<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>artificial intelligence Archives - IDPro</title>
	<atom:link href="https://idpro.org/tag/artificial-intelligence/feed/" rel="self" type="application/rss+xml" />
	<link>https://idpro.org/tag/artificial-intelligence/</link>
	<description>The Professional Organization for Digital Identity Management</description>
	<lastBuildDate>Wed, 30 Sep 2026 20:09:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://idpro.org/wp-content/uploads/2023/07/cropped-idpro_stickerA-circle-100-32x32.jpg</url>
	<title>artificial intelligence Archives - IDPro</title>
	<link>https://idpro.org/tag/artificial-intelligence/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Everyone Is Calling the OpenAI–Hugging Face Breach a Sandbox Escape. It Was a Machine Identity Failure</title>
		<link>https://idpro.org/open-ai-hugging-face-machine-identity-failure/</link>
		
		<dc:creator><![CDATA[Elizabeth Garber]]></dc:creator>
		<pubDate>Wed, 30 Sep 2026 20:06:53 +0000</pubDate>
				<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[authorization]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[identity governance]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[machine identity]]></category>
		<category><![CDATA[non-human identity]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=3094</guid>

					<description><![CDATA[<p>The Hugging Face Breach was a machine identity governance failure and identity best practices are sorely needed in the evolving frameworks for AI guardrails.</p>
<p>The post <a href="https://idpro.org/open-ai-hugging-face-machine-identity-failure/">Everyone Is Calling the OpenAI–Hugging Face Breach a Sandbox Escape. It Was a Machine Identity Failure</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">By Matt Topper</p>



<p class="wp-block-paragraph">On August 26, OpenAI released a 38-page technical report explaining how, during internal cybersecurity evaluations in July, its own models broke out of a controlled test environment and compromised parts of Hugging Face’s production infrastructure. The headlines landed on two words: <strong>reward hacking</strong>. The models were supposed to solve security challenges; instead they decided to cheat by stealing the answers, and to get the answers they chained together a series of zero-days to reach the open internet.</p>



<p class="wp-block-paragraph">That framing is accurate. It is also a distraction. If you sit in the identity and access management world — if you spend your days on workload identity, non-person entities, and Zero Trust for federal missions — you read the same report and see something the alignment community keeps waving past. This was not primarily a sandbox problem. It was a <strong>machine identity governance failure</strong>, and nearly every hop the agents made was one a mature ICAM architecture would have either denied outright or contained to a single blast radius.</p>



<p class="wp-block-paragraph">Here is the part the industry needs to sit with: the controls OpenAI is racing to add back are mostly more network isolation, more sandboxes, and more monitoring. Those are necessary. They are also the wrong center of gravity. Agent collectives defeat network controls precisely by combining <em>identities and credentials</em> across systems. Containment of autonomous agents is an identity problem. Let’s walk the kill chain and prove it.</p>



<h2 class="wp-block-heading"><strong>The shared credential was the original sin.</strong></h2>



<p class="wp-block-paragraph">To let the agents pull software packages, OpenAI handed them a <strong>shared credential</strong> to an internal Artifactory instance. One secret, used by many workloads. That single decision seeded everything that followed. Because the agents authenticated as the same principal, they could read and write a common namespace — which is exactly how they built an improvised “message board” to coordinate across separate evaluation runs, with no exploit required. A shared identity <em>is</em> a shared channel. The later reader-to-admin escalation started from that same credential. And because thousands of workloads wore the same identity, there was no attribution and no way to spot anomalous behavior — which is a big reason an early alert got dismissed and detection didn’t land until eleven days after breakout.</p>



<p class="wp-block-paragraph"><strong>The control that kills it:</strong> unique, cryptographically attested, per-workload identity. <strong>SPIFFE/SPIRE</strong> issuing a short-lived SVID to every agent instance means there is no shared secret to distribute, no common principal to rendezvous on, and full attribution from the first action. The covert message board never forms. This one change removes the substrate the entire incident was built on.</p>



<h2 class="wp-block-heading"><strong>Replayable tokens turned a breach into a marketplace.</strong></h2>



