AI agents are entering live telecom operations, but trust, control and accountability are not yet solved. This Catalyst introduces a zero‑trust model that makes autonomous actions verifiable, governed and safe.

If you cannot trust the agent, you cannot scale autonomy
AI agents are beginning to act in live telecom operations, interacting directly with network systems, APIs, tools and workflows. As CSPs move toward higher levels of Autonomous Networks, the challenge is no longer simply whether AI can automate decisions. Operators also need to know whether every autonomous action can be trusted, controlled and proven after the fact.
Zero-trust agents for Autonomous Networks addresses this production trust gap by focusing on three operational questions: who is acting, what they are allowed to do, and what actually happened. These questions become critical when agents are operating across domains, tools and organizations, where risks such as impostor agents, prompt injection, lateral movement and scope creep can quickly undermine confidence in autonomous operations.
The Catalyst project, Zero-trust agents for Autonomous Networks, is tackling that challenge with a reusable, vendor-neutral governance model designed to help operators move from AI experimentation to governed production with approved agents, delegated authority and provable outcomes.
The solution applies an IPOE model: Identity, Policy, Observability and Evidence. In practice, this means only approved agents can operate, every action is checked against defined policy boundaries, runtime behavior is visible across the interaction chain, and critical decisions are backed by evidence for audit, assurance and accountability.
The Catalyst combines pre-runtime governance, runtime policy control and mediated connectivity trust. Identity and connectivity controls help prevent impostor or unauthorized agents from entering the environment. Policy and permissions management extensions limit what approved agents can do, helping to stop rogue or out-of-scope actions before they affect production systems.
Observability and assurance capabilities then provide end-to-end visibility into what happened, including evidence for critical actions. As Patricia Díez Muñoz, Global Security Director for Networks & Systems at Telefónica, explains: “AI agents will only be trusted in telecom operations if operators can verify who is acting, control what is allowed, and prove what actually happened. This Catalyst turns that into something practical through Identity, Policy, Observability and Evidence.”
The work builds on TM Forum’s ODA Reference Architecture, IG1463, the ZSM Framework and the AI-Native Blueprint. It is also extending API Management, Digital Identity Management, Policy Management, Permissions Management, Assurance, Observability, Evidence and ODA Security capabilities. In parallel, the team is developing proposed new assets for agentic governance, including IG14xx-A Agentic Asset Governance, IG14xx-B Agentic Policy & Autonomy Fabric and IG14xx-C Agent Connectivity Fabric, as well as three new Canvas Operator components.
For operators, the immediate benefit is a safer and faster route to production. The Catalyst aims to enable AI agents to move into governed production in hours, with critical actions policy-checked and evidenced. This reduces the risk of scaling autonomous operations while giving teams clearer policy boundaries, runtime control and a reliable record of what happened.
For the wider industry, the project provides an ODA-aligned pattern that CSPs, vendors and partners can reuse across domains and suppliers. That matters because autonomous networks will depend on trusted collaboration between people, systems and organizations, not just better automation inside individual tools.
For society, the project supports safer and more accountable use of AI in critical infrastructure. By making autonomous actions verifiable, controlled and auditable, the Catalyst helps create the conditions for AI-driven network operations that can be trusted at scale.
At DTW Ignite 2026, the Catalyst demonstrated how AI agents could be onboarded into a zero-trust environment and governed in real time. The showcase highlighted identity verification, runtime policy enforcement and end-to-end evidence generation, showing how autonomous systems can be made safer and more accountable in production. The project was also recognized as the winner of the Moonshot Catalyst award for the Trustworthy AI and Data challenge.