is not:

Which country has the smartest AI model?

It is:

Which technical and governance architecture will determine how large populations of intelligent agents identify one another, become discoverable, establish trust, exchange tasks, invoke tools, transact, and act across institutional boundaries?


The model race is hiding another race

The global AI competition is usually narrated through models.

Who has the strongest reasoning model?

Who has more compute?

Who controls the best chips?

Which laboratory reaches the next capability threshold?

Which country is closing the benchmark gap?

Those questions matter.

But a different contest is developing underneath them.

Imagine that millions of AI agents operate across companies, government agencies, factories, vehicles, robots, marketplaces and cloud platforms.

Before Agent A can ask Agent B to do anything, several questions arise.

Who is Agent B?

How can A verify that identity?

How does B describe what it can do?

Where does A discover B?

How do they authenticate?

Which interaction format do they share?

What tools can B invoke?

How is access controlled?

How is B suspended or revoked?

How can the transaction later be audited?

What happens when B wants to purchase something?

These questions are not questions about model intelligence.

They are questions about infrastructure.

On 22 May 2026, China formally published a seven-part national technical series addressing almost exactly this layer.

It is called:

GB/Z 185-2026 — Artificial Intelligence — Agent Interconnection.

And it may prove to be one of the most strategically important but least internationally discussed AI developments of 2026. (Openstd)


1. China did not publish one agent standard. It published a stack.

GB/Z 185-2026 consists of seven linked parts, all published on 22 May 2026 through China’s national standardization system. (Openstd)

PartFunction
GB/Z 185.1General architecture
GB/Z 185.2Agent identity code
GB/Z 185.3Identity management
GB/Z 185.4Agent description
GB/Z 185.5Agent discovery
GB/Z 185.6Agent interaction
GB/Z 185.7Agent tool invocation

Official Chinese interpretation describes them as one continuous technical sequence. Part 1 establishes the overall architecture. Part 2 addresses the encoding, assignment and management of agent identity codes. Part 3 covers registration, accounts, credentials and authentication. Part 4 defines capability descriptions and how they are registered, published and updated. Part 5 specifies discovery. Part 6 covers peer-to-peer, group and hybrid agent interaction. Part 7 specifies architecture, processes and data formats for invoking external tools. (digitalchina.gov.cn)

The sequence matters.

It is effectively:

IDENTITY → CAPABILITY DESCRIPTION → DISCOVERY → AUTHENTICATION → INTERACTION → TOOL INVOCATION → TASK EXECUTION

That is much more than a messaging protocol.

It is a preliminary architecture for machine participation.


2. China calls this an “era of collaboration”

The official Ministry of Industry and Information Technology interpretation is unusually explicit about the intended direction.

It describes agents as systems capable of perception, memory, decision-making, interaction and execution, and says that collaboration among “massive intelligent agents” across different systems, platforms and scenarios has become an important industrial trend. It identifies enterprise operations, manufacturing, urban governance and public services as current application areas and says deployment will extend further into physical-world systems including embodied intelligent robots. (digitalchina.gov.cn)

The same document explains why China believed a national framework was necessary.

Agents built by different vendors currently lack unified specifications for:

identity;

capability description;

discovery and matching;

interaction;

tool invocation.

The result, according to the official analysis, is high adaptation cost, weak collaboration efficiency and difficulty establishing trusted management. It explicitly mentions MCP and A2A as international protocols but says no unified international consensus yet exists and that those protocols do not fully meet the requirements of China’s developing agent industry. (digitalchina.gov.cn)

The Chinese answer is therefore not simply to wait for one private protocol to win.

It is to define a national technical framework covering the entire interconnection chain.

That is a strategic choice.


3. The architecture begins with identity

The most politically interesting part of the series may not be interaction.

It may be identity.

GB/Z 185.2 covers agent identity codes. GB/Z 185.3 covers identity management. Official guidance says identity codes are allocated through identity registration service providers using a hierarchical identifier system, with one identity code corresponding uniquely to one agent. After verification, the relevant registration service can create an account, allocate an identity code and issue credentials. The lifecycle includes update, suspension, reactivation and revocation. (digitalchina.gov.cn)

This is technically understandable.

Large-scale interoperability requires persistent answers to:

Who are you?

Can I verify you?

Are your credentials still valid?

Has your identity been revoked?

But identity systems are never purely clerical.

The identity layer determines which machine actors can become recognised participants in the network.

This is where agent interoperability begins to intersect with governance.

An agent that cannot be identified may not be trusted.

An agent that cannot obtain accepted credentials may not be allowed to interact.

An identity that can be suspended or revoked can be removed from participation.

The design of identity therefore creates part of the admission architecture of an agent ecosystem.

This does not mean that China’s national standards establish one central government registry for every agent. The official material refers to identity registration service providers, and the precise deployment topology can vary. (digitalchina.gov.cn)

But it does establish something conceptually important:

Agent identity is being treated as infrastructure rather than as an incidental application feature.

That is a major transition.


4. Identity is becoming the passport layer of machine action

Human economic and institutional systems rely heavily on recognised identity.

A company needs a legal identity.

An employee needs an organisational identity.

A website relies on domains and certificates.

A bank account belongs to a recognised account holder.

