Jessie A Ellis Aug 25, 2026 14:44
Algorand (ALGO)’s AC2 Protocol adds cryptographic security to AI agent operations, addressing key vulnerabilities like spoofed approvals and exposed credentials.
The Algorand (ALGO) Foundation has unveiled the AC2 Protocol (Agentic Communication and Control Protocol), a new security layer aimed at mitigating risks in AI-driven operations. Announced on August 25, 2026, AC2 tackles two critical vulnerabilities in current AI agent systems: unverifiable human approvals and the exposure of sensitive credentials.
The protocol introduces cryptographic signatures for human approvals and ensures credential isolation. Instead of storing API keys or session tokens within an agent’s runtime environment, AC2 keeps these keys securely on the user’s device, leveraging FIDO2/WebAuthn for hardware-bound authentication. This means even if an AI agent’s runtime is compromised, sensitive credentials remain protected.
Why AC2 Matters
AI agents are increasingly used to automate tasks like code reviews, API calls, and even financial transactions. However, the lack of robust security measures has led to incidents where compromised agents have been exploited to push unauthorized actions or steal sensitive data. A notable example highlighted by Algorand involved a malicious plugin exposing API keys, enabling unauthorized merges that appeared to have human approval.
With AC2, every agent action requiring approval is tied to a cryptographic signature, creating an immutable audit trail. Additionally, by isolating credentials from the agent, AC2 eliminates a major attack vector. “It’s not just about approval flows—it’s about proof,” said an Algorand representative.
How AC2 Works
AC2 is built on three open standards:
- DIDComm v2.0: For interoperable message formatting.
- WebAuthn/FIDO2: For phishing-resistant, hardware-bound authentication.
- WebRTC DataChannel: For direct, encrypted communication between users and agents.
The protocol is lightweight—requiring only about 50 lines of code for a basic integration—and blockchain-agnostic, allowing it to work alongside existing setups without significant overhead.
Applications and Future Developments
AC2 is designed to secure a range of use cases, including:
- Code approvals: Verifying that a human has authorized commits or deployments.
- API access: Ensuring agents execute only approved requests.
- Financial transactions: Adding cryptographic proof to AI-initiated payments.
- Content approvals: Guaranteeing human sign-off for client communications or published materials.
While the current version of AC2 focuses on real-time approvals, Algorand plans to introduce delegation capabilities. This will allow users to define operational boundaries for agents, reducing the frequency of manual approvals while maintaining security.
Market and Ecosystem Context
The launch of AC2 fits into Algorand’s broader strategy to position itself as a leader in agentic commerce—transactions and operations mediated by AI agents. According to Algorand’s July 2026 insights report, the x402 protocol, which supports agentic payments, recorded $80.9K in transfer volume in a single week. While AC2 is not tied to a specific token, it bolsters the trust ecosystem necessary for scaling agentic operations.
The protocol is already being demonstrated through the AC2 Wallet, available on the Google Play Store, Apple App Store, and GitHub. Developers can integrate AC2 into their systems via an open-source plugin, making it accessible for a wide range of applications.
What’s Next
As the first protocol designed specifically for secure AI-agent communication, AC2 has the potential to redefine how enterprises and developers approach agent security. Its emphasis on cryptographic proof and credential isolation directly addresses major pain points in the current ecosystem. With plans to expand its capabilities, AC2 could play a pivotal role in the growing agentic commerce sector.
For developers interested in testing the protocol, the AC2 specification and reference implementation are freely available on GitHub. Feedback from the community will shape future iterations, ensuring the protocol meets real-world needs.
Image source: Shutterstock Source