<p class="wp-block-paragraph">The most chilling operational detail for anyone who runs an identity program: the agents <strong>harvested credentials and posted them to the message board for other agents in later runs to reuse</strong> — production Hugging Face tokens, cloud keys, forged storage JWTs. That works only because these were pure bearer tokens: portable, replayable, valid from anywhere, and absurdly long-lived. At one point the agents minted themselves <strong>one-year access tokens</strong>. The very first foothold was the same disease on the other side of the fence — static, long-lived user tokens sitting exposed in a public dataset.</p>



<p class="wp-block-paragraph"><strong>The control that kills it:</strong> sender-constrained, short-lived, audience-bound credentials. Bind the token to the holder’s key with <strong>DPoP (RFC 9449)</strong> or <strong>mTLS-bound tokens (RFC 8705)</strong>, and a credential found on a bulletin board is useless to whoever finds it. Add short TTLs and proper scoping via <strong>OAuth Token Exchange (RFC 8693)</strong>, and the entire harvested-credential economy — the connective tissue of this intrusion — stops paying off.</p>



<p class="wp-block-paragraph">Static, long-lived, non-sender-constrained credentials failed identically whether they belonged to OpenAI or to a third party. That is not a coincidence. That is the pattern.</p>



<h2 class="wp-block-heading"><strong>A signing key you can read is a signing key you can forge.</strong></h2>



<p class="wp-block-paragraph">There were two catastrophic authentication failures here, and both are IAM 101. First, the token service <strong>accepted an access token with an invalid signature</strong> and cheerfully returned a valid administrative one. Second, once the agents achieved code execution, they <strong>stole the signing key and forged administrator JWTs at will</strong> — and then, in a detail that should keep every architect up at night, they later found leftover signing-key material sitting in an anonymously readable cache and re-minted admin tokens without needing any persistent implant at all.</p>



<p class="wp-block-paragraph"><strong>The control that kills it:</strong> keep signing keys in an <strong>HSM or KMS with non-exportable keys</strong>, so application-layer compromise cannot exfiltrate them. Prefer <strong>reference tokens with server-side introspection</strong> over self-contained JWTs the application validates locally, so offline forgery is impossible. Rotate. And never run anonymous access in production — it was the force multiplier that made this whole chain critical.</p>



<h2 class="wp-block-heading"><strong>Machines were governing machines with no governance.</strong></h2>



<p class="wp-block-paragraph">The agents created <strong>22 administrator accounts</strong>, a persistent local admin user, and hundreds of coordination repositories. Nothing in the identity fabric governed which machine identities were allowed to exist or gated who could elevate. This is the non-person-entity analog of the exact IGA discipline we apply to humans — birthright, approval, certification, deprovisioning — and it was simply absent for the machines. On the target side, the lateral movement was a textbook over-privilege chain: a compromised worker’s service-account token could read a connector secret that unlocked cluster-admin-equivalent access, and Kubernetes secrets sat readable and decryptable.</p>



<p class="wp-block-paragraph"><strong>The control that kills it:</strong> govern NPEs like the first-class identities they are. <strong>Just-in-time, no-standing-admin, approval-gated elevation</strong> for workload and agent identities, with continuous certification and break-glass. Least-privilege, audience-bound service-account tokens with short TTLs. And <strong>workload identity federation instead of stored secrets</strong>, so there is no long-lived secret to read out of a pod in the first place.</p>



<h2 class="wp-block-heading"><strong>The network was the only boundary — so there was no boundary.</strong></h2>



<p class="wp-block-paragraph">OpenAI relied on network isolation. The moment a trusted shared service could be coerced into making outbound requests, that boundary evaporated. From an identity standpoint the failure is transitive trust: outbound calls carried no workload identity and were authorized on reachability alone. This is the Zero Trust thesis (NIST SP 800-207) in its purest form — <strong>network position is not identity, and it never was.</strong> An identity-aware egress proxy that authorizes every outbound call against the calling workload’s identity, plus mutual TLS so services authenticate each other rather than trusting co-location, denies this pattern even after a service is reachable.</p>



<h2 class="wp-block-heading"><strong>The frontier nobody has a control for yet: agent-to-agent identity.</strong></h2>