A payment requires recognised participants.

A licensed professional holds credentials.

Agents increasingly require analogous—not identical—technical structures.

An agent acting for a corporation may need to prove:

which agent it is;

which organisation it belongs to;

which human or institutional principal it represents;

which credentials it possesses;

which capabilities it claims;

whether those credentials are valid now.

This is exactly why NIST in the United States has independently elevated agent authentication and identity infrastructure into a major research and standards priority. Its 2026 AI Agent Standards Initiative specifically identifies agent authentication and identity as a research pillar needed for secure human-agent and multi-agent interaction. (NIST)

The convergence is striking.

The political systems are different.

The institutional routes are different.

The technical problem is shared:

Before machines can exercise delegated authority across institutional boundaries, other systems need a reliable way to know which machine is acting.


5. But identity is not authority

This point is essential for Synthocracy.

A globally interoperable agent identity system could solve a serious engineering problem while leaving a governance problem untouched.

Suppose Agent A has:

a valid identity code;

a valid credential;

successful authentication;

permission to invoke a purchasing tool.

None of those facts proves that Agent A possesses legitimate authority to make the purchase.

The distinction from our earlier analysis remains fundamental:

IDENTITY ≠ PERMISSION ≠ AUTHORITY.

Identity answers:

Who or what is acting?

Authentication answers:

Can that identity be verified?

Technical authorization answers:

Will this infrastructure permit the operation?

Authority asks:

Why is this agent legitimately entitled to make this consequential decision?

China’s standards architecture appears strong on identity, credentials, authentication and permission control. The official interpretation states that requesting and service agents should mutually authenticate before interaction and that access control and interconnection authorization should operate through registration, discovery, interaction and tool invocation. (digitalchina.gov.cn)

That is necessary.

It does not eliminate the need for a separate authority layer.

Indeed, the better machine identity becomes, the easier it becomes to ask the harder question:

This agent is definitely Agent A. But who authorised Agent A to exercise this power?


6. The next layer is capability description

After identity, China’s architecture asks what the agent can do.

GB/Z 185.4 covers agent description. The official interpretation says the standard specifies capability descriptions together with registration, publication and update mechanisms. (digitalchina.gov.cn)

This may look mundane.

It is not.

A machine-readable capability description changes an agent from a hidden software component into something other agents can reason about.

Instead of hard-coding:

Call Vendor X API.

an agent ecosystem can increasingly operate more like:

Find an agent capable of task X under conditions Y.

That changes the topology of software.

Capability becomes discoverable.

And discoverability creates a new form of machine-readable market visibility.

The important question is no longer merely:

Does the agent exist?

It becomes:

Can another agent know that it exists and understand what it offers?

That is where standardisation begins to shape economic opportunity.


7. Discovery is not a neutral layer

GB/Z 185.5 addresses agent discovery. Its purpose is to standardise how agents find other agents capable of performing required tasks. (std.samr.gov.cn)

The American open ecosystem is working on the same problem through different mechanisms. A2A enables agents to advertise capabilities and discover or collaborate with other agents across platforms, while the Linux Foundation’s 2026 DNS-AID project proposes decentralised agent and MCP-server discovery using existing DNS infrastructure. (linuxfoundation.org)

This looks like a technical implementation question:

registry or DNS;

central or decentralised;

Agent Card or another description schema.

But discovery has political consequences.

If future agents increasingly choose:

suppliers;

information sources;

service providers;

software components;

payment counterparties;

logistics partners;

other agents,

then discovery architecture influences who becomes visible to machine decision-makers.

This is the agentic analogue of a much older internet problem.

Search engines did not merely help people navigate the web.

Their ranking systems became infrastructure of visibility.

App stores did not merely list software.

Their admission and ranking rules influenced market access.

Marketplaces did not merely connect sellers and buyers.

Their search and recommendation systems shaped economic opportunity.

Agent discovery can acquire similar significance.

The discovery layer can become a market-access layer.


8. The politics begins before ranking

It would be easy to think that the political issue emerges only when a discovery service ranks agents.

The problem begins earlier.

Before ranking, somebody determines:

which metadata fields exist;

which capabilities can be represented;

which credentials count;

which trust indicators are recognised;

which registries are queried;

which agents are excluded;

how identity is verified;

how stale descriptions are treated;

whether foreign identities are interoperable;

whether local policy blocks certain agents before discovery.

Machine legibility therefore has an architecture.

An organisation may be perfectly legitimate to humans and effectively nonexistent to an agent because its capabilities cannot be represented in the accepted schema.

An agent may be highly capable but undiscoverable because it is outside recognised registries.

Another may become privileged because its metadata maps cleanly onto the discovery system.

This is why interoperability standards are not merely plumbing.

They determine what can enter the machine-readable field of possible action.


9. Interaction turns discovery into cooperation

GB/Z 185.6 goes beyond finding agents and standardises interaction modes. The official interpretation identifies peer-to-peer, group-based and hybrid interaction. (digitalchina.gov.cn)

This is where one agent becomes an institution of agents.

A single system can request assistance.

Several agents can coordinate.

A group can divide tasks.

Specialised agents can combine into a workflow.

The governance consequences follow quickly.

Who chairs the interaction?

