How Ant Group and 20+ Partners Are Building a Trustworthy Agent Ecosystem with ASL
Ant Group outlines the security challenges of scaling AI agents and describes its native‑security AgentOS platform, the ASL trust protocol, and the Avernet collaboration infrastructure, developed together with more than twenty industry partners to enable trustworthy multi‑agent interactions.
At the 2026 World AI Conference’s “From Large Models to Agents” forum, Ant Group vice‑president and Chief Security Officer Chen Liang highlighted trust as the core pain point for large‑scale agent deployment, noting that stronger agents bring harder‑to‑control risks.
Ant Group announced a joint effort with over twenty partners—including Qianwen, Xiaomi, Zhipu, BYD, and SenseTime—to advance the Agent Security Link (ASL) protocol, aiming to solidify a trustworthy interconnection layer for agents.
Evolution of Agents and Emerging Risks
Agents have progressed from simple dialogue bots to executors that can invoke tools, process data, and perform real‑world tasks. Multi‑agent collaboration and heterogeneous system integration are becoming the norm, requiring agents to access diverse data sources, external tools, and system permissions. If an agent’s identity cannot be verified, its intent is altered, or its authorization expands unchecked, risks can propagate along the collaboration chain.
Native Security with AgentOS
To address these challenges, Ant proposes two pillars: native security embedded in the agent runtime and a trustworthy interconnection protocol. The native‑security pillar materializes as AgentOS, a runtime foundation adapted to various device forms. For wearables such as smart glasses and earphones, Ant offers LingDevice OS, emphasizing edge‑cloud coordination, low power consumption, and cross‑device connectivity. For enterprise scenarios with multiple users and complex tasks, an enterprise‑grade AgentOS provides high‑concurrency, distributed scheduling.
Within the Agent engine, Ant introduces native security and a “gear‑shift” orchestration mechanism that balances execution efficiency, inference capability, and runtime cost while pushing security down to the operating‑system layer.
On top of the runtime, Ant has built an “immune system” covering security assessment, identity and permission management, runtime protection, and supply‑chain security. Before deployment, agents undergo security evaluation to identify risks and capability limits. During operation, agents are subject to entity authentication, unified identity, least‑privilege authorization, sandboxing, real‑time detection, anomaly handling, and audit logging. Supply‑chain risks are mitigated through API, service, plugin, tool, and model scanning with policy enforcement.
ASL: Trust After Connection
Existing protocols such as MCP and A2A focus on how agents connect and invoke each other. ASL extends these by addressing the question “Can the connection be trusted?” It adds four capabilities—trustworthy identity, trustworthy connection, trustworthy intent, and trustworthy authorization—forming a verifiable, transferable, enforceable, and auditable trust chain for cross‑agent collaboration.
Trustworthy identity verifies devices and agents and enables identity flow across the collaboration chain. Trustworthy connection establishes end‑to‑end encrypted channels. Trustworthy intent validates command sources to prevent tampering. Trustworthy authorization enforces the principle of least privilege, constraining delegated permissions and preventing escalation.
ASL leverages underlying security primitives such as Trusted Execution Environments (TEE), decentralized identifiers (DID), and public‑key infrastructure (PKI), and it already supports scenarios like phone assistants, AI glasses, smart vehicle consoles, and embodied AI.
Chen emphasizes that ASL is not meant to replace existing inter‑agent protocols but to complement them with an additional layer of trust.
Collaboration Infrastructure: Avernet
Beyond AgentOS and ASL, Ant introduces Avernet, an infrastructure for multi‑agent organization and open ecosystems. Avernet addresses discovery, consensus, coordinated execution, and feedback evolution, applicable to operational efficiency, AI research, and collective decision‑making.
In Ant’s overall architecture, AgentOS supplies the native‑security runtime, the immune system governs the agent lifecycle, Avernet enables coordinated multi‑agent work, and ASL provides trustworthy cross‑device and cross‑entity connections.
Chen concludes that scaling agents requires not only stronger models but also robust operating systems, collaboration networks, and trust protocols. Ant aims to drive open‑source development and ecosystem co‑creation with industry partners to move agents from “can connect” to “can collaborate securely.”
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