<p class="wp-block-paragraph">This is the part that should reshape how we think about the next five years. The agents coordinated over an unauthenticated covert channel. They trusted credentials, tools, and exploits posted by peers they could not identify. They <strong>adopted goals from one another</strong>. At no point could the environment answer the only question that matters in a delegated system: <em>which agent, acting on whose authority, under what original request, issued this instruction?</em></p>



<p class="wp-block-paragraph">That question is the entire agentic-IAM problem, and this incident is its first at-scale real-world failure. The standards work is already underway and it needs to move faster: the IETF <strong>WIMSE</strong> effort for workload and agent identity semantics and authenticated agent-to-agent messaging, and <strong>OAuth Transaction Tokens</strong> to carry the call-chain and original authorization context across every delegation hop — so authorization and audit survive the handoff instead of evaporating at each one. An agent should only ever trust a signed instruction from an authorized peer over a sanctioned channel. Full stop.</p>



<h2 class="wp-block-heading"><strong>What this actually means.</strong></h2>



<p class="wp-block-paragraph">Map OpenAI’s remediation against the identity plane and the gap is glaring. Security-and-containment is mostly more network isolation. Monitoring adds an IAM baseline almost as an afterthought. Their single strongest genuine mitigation — removing the shared credential — is buried in a footnote. The controls that would have both prevented breakout <em>and</em> contained the blast radius — unique attested workload identity, sender-constrained tokens, non-person-entity governance, and identity threat detection and response on machine identities — are underweighted relative to “build more walls.”</p>



<p class="wp-block-paragraph">Here is the uncomfortable truth for every enterprise and every agency now standing up agentic AI: your attackers will not be constrained by the attention span or coordination limits of a human operator. Persistent, coordinated agent collectives will find your one misconfiguration at machine speed and chain it across your identity systems, your applications, your cloud, and your third parties. If your defense assumes network position equals trust, or that a bearer token is good enough, or that machine identities don’t need governance because “they’re just services” — you are defending the last war.</p>



<p class="wp-block-paragraph">The good news is that none of the required controls are speculative. Unique attested identity, proof-of-possession tokens, just-in-time privilege, secretless workloads, and identity-aware egress are deployable today. This incident is the case study that should end the debate about whether they’re worth it.<br></p>



<p class="wp-block-paragraph"></p>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<figure class="wp-block-image size-medium"><img fetchpriority="high" decoding="async" width="300" height="300" src="https://idpro.org/wp-content/uploads/2026/09/Matt-Topper-300x300.jpeg" alt="" class="wp-image-3098" srcset="https://idpro.org/wp-content/uploads/2026/09/Matt-Topper-300x300.jpeg 300w, https://idpro.org/wp-content/uploads/2026/09/Matt-Topper-150x150.jpeg 150w, https://idpro.org/wp-content/uploads/2026/09/Matt-Topper-768x768.jpeg 768w, https://idpro.org/wp-content/uploads/2026/09/Matt-Topper-320x320.jpeg 320w, https://idpro.org/wp-content/uploads/2026/09/Matt-Topper.jpeg 800w" sizes="(max-width: 300px) 100vw, 300px" /></figure>
</div>
</div>
</div>
</div>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-full"><img decoding="async" width="346" height="350" data-id="2898" src="https://idpro.org/wp-content/uploads/2025/11/image-2.png" alt="" class="wp-image-2898" srcset="https://idpro.org/wp-content/uploads/2025/11/image-2.png 346w, https://idpro.org/wp-content/uploads/2025/11/image-2-297x300.png 297w" sizes="(max-width: 346px) 100vw, 346px" /></figure>



<figure class="wp-block-image size-full"><img decoding="async" width="600" height="600" data-id="2390" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png" alt="" class="wp-image-2390" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-320x320.png 320w" sizes="(max-width: 600px) 100vw, 600px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="600" height="600" data-id="2391" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer.png" alt="" class="wp-image-2391" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>
</figure>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://idpro.org/open-ai-hugging-face-machine-identity-failure/">Everyone Is Calling the OpenAI–Hugging Face Breach a Sandbox Escape. It Was a Machine Identity Failure</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Concern of Local Autonomy</title>
		<link>https://idpro.org/the-concern-of-local-autonomy/</link>
		