Which agent has decision priority?

Can agents disagree?

Can one delegate to another?

Whose permissions travel?

Which messages are authoritative?

Can agents create coalitions or call additional participants?

Which interaction history is auditable?

The Chinese standard solves an interoperability layer.

It does not make these institutional questions disappear.

It makes them more urgent because standardised interaction lowers the cost of creating larger multi-agent systems.

This is one of the recurring dynamics of infrastructure:

Interoperability reduces friction. Reduced friction increases scale. Increased scale changes governance.


10. Tool invocation is the boundary between talking and acting

Part 7 may be the most consequential part operationally.

GB/Z 185.7 covers the architecture, processes and data formats through which agents invoke external tools. (Openstd)

This is the point where intelligent systems leave the world of agent-to-agent communication and begin changing external systems.

A tool can:

query a database;

write a record;

send a message;

deploy code;

control equipment;

execute a transaction;

book a service;

change a workflow;

trigger another system.

Tool invocation is therefore where interoperability becomes actuation.

The sequence now becomes:

IDENTITY → DISCOVERY → INTERACTION → TOOL → CONSEQUENCE

This is exactly the point at which Synthocracy’s authority questions become unavoidable.

Who authorised the tool invocation?

What mandate was active?

Was the agent allowed to delegate?

Could the tool distinguish the original principal from the immediate caller?

Could access be revoked?

Would a monitor see the entire trajectory?

Could the action be reversed?

A protocol can standardise the call.

It cannot by itself legitimate the consequence.


11. China’s five-domain architecture reveals the ambition

The official interpretation of GB/Z 185 defines five conceptual domains.

A User Domain initiates tasks and receives results.

An Agent Domain handles identity maintenance, descriptions, authentication, interaction and tool access.

A Management Service Domain provides identity, credential and authentication services.

An Interconnection Service Domain provides description management, discovery and message routing.

A Resource Access Domain provides access to tools and external resources. (digitalchina.gov.cn)

This is significant because it separates functions that early agent systems often collapse inside one application.

Identity becomes infrastructure.

Discovery becomes infrastructure.

Routing becomes infrastructure.

Tool access becomes infrastructure.

The agent itself becomes one participant inside a wider technical environment.

That is what makes the series more important than another API specification.

It sketches a system architecture for agent society—using “society” here only as an analytical metaphor for populations of interacting machine actors, not as a claim of machine personhood.


12. The seven-part stack is already becoming a nine-part stack

The most important update since the original May publication is that China has not stopped at Part 7.

On 23 July 2026, the national standards system initiated Part 8: Agent Audit, with a ten-month project cycle. The drafting organisations listed include the China Electronics Standardization Institute, Beijing University of Posts and Telecommunications and Qihoo 360. (std.samr.gov.cn)

Then, on 17 August, another project was registered:

Part 9: Agent Transaction.

The listed drafting organisations include the China Electronics Standardization Institute, Beijing University of Posts and Telecommunications, Alibaba Cloud, Ant Group and the China Financial Certification Authority. (std.samr.gov.cn)

This is a major signal.

The architecture is expanding from:

identity → description → discovery → interaction → tools

toward:

audit → transaction.

The movement is logical.

Once agents can identify each other, interact and invoke tools, the next questions are:

Can their activity be reconstructed?

and:

Can they exchange economic value?

That is a transition from agent interoperability to agent institutional infrastructure.


13. Part 9 may eventually matter more than Part 1

It is too early to know what the final Agent Transaction document will contain. It is still being drafted, and the official project record currently establishes the project, not its final technical architecture. (std.samr.gov.cn)

But the existence of the project is strategically interesting.

An agent that can communicate is useful.

An agent that can invoke tools is operational.

An agent that can transact becomes an economic actor in a technical sense.

It may be able to:

purchase compute;

purchase data;

pay for services;

settle with another agent;

negotiate commercial execution;

authorise microtransactions;

operate within a machine-readable budget.

The precise design remains unknown.

But the sequence is clear enough to watch:

IDENTITY → DISCOVERY → ACTION → AUDIT → TRANSACTION

At that point, the infrastructure begins to resemble the foundations required for a machine-speed economy.


14. China is simultaneously extending standards into sectors

The agent-interconnection series is not isolated.

China’s official standards system shows a wider portfolio under construction or already published around agent deployment.

A reference architecture for industrial agents, GB/Z 195-2026, was published in July. (std.samr.gov.cn)

A national guidance project for government intelligent agent systems is being drafted, with participation including the China Electronics Standardization Institute, Alibaba Cloud, Huawei and government-software organisations. (std.samr.gov.cn)

A separate project concerns industrial-agent skill interfaces and interoperability, with Beijing University of Aeronautics and Astronautics, Tsinghua University, CESI and industrial software companies among the participants. (std.samr.gov.cn)

Another national project addresses an application framework and interfaces for embodied agents, involving organisations including the Beijing Humanoid Robot Innovation Center, UBTECH, Unitree, Beijing Academy of Artificial Intelligence, Xiaomi robotics, Ant, Huawei Cloud and Baidu. (std.samr.gov.cn)

There is also a project for an agent model governance framework. (std.samr.gov.cn)

The pattern is increasingly difficult to dismiss as one technical experiment.

