In a move that could reshape how AI assistants collaborate inside organizations, a coalition of major enterprise-software vendors today announced the Assistant Handoff Protocol (AHP), an open specification designed to let workplace AI agents transfer task state, security context and explicit user consent between applications.
What AHP does
AHP specifies a compact, machine-readable "handoff bundle" that an originating assistant attaches to an outgoing task when it delegates work to another assistant or back to an enterprise application. The bundle contains:
- Task state: intent, relevant documents or data pointers, and partial outputs (with version IDs and timestamps).
- Security and authorization context: identity tokens, role-based access claims, and tenant identifiers required to continue the task without re-authentication.
- User consent metadata: explicit consent scopes and a human-readable summary of what data will be shared and for what purpose.
- Provenance and audit headers: cryptographic signatures, originating model/version identifiers, and configurable retention flags for compliance logs.
Designed to be transport-agnostic, AHP works over REST, gRPC or event buses and is deliberately lightweight to support low-latency handoffs in conversational flows, collaborative drafting, and automated workflows.
Why vendors are pushing AHP now
Enterprise AI adoption has moved from proof-of-concept assistants to distributed, multi-agent workflows: a sales assistant drafts proposals, a finance bot checks pricing rules, and an HR agent manages approvals. Until now, these handoffs were brittle: each vendor used proprietary APIs, re-requested credentials, or forced manual copy/paste that splintered context and created compliance gaps.
AHP addresses three immediate pain points cited by early adopters:
- Context loss. Re-authenticating and re-supplying documents at each hop breaks conversational flow and increases error rates.
- Auditability. Compliance teams need clear, tamper-evident records of what data moved between agents and why.
- Consent management. Employees and customers must know when an assistant shares their data with a downstream tool, and be able to scoping or revoke that consent.
Vendors say the protocol reduces integration time for partner-built assistants and lowers the operational risk of distributed AI orchestrations.
Who’s behind the specification
The initial working group includes several established enterprise players and cloud providers, plus three open-source orchestration projects. The founding participants—who jointly published the first AHP draft and implementation reference—said they will maintain the specification under a neutral foundation to encourage broader adoption.
Project maintainers released a permissive license for the AHP spec and published server and client SDKs in Go, Java and TypeScript, as well as sample connectors for popular workflow platforms.
How AHP handles security and compliance
AHP integrates multiple layers to reduce the attack surface that emerges when one assistant hands off to another:
- Short-lived, scoped tokens. Handoffs use exchange-only tokens that are valid for a narrow scope and time window.
- Selective redaction. Bundles can include encrypted references to sensitive data stored in the source tenant’s encrypted stores; downstream agents receive pointers and a just-in-time attestation to access the data only if authorized.
- Cryptographic provenance. Each bundle carries a signature chain so compliance logs can prove where, when and by which model the handoff originated.
By standardizing these mechanisms, AHP aims to make it easier for security teams to reason about multi-agent flows and for auditors to reconstruct events without harvesting full data payloads into a central repository.
Early reactions and potential friction
Security and privacy officers welcomed the idea of a common handoff standard but warned that the draft leaves implementation choices that could affect risk. For instance, the protocol permits both pointer-based sharing (preferred by privacy teams) and full-payload embedding (convenient for performance). How vendors default those behaviors will matter.
Integration architects flagged versioning and model identity as a potential source of complexity. If assisting agents use different model families or prompt-engineering layers, downstream behavior may be unpredictable even with complete task state. The AHP draft acknowledges this and includes fields for model signatures and a “compatibility score” intended to help orchestrators decide whether to proceed or to re-run certain checks.
What AHP means for enterprises
For IT teams, AHP promises to reduce bespoke engineering work needed to glue assistants together across SaaS boundaries. Compliance teams get standardized metadata that can feed into existing GRC and SIEM systems, and product managers can design smoother multi-step experiences where assistants collaborate rather than compete.
Adoption will depend on three practical milestones:
- Vendor defaults. Will vendors choose secure defaults (pointer-based sharing, minimal scope) or convenience defaults (embed everything)?
- Foundation governance. A neutral custodian will need to shepherd the spec and arbitrate changes as new attack vectors or legal requirements emerge.
- Enterprise readiness. Organizations must inventory where assistants run (cloud, private cloud, on-prem) and whether their identity fabrics can support short-lived cross-tenant tokens.
Next steps
The working group invited public feedback on the AHP draft for a 60-day review period and announced pilot partnerships with several Fortune 200 customers to validate the spec in production workflows. The maintainers aim to graduate the draft to a 1.0 specification within nine months if pilot results are favorable.
As enterprises push toward more connected, assistant-driven workflows, a common handoff protocol could become a foundational interoperability layer — reducing friction while creating a clearer surface for security and compliance. The industry’s response over the coming months will determine whether AHP becomes a de facto standard or another vendor-led variation in an already fragmented stack.