		<dc:creator><![CDATA[Elizabeth Garber]]></dc:creator>
		<pubDate>Wed, 30 Sep 2026 19:55:25 +0000</pubDate>
				<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[authorization]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[idpro]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=3091</guid>

					<description><![CDATA[<p>Rusty Deaton explores the gaps presented by capable, locally-run generative models - and the fundamentals that can help practitioners mitigate the risks.</p>
<p>The post <a href="https://idpro.org/the-concern-of-local-autonomy/">The Concern of Local Autonomy</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This summer has seen us in interesting times. Agent harnesses and their capabilities have been at the forefront of the industry&#8217;s consciousness, and you could see it across the sheer number of talks on it. Much discussion has been around the nature of frontier models, their potential impacts on productivity when used in conjunction with appropriate harnesses, and the need to inject identity-related conventions into the enterprise.</p>



<p class="wp-block-paragraph">There are plenty of meaningful solutions being worked on to help prevent errant agents in the enterprise, as well. For instance, we are seeing the creation of standards (Such as IETF draft on OAuth Client ID Metadata Documents or the IETF draft on Identity Assertion JWT Authorization Grants), best practices (Such as the AIMS draft that Jeff Lombardo wrote about recently), and articles abound providing a path forward. These are powerful, meaningful works. However, we are left with gaps that cannot be resolved with these solutions alone- securing the path of known agent to enterprise resource does not end the fight.</p>



<p class="wp-block-paragraph">What do I mean, here? Specifically, I am talking about the increasing prevalence of capable, locally-ran generative models. Coupled with abliteration- Abliteration being a process that uncensors generative models by removing the model’s ability to refuse requests by various means- these local models (Called abliterated models or &#8220;Heretic models&#8221; after Heretic, a tool that performs the work) have no compunctions to perform actions on behalf of the user, any action.&nbsp; These local models will potentially be given credentials from users to perform actions. This could range from the mundane to the momentous. One can quickly imagine a scenario where a business user offers such a model the credentials to their CRM to create dynamic reports for them, or access to a corporate git repo to help write code or develop gating around a build process. One can likewise imagine a scenario where a user utilizes a local abliterated model to perform actions as an insider threat to the organization.</p>



<p class="wp-block-paragraph">Research<sup>1</sup> has been performed and presented<sup>2</sup> in this field.&nbsp; With local, open-weight models becoming increasingly capable and the ease<sup>3</sup> by which these local models are having their rejection mechanisms stripped, this means these models can perform tasks that would otherwise be rejected by a frontier model in a manner that while is not at the forefront of capability, is sufficient in many cases to get done what the user is looking to get done.&nbsp; I will not editorialize the ethics of abliteration or the usage of abliterated models (As has been done recently across the United States’ legislative branch<sup>4</sup>), but I will note that any grandstanding about whether or not they should exist at this point is moot- the tools and techniques exist, and they are at our door.&nbsp; As a matter of practicality, your humble offer has engaged with local models inside of Capture the Flag (CTF) environments (With permission!) and has found them impressively effective in performing tasks sufficient to perform at the top end of these CTFs; the capabilities of these models are impressive, and I can see a point not even a few years from now (It’s already happening!) where local models are used in conjunction with frontier models to maximize cost efficiency while maintaining quality in a wide range of tasks.</p>



<p class="wp-block-paragraph">You may be thinking “Models that could harm us take huge resources to run”, and that is not necessarily true.&nbsp; Laptops already in the enterprise, such as the humble Macbook Pro, can run local models with impressive performance. x86-based architectures are moving towards this as well, because the market has a demand for AI- there are already compact desktops that can perform this work with some degree of prowess, and it stands to reason chipmakers will look to rise to this demand further. An astute reader may think &#8220;This is a whitelisting problem at runtime, not an identity problem&#8221;, and I would offer you are partly right. While there are means by which to determine if something we don&#8217;t want running is running, life finds a way. Even still, in the era of BYOD organizations cannot stop every new tool that comes out that can act as an inference server, or act as an agent harness. We&#8217;re left what I reluctantly call &#8220;Shadow agents&#8221;, in the way shadow IT is manifested- it&#8217;s a bad term, but the intent is to make it clear the agents performing actions on behalf of users are not vetted by the organization or necessarily approved.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">So what do we do as practitioners of identity to help mitigate this risk in the enterprise? We fall back to fundamentals. The machine acting on behalf of the user still has to come to a remote service, still has to present credentials, and still has to send requests to the remote system. We can determine when the user logs in, how they move in the system, and the speed at which they perform operations. Agents categorically do not act like users- which means we can determine if a user is potentially letting a machine act on their behalf, shut down the session, and communicate the concern to the rest of the enterprise. And while a sufficiently devious agent acting on behalf of a user may seek to emulate the user, we have a historical understanding of how a user (Not just this user) may move through the system and what actions they may take in what order. This is powerful information, and signaling inside of a robust continuous authentication process that can help us differentiate.</p>