China appears to be building a horizontal agent layer and then extending it vertically into government, industry, devices and embodied systems.


15. This is not simply “the Chinese state imposing a standard”

That interpretation would be too crude.

More than 70 key enterprises participated in development of the initial GB/Z 185 series under MIIT guidance. (digitalchina.gov.cn)

The Part 1 drafting roster alone includes organisations such as Huawei, Ant Group, Alibaba Cloud, Xiaomi, Kuaishou, Lenovo, China Mobile, Volcano Engine, ZTE, Hikvision, Inspur, 360-related entities and multiple research institutions and telecom organisations. (std.samr.gov.cn)

Part 2 includes Huawei and Alibaba.

Part 6 includes Huawei and Ant.

Part 9 includes Alibaba Cloud, Ant Group and the China Financial Certification Authority. (std.samr.gov.cn)

The model is better understood as state-coordinated industrial standardisation.

Government establishes national strategic direction and standardisation mechanisms.

Technical institutes coordinate.

Companies and research organisations participate in design.

The resulting framework becomes available for industrial implementation and sectoral extension.

This is important because it means the standards may have both administrative legitimacy and practical industry input.


16. And the documents themselves are not mandatory

This distinction also matters.

GB/Z is the Chinese designation for a national standardization guiding technical document. Chinese rules state that such documents should not acquire mandatory or administrative force merely through citation. (SAMR)

So describing GB/Z 185 as if Beijing had legally ordered every Chinese AI agent to use one protocol would be inaccurate.

Standardisation can matter without legal compulsion.

A technical document can influence:

government procurement;

platform design;

conformity testing;

industry integration;

vendor expectations;

sectoral specifications;

future standards;

training and certification;

international standards proposals.

Standards can become powerful because actors coordinate around them, not only because law commands compliance.

TCP/IP did not become important because one government prosecuted people for using another networking stack.

USB did not need criminal law to acquire enormous infrastructure power.

Interoperability creates its own incentives.

The question is therefore not simply:

Is GB/Z 185 mandatory?

It is:

Will enough important systems build around it that compatibility becomes valuable or necessary?

That remains an empirical question.

It should be watched rather than assumed.


17. The American architecture is developing in the opposite direction

The United States is also building the agent layer, but institutional sequencing looks different.

On 17 February 2026, NIST launched its AI Agent Standards Initiative around three pillars:

facilitating industry-led standards;

fostering community-led protocols;

advancing research into agent security and identity.

NIST explicitly says it aims to help create an interoperable and secure agent ecosystem while maintaining U.S. technological leadership and influence in international standards bodies. (NIST)

But much of the operational protocol layer emerged first from technology companies and open-source ecosystems.

Google created A2A, which later moved to Linux Foundation governance. By April 2026 the project reported support from more than 150 organisations and integration across major cloud platforms including Google, Microsoft and AWS. (linuxfoundation.org)

Anthropic created the Model Context Protocol, which subsequently became part of the Linux Foundation’s Agentic AI Foundation alongside Block’s goose and OpenAI’s AGENTS.md. (linuxfoundation.org)

The Linux Foundation has also launched DNS-AID for decentralised discovery of agents and MCP servers through existing DNS infrastructure. (linuxfoundation.org)

So the stylised American sequence looks more like:

COMPANY INNOVATION → OPEN PROTOCOL → ECOSYSTEM ADOPTION → FOUNDATION GOVERNANCE → STATE FACILITATION / INTERNATIONAL STANDARDISATION

China looks more like:

STATE STRATEGY → NATIONAL TECHNICAL FRAMEWORK → INDUSTRY CO-DESIGN → DEPLOYMENT → SECTORAL EXTENSION → INTERNATIONAL MUTUAL RECOGNITION

These are analytical ideal types.

Reality on both sides is more mixed.

But the difference is useful.


18. America is betting partly on protocol competition

The American approach carries a familiar logic.

Let developers experiment.

Allow protocols to emerge.

Let companies adopt the ones that work.

Move important protocols into neutral governance.

Build industry coalitions.

Allow de facto standards to develop through usage.

Then connect successful standards to government coordination and formal international bodies.

This can move quickly.

A2A went from a Google-originated protocol to Linux Foundation governance and broad enterprise support in roughly a year. (linuxfoundation.org)

The Agentic AI Foundation has rapidly accumulated companies across financial services, infrastructure, enterprise software and government-adjacent organisations. (linuxfoundation.org)

The advantage is adaptability.

The risk is fragmentation.

Several overlapping mechanisms can compete around:

identity;

agent cards;

discovery;

authentication;

tool access;

payments;

capability schemas;

audit.

NIST’s initiative explicitly identifies fragmentation and lack of interoperability as a problem it wants to reduce. (NIST)

China’s approach begins from the opposite premise:

define more of the common architecture early.


19. Neither system is purely centralised or decentralised

It is tempting to write:

China = centralised.

America = decentralised.

That is analytically lazy.

China’s standards involve extensive corporate participation.

America’s ecosystem increasingly relies on neutral foundations, NIST coordination, cloud-platform concentration and large technology companies capable of making protocols de facto defaults.