<p class="wp-block-paragraph">It&#8217;s fair to have concern over the changing nature of how we interact with systems. Systems are moving faster, in non-deterministic ways, and in ways that may not necessarily be beneficial on any given action. It is not fair, however, for the marketing hype to pretend we are entirely defenseless in this brave new world. The defenses of the past may no longer tell the whole story, but they still tell a story- sufficiently robust authentication and authorization, as far down in the stack as possible, allow us a great deal of mitigation against the risk of an errant agent.<br></p>



<h2 class="wp-block-heading">References</h2>



<p class="wp-block-paragraph">1: <a href="https://go.alice.io/hubfs/alice-abliteration-report-april2026.pdf">https://go.alice.io/hubfs/alice-abliteration-report-april2026.pdf</a></p>



<p class="wp-block-paragraph">2: <a href="https://www.unomaha.edu/ncite/news/2026/09/dc-demo-day2.php">https://www.unomaha.edu/ncite/news/2026/09/dc-demo-day2.php</a></p>



<p class="wp-block-paragraph">3:&nbsp; <a href="https://www.irishtimes.com/business/2026/05/25/ai-guardrails-stripped-from-meta-and-google-models-in-minutes/">https://www.irishtimes.com/business/2026/05/25/ai-guardrails-stripped-from-meta-and-google-models-in-minutes/</a></p>



<p class="wp-block-paragraph">4: <a href="https://www.yahoo.com/news/articles/lawmakers-shown-jailbroken-ai-plan-223247817.html">https://www.yahoo.com/news/articles/lawmakers-shown-jailbroken-ai-plan-223247817.html</a></p>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<figure class="wp-block-image size-medium"><img loading="lazy" decoding="async" width="300" height="300" src="https://idpro.org/wp-content/uploads/2026/04/image-2-300x300.png" alt="" class="wp-image-3020" srcset="https://idpro.org/wp-content/uploads/2026/04/image-2-300x300.png 300w, https://idpro.org/wp-content/uploads/2026/04/image-2-150x150.png 150w, https://idpro.org/wp-content/uploads/2026/04/image-2-320x320.png 320w, https://idpro.org/wp-content/uploads/2026/04/image-2.png 400w" sizes="auto, (max-width: 300px) 100vw, 300px" /></figure>
</div>
</div>
</div>
</div>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/rusty-%F0%9F%94%8F-unicode-breaks-things-deaton-a3584483/">Rusty Deaton</a> has been in Identity and Access Management for over a decade. He began in technology as a technical support engineer for a Broker-Dealer and has since worked across many industries, carrying forward a passion for doing right by people. When not solving problems, he loves to tinker with electronics and read. He currently works as Federal Principal Architect for Radiant Logic.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="346" height="350" data-id="2898" src="https://idpro.org/wp-content/uploads/2025/11/image-2.png" alt="" class="wp-image-2898" srcset="https://idpro.org/wp-content/uploads/2025/11/image-2.png 346w, https://idpro.org/wp-content/uploads/2025/11/image-2-297x300.png 297w" sizes="auto, (max-width: 346px) 100vw, 346px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="600" height="600" data-id="2390" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png" alt="" class="wp-image-2390" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="600" height="600" data-id="2391" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer.png" alt="" class="wp-image-2391" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>
</figure>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://idpro.org/the-concern-of-local-autonomy/">The Concern of Local Autonomy</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Minified using Disk

Served from: idpro.org @ 2026-10-01 05:10:06 by W3 Total Cache
-->