A decentralised protocol ecosystem can still be dominated by a small number of infrastructure providers.

A government-coordinated national standard can still allow multiple implementations and private competition.

The more interesting distinction is therefore:

Where does coordination happen, and which institutions acquire the ability to define the common layer?

In China, national standardisation is an explicit coordination venue.

In the U.S., protocol projects, open-source foundations, hyperscalers, industry consortia, NIST and international standards organisations form a more distributed coordination environment.

Both architectures produce centres of power.

They simply place them differently.


20. Standards can become constitutional infrastructure without being law

This is where Synthocracy enters.

A constitution determines, among other things, which actors exist, which powers they possess and how they interact.

Technical standards do not perform this function in the same legal or political sense.

But at the machine level, they can perform an analogous infrastructural function.

An agent standard can define:

what counts as an identity;

what metadata describe a capability;

how another agent discovers it;

how authentication works;

what messages are valid;

how a tool is invoked;

which lifecycle states exist;

how an identity is suspended;

how an interaction can later be audited.

These decisions shape the space of possible machine action.

They can therefore become part of what we might call, analytically, the constitutional infrastructure of agent ecosystems.

Not because protocol engineers become legislators.

Because architecture determines which actions are easy, difficult, visible, attributable or impossible.


21. Whoever defines identity influences membership

Suppose future international agent commerce requires accepted machine identities.

A Chinese enterprise agent carries one type of identity.

An American agent another.

A European public-sector agent another.

A bank requires stronger credentials.

A government system allows only agents from recognised identity providers.

A global marketplace accepts several trust frameworks.

The resulting question is not trivial:

Which identities are mutually recognised?

This resembles existing problems in:

digital certificates;

payments;

telecommunications;

electronic signatures;

cross-border identity;

domain names.

But agents add delegated autonomy.

An identity is not simply proving that a user exists.

It is enabling a machine actor to enter a system and potentially act.

The politics of identity standards may therefore become the politics of agent membership.


22. Whoever defines capability descriptions influences legibility

The same logic applies to capability schemas.

Suppose the standard agent description has fields for:

service category;

input types;

output types;

price;

security level;

jurisdiction;

trust score;

certification;

latency;

model family;

permission requirements.

What if an important property is absent?

What if one ecosystem encodes regulatory status and another does not?

What if one registry represents provenance and another prioritises benchmark performance?

Machine-readable categories are not simply descriptions of reality.

They determine what automated systems can easily compare.

The metadata model can therefore shape:

which features become salient;

which agents are considered substitutable;

which risks are visible;

which suppliers become machine-readable.

This is a deeply Synthocratic problem.

The schema determines part of what the machine can see.


23. Whoever defines discovery influences market access

Once capability becomes machine-readable, discovery can become economically decisive.

Future procurement agents may not search the open web as humans do.

They may query:

trusted registries;

A2A directories;

DNS-based agent records;

platform marketplaces;

private enterprise registries;

national infrastructure.

If those discovery systems become default routes to economic activity, machine visibility becomes a condition of trade.

A supplier could be legally present, financially sound and attractive to human buyers while effectively absent from autonomous procurement because no recognised agent or machine-readable capability representation exposes it to the discovery layer.

This is closely related to a wider transition already visible in agentic commerce:

human-readable presence is becoming insufficient; systems increasingly require machine-readable and eventually machine-executable presence.

Agent standards may determine the grammar of that presence.


24. Whoever defines tool invocation influences actuation

Tool standards have still greater consequence.

Discovery determines who can be considered.

Tool invocation determines what can happen.

A tool schema can define how agents:

submit data;

invoke business processes;

commit transactions;

control devices;

trigger workflows;

request restricted operations.

That means tool interoperability is not simply another convenience layer.

It is infrastructure of delegated execution.

Security mechanisms matter.

Authority semantics matter.

Audit context matters.

Revocation matters.

The risk is not merely that an incompatible tool fails.

The risk is that a highly interoperable tool works perfectly for an actor whose authority was never properly established.

This is why the global agent-standard race cannot be understood only through interoperability.

We need governable interoperability.


25. China itself is moving toward audit

The planned Part 8 is particularly interesting from this perspective.

The existence of Agent Audit as the next extension acknowledges that interconnected agents create a traceability problem. (std.samr.gov.cn)

Identity establishes who the agent is.

Interaction establishes what it exchanged.

Tool invocation establishes how it reached external resources.

Audit potentially establishes how activity can later be reconstructed.

That is precisely the direction explored in our previous article:

EVENT PROVENANCE → DECISION PROVENANCE → AUTHORITY PROVENANCE.

The open question is how far technical audit standards will go.

Will they record only events?

Or will they preserve:

principal;

delegated mandate;

authority changes;

human approvals;

cross-agent provenance;

transaction context?

The final Part 8 document is not yet available, so it would be premature to claim an answer.

But this should become a major monitoring point for Synthocracy Institute.


26. Part 9 turns standards into geopolitical economics

The same is true of Agent Transaction.

If China succeeds in creating widely adopted standards linking:

identity;

discovery;

interaction;

tool invocation;

audit;

transaction,

then it will possess more than an agent protocol.

It will possess a candidate architecture for a machine-native commercial stack.

This does not mean it will dominate global commerce.

It does not mean American protocols will lose.

It does not mean one standards family will control everything.

But it changes the geopolitical object of competition.

The contest is no longer:

Whose model answers better?

It becomes:

Whose agents can most easily participate in real institutions and markets?

And eventually:

Whose interoperability rules become normal outside the country that created them?


27. China is explicitly internationalising the question

China is not presenting agent interconnection as a purely domestic project.

On 17 July 2026, the Cyberspace Administration of China released a Global Cooperation Initiative on Agent Trust, Interconnection and Interoperability.

The initiative calls for research into agent identity recognition and collaborative trust, cross-platform interoperability, open and non-discriminatory international standards, compatibility at interface, protocol, semantic and process levels, and shared infrastructure for what it describes as an intelligent internet. It also calls for applications across science, industry, consumption, public welfare and social governance, while addressing data protection and cross-border data flows. (CAC)

This is important.

China is not simply saying:

Use our domestic protocol.

Its official position is more sophisticated:

build domestic technical architecture while pushing international interoperability and mutual recognition.

Whether international actors adopt Chinese technical proposals is another question.

But the ambition is clearly global.


28. Standards are part of China’s wider AI diplomacy

The agent initiative arrived in the same WAIC period in which China announced broader proposals for international AI cooperation, ethics governance and the new World Artificial Intelligence Cooperation Organization. Chinese official materials emphasise open-source ecosystems, shared compute, standards cooperation and AI capacity building for developing countries. (Xinhua)

This creates a plausible international strategy.

China can export not merely models.

It can offer:

open models;

domestic compute technology;

industrial AI systems;

robotics;

training;

standards;

agent infrastructure;

government deployment experience.

For developing economies building new AI infrastructure rather than retrofitting old systems, standards can matter greatly.

Adopting one architecture early can produce long-lived path dependence.

This is not uniquely Chinese.

American technology standards have shaped global computing for decades.

The important point is that agent interoperability is becoming another field of standards diplomacy.


29. The race is not only China versus America

A bilateral framing would still be incomplete.

IEEE has active 2026 projects for:

Agent Description, Discovery, and Registry interoperability;

Agent-to-Agent interoperability in industrial intelligent agent systems;

Agent-to-Tool and Data Access interfaces. (IEEE Standards Association)

ETSI is studying security for inter-AI-agent communications. (ETSI Portal)

ISO/IEC JTC 1/SC 42 remains the primary international AI standardization committee, with a broad 2026 work programme across governance, conformity assessment and human-machine interaction. (ISO)

The Linux Foundation hosts a rapidly expanding open agent-protocol ecosystem.

China has a national technical stack.

NIST is attempting to foster U.S. industry leadership while influencing international standards.

So the future is unlikely to be:

Chinese standard OR American standard.

It may instead consist of several overlapping layers:

formal international standards;

national frameworks;

open protocols;

vendor implementations;

sector-specific profiles;

private trust networks.

The decisive question will be which layers interoperate.


30. Interoperability may become geopolitical compatibility

Consider three future agents.

A Chinese industrial agent uses a GB/Z-derived identity and discovery architecture.

An American enterprise agent uses A2A and MCP.

A European agent operates under a regulated trust framework and an international IEEE or ISO profile.

Can they transact?

If yes, which layer translates identity?

Which trust provider is recognised?

Which capability description wins?

Which audit context survives translation?

Whose authorization semantics apply?

Where is the data stored?

Which jurisdiction governs the transaction?

Can one ecosystem revoke an identity recognised by another?

Does a foreign agent need to register locally?

Interoperability therefore moves beyond syntax.

It becomes a question of institutional compatibility.

That may be one of the defining governance problems of the late 2020s.


31. There are at least four possible standardisation outcomes

FORESIGHT — These are scenarios, not predictions.

One possibility is convergence. A2A, MCP, Chinese standards, IEEE work and other protocols converge around common identity, discovery and interaction concepts, with translation layers making national origin relatively unimportant.

A second possibility is layered interoperability. Different ecosystems retain their own identity and governance layers but share transport and capability-description standards. Agents interact across gateways much as different payment and telecom networks interoperate today.

A third possibility is bloc formation. Distinct trust and identity ecosystems emerge around geopolitical and regulatory regions, with partial interoperability between them.

A fourth possibility is platform dominance. Formal national standards matter less than whichever cloud, marketplace, operating system or agent platform obtains sufficient scale to establish de facto defaults.

All four remain plausible.

The relevant policy task is not to pick one prematurely.

It is to identify the signals that would indicate which architecture is emerging.


32. The most important signal will not be publication. It will be adoption.

China has already published GB/Z 185.

That does not tell us whether it becomes infrastructure.

The Institute should now monitor:

whether Chinese cloud providers implement the identity architecture;

whether major agent platforms expose GB/Z-compatible descriptions;

whether government procurement references the series;

whether conformity-testing ecosystems emerge;

whether agent identity codes appear in production systems;

whether Part 8 audit and Part 9 transaction reach publication;

whether sectoral standards reference the interconnection layer;

whether Chinese protocols obtain implementation outside China;

whether international standards incorporate compatible concepts;

whether A2A/MCP gateways into GB/Z environments become common.

Standards power comes from implementation.

A PDF cannot govern an ecosystem.

An adopted interface can.


33. We should watch the identity registrars

A particularly important subfield may be almost invisible today:

agent registration infrastructure.

The official Chinese interpretation says agent identity codes are allocated through identity registration service providers. (digitalchina.gov.cn)

If the architecture scales, those services could become strategically important.

They may determine:

identity issuance;

verification;

credential management;

suspension;

reactivation;

revocation.

That makes them analogous, in limited technical respects, to combinations of:

identity providers;

certificate authorities;

registries;

trust-service providers.

Who operates them?

How many exist?

Can they recognise foreign agents?

What evidence is required?

How is compromise handled?

Can one provider revoke another’s trust?

What happens across jurisdictions?

These questions deserve dedicated research.

The identity registry may become one of the hidden control points of agent society.


34. Discovery services deserve the same scrutiny

The same applies to discovery.

Who runs the discovery service?

Is it decentralised?

Can agents publish their own descriptions?

Are descriptions verified?

Who determines trust scores?

Can one agent pay for prominence?

Does performance history affect ranking?

Are sanctioned or prohibited agents filtered out?

Can governments mandate exclusion?

Can companies prefer their own ecosystem?

A future agent discovery layer could combine attributes of:

DNS;

Google Search;

an app store;

a procurement marketplace;

a trust registry.

That is an extraordinary concentration of potential functions.

It should be governed accordingly.


35. Standardisation can reduce power as well as concentrate it

There is also a strong positive case for interoperability.

Without standards, a few dominant platforms may control closed agent ecosystems.

An enterprise that adopts one platform becomes locked into its:

identity;

tools;

agent directory;

permission model;

logs;

payments.

Open interoperable standards can reduce that power.

A portable agent identity could make switching easier.

Standard capability descriptions could prevent vendor lock-in.

Open discovery mechanisms could reduce dependence on one marketplace.

Standard audit records could improve accountability.

Shared tool interfaces could let smaller providers compete.

A2A’s Linux Foundation governance explicitly presents vendor neutrality and reduced lock-in as goals. (linuxfoundation.org) China similarly describes GB/Z 185 as a way to reduce adaptation costs and allow heterogeneous agents to be managed, scheduled, combined and reused across systems. (digitalchina.gov.cn)

Standards therefore have a double character.

They can create gatekeepers.

They can also weaken gatekeepers.

The governance question is not whether standards are inherently centralising.

It is who controls the standard, implementation, registry and trust layer after adoption.


36. The standard should not silently become the authority model

One danger deserves special attention.

If identity, authentication and permission are standardised successfully, institutions may begin to assume that a technically compliant agent is also legitimately authorised.

That would recreate the problem examined in Permission Is Not Authority.

A compliant agent may have:

valid identity;

valid credentials;

successful discovery;

valid interaction;

valid tool invocation.

And still act beyond its institutional mandate.

The interoperability architecture should therefore leave room for authority context.

Eventually, agent transactions may need to preserve:

principal;

delegated mandate;

scope;

purpose;

limits;

expiry;

revocation;

decision discretion.

Otherwise the standards ecosystem may become exceptionally good at answering:

Can Agent A perform operation X?

while remaining weak at answering:

Why is Agent A entitled to decide that operation X should occur?

That distinction is precisely where technical standardisation meets governance.


The Synthocracy Agent Interoperability Governance Test

This preliminary diagnostic is intended for standards, protocols and agent ecosystems rather than individual AI models. It is not a conformity-assessment instrument.

1. Identity — Who counts as an agent? Does the architecture provide distinct, verifiable agent identity, lifecycle management and revocation, and who controls issuance or recognition of that identity?

2. Principal — On whose behalf does the agent act? Can the infrastructure distinguish the immediate machine identity from the human or institution whose authority ultimately initiated the action?

3. Capability Description — What can become machine-legible? Which attributes can an agent publish about itself, who verifies them, and which important characteristics cannot be represented?

4. Discovery — Who becomes visible? Which registries, directories, protocols or ranking mechanisms determine which agents can be found, and can technically or politically excluded actors disappear from the machine-readable choice set?

5. Authentication and Permission — What allows interaction? How are trust, credentials and access controlled across vendors and jurisdictions, and can credentials be suspended or revoked rapidly?

6. Delegation — Does authority survive interoperability? When Agent A delegates to Agent B across systems, is original principal and scope preserved, narrowed, or lost?

7. Tool Invocation — Who can cause external effects? Does interoperability preserve enough authority context when an agent moves from communication into execution?

8. Audit — Can the cross-system trajectory be reconstructed? Are identity, interaction, delegation, tool calls, human interventions and state changes correlated across organisational boundaries?

9. Transaction — How does economic authority travel? If agents can buy, sell or transfer value, can spending authority, counterparties, limits, consent and revocation remain attributable to the original mandate?

10. Contestability — Who can challenge the infrastructure itself? If identity is revoked, discovery suppresses an agent, a trust score is wrong or a transaction is blocked, what route exists for review, correction and remedy?

The governing question is:

Does interoperability merely make agent action possible, or does it make agent action governable?


37. The two emerging operating systems of agent power

We can now restate the U.S.–China comparison more precisely.

Analytical model: United States

FIRM-ORIGINATED INNOVATION

OPEN PROTOCOLS

FOUNDATION / COMMUNITY GOVERNANCE

ENTERPRISE ADOPTION

NIST FACILITATION

INTERNATIONAL STANDARDS LEADERSHIP

Analytical model: China

NATIONAL AI STRATEGY

STATE-COORDINATED TECHNICAL STANDARDISATION

INDUSTRY CO-DESIGN

COMMON NATIONAL ARCHITECTURE

SECTORAL DEPLOYMENT

INTERNATIONAL INTEROPERABILITY / MUTUAL RECOGNITION

Neither chain should be mistaken for literal command hierarchy.

They are institutional patterns.

And both are trying to solve the same emerging problem:

how to move from isolated AI systems to an interoperable population of acting agents.


38. The deeper competition is over the default architecture

This changes the geopolitical question.

A country does not need every global agent to use a domestically invented model in order to exercise technological influence.

If its standards shape:

identity;

trust;

capability description;

discovery;

transactions;

audit,

then foreign models may operate inside an architecture designed elsewhere.

Conversely, a country may build excellent national models but depend heavily on foreign protocols, cloud infrastructure, identity systems and marketplaces.

Model sovereignty and infrastructure sovereignty are different.

This is why the AI race increasingly resembles earlier infrastructure competitions:

operating systems;

mobile standards;

telecommunications;

payments;

internet protocols;

cloud platforms;

semiconductor ecosystems.

The intelligence layer attracts attention.

The interoperability layer may determine persistence.


39. The operating system metaphor should be used carefully

Calling these frameworks an “operating system for agent society” is useful only as an analytical metaphor.

GB/Z 185 is not literally an operating system.

Neither is A2A.

Neither is MCP.

But together the emerging standards layers perform functions analogous to basic operating infrastructure:

identifying actors;

describing resources;

connecting participants;

routing messages;

granting access;

invoking capabilities;

recording events.

As those functions standardise, the agent ecosystem becomes less like a collection of isolated applications and more like a common execution environment.

That is why the standards layer deserves attention equivalent to the model layer.


40. The Synthocracy question: where does power move?

The central idea of Synthocracy is that power does not disappear when institutions adopt AI.

It moves into different components of the decision system.

Agent interoperability gives us a new map.

Power can move into:

IDENTITY — who is recognised.

DESCRIPTION — what capabilities are legible.

DISCOVERY — who becomes visible.

AUTHENTICATION — who is trusted.

INTERACTION — who can participate.

TOOL INVOCATION — who can act.

AUDIT — whose actions become reconstructable.

TRANSACTION — who can move value.

A political scientist looking only at laws may miss much of this architecture.

A computer scientist looking only at protocols may miss its institutional consequences.

Synthocracy exists in the gap between the two.


Conclusion — The next AI race may be over the rules of machine participation

The publication of GB/Z 185-2026 deserves more international attention than it has received.

China has created a seven-part national technical framework covering agent architecture, identity codes, identity management, capability descriptions, discovery, interaction and tool invocation. The official framework treats these as one closed-loop system moving from trusted identity and visible capabilities to discovery, collaboration, tool access and task completion. (digitalchina.gov.cn)

And the architecture is already expanding.

Agent Audit is under development as Part 8.

Agent Transaction is under development as Part 9. (std.samr.gov.cn)

Around it, China is developing additional standards for government agents, industrial agents, embodied agents, platform infrastructure and agent governance. (std.samr.gov.cn)

The United States is constructing the same broad layer through a different institutional route. A2A, MCP, DNS-based discovery and other open protocols emerged from firms and open-source communities; the Linux Foundation increasingly provides neutral governance; NIST is now explicitly fostering industry-led standards, community-led protocols and agent-identity research while seeking U.S. leadership in international standards. (NIST)

The difference should not be reduced to:

China regulates. America innovates.

Both innovate.

Both standardise.

Both combine government and industry.

The more interesting difference is where coordination begins and how the common layer is produced.

China is attempting to establish a coordinated national agent architecture early enough to shape industrial deployment.

The United States is allowing protocol ecosystems to emerge competitively and then coordinating them through foundations, industry and public standards institutions.

International bodies are developing additional layers of interoperability.

The outcome is still open.

But the object of competition is becoming visible.

The next strategic AI question may not be:

Who owns the most intelligent model?

It may be:

Whose architecture determines how intelligent machines are recognised, discovered, trusted, authorised, connected, audited and permitted to act?

That architecture will influence which agents can participate.

Which companies can become machine-visible.

Which identities are trusted across borders.

Which tools can be invoked.

Which transactions can execute.

Which actions remain attributable.

And which institutions retain the ability to stop or challenge them.

This is why GB/Z 185 matters.

It is not merely a technical specification for agents talking to agents.

It is an early attempt to standardise the layer through which machine intelligence becomes an interoperable participant in institutions, markets and infrastructure.

The global model race will continue.

But underneath it, another race has already begun:

the race to define the rules of machine participation.

And the winner of that race may exercise influence long after today’s leading model has been replaced by the next one.


Synthocracy Institute — Power & Accountability When AI Co-Decides