The critical infrastructure IAM knot
Telcos worldwide spend billions of dollars each year on identity and access management (IAM) and compliance-related activities as they manage increasingly distributed and highly regulated networks.
Competitive economics aside, this is leading to traditional IAM operating models buckling under the pressure of complex networks that span a smorgasbord of technology domains and vendor environments, as well as an exploding number of human and machine identities.
Permissions management has also evolved from a technical concern into a matter of public and government service resilience and critical infrastructure protection.
Pressure is especially acute in Europe for operators serving sovereign and enterprise clients, even where governance principles are strong, including navigating regional and national data protection and critical infra frameworks.
“In a world where network infrastructure underpins critical public and government services, getting permissions management right is not optional, it is existential.”
Karsten Thon, Senior Business Architect, Deutsche Telekom.
From manual burden to agentic AI
One of the biggest challenges that operators are facing with IAM is translating complex regulatory and contractual requirements into technical access controls.
These rules are frequently buried in documents, which can be written in multiple languages or expressed in dense legal jargon that engineers struggle to interpret.
Arch-rivals Deutsche Telekom and Vodafone have been working together to address this major point of industry operational friction as joint-Champions of the Trusted agentic AI for access management TM Forum Catalyst proof-of-concept. This sought to leverage a confluence of compliance, agentic AI, and competitive telecom economics in order to move a downstream audit burden to an ‘upstream, automated property of the network’.
The Catalyst was demonstrated at this year’s DTW Ignite with project team collaborators Celfocus, GIP Exyr, and Tallence, to showcase how agentic AI can continuously interpret contractual obligations and automatically translate them into enforceable network access policies.
“When I’m coming to my engineers, handing over legal documents, saying, ‘Look, please transform this into system requirements’, they usually go, ‘Please don’t — why me? Pick someone else!’.”
Steffen Krippner, Senior Manager for OSS Fulfilment, Vodafone.
Through application of AI, the time required to ingest legal documents and update IAM policies was slashed dramatically by the project team.
Evidencing this achievement, Vodafone’s Steffen Krippner confirmed that a process traditionally taking an engineer multiple weeks of cross-domain, multi-vendor coordination was able to be completed by an AI agent within a single day. The project team claimed reduction of more than 90% in the time between a legal or contractual change and its enforced access rule, seemingly meeting its target of going from weeks to hours.
Watch: TelcoTitans TV interview with Vodafone’s Steffen Krippner and Tallence’s Marc Seidemann at DTW Ignite 2026…
While IAM in all industry verticals is variously estimated to be a market worth over $20bn and growing this decade at a CAGR in the 10%–20% range, telcos (representing a significant sub-segment) operate on a completely different level and scale to typical enterprises. Corporate IAM might handle thousands of employees with standard role-based access, but operators’ IAM can be managing millions of consumer accounts. It is also being pushed deeper into network operations, and the strategy for wholesale and enterprise connectivity can sit close to OSS (rather than central IT). The scope continues to broaden, too, such as supporting identity federation for MVNO partners and 5G-specific identity functions for IoT.
Inside the Catalyst: DIM and the Compliance Agent
To make this automated policy ingestion a reality, a solution was engineered that pairs an AI Compliance Agent (also referred to as a ‘Legal LLM’) with a robust Digital Identity Management (DIM) layer.
The AI Compliance Agent acts as the front end of the translation process, ingesting dense regulatory, contractual, and corporate-policy text. Legal nuances are then parsed, and IAM policy update candidates proposed.
Within the Catalyst, network management automation vendor GIP Exyr drove an exploratory ‘hybrid’ approach, employing multiple base LLMs — including from Anthropic and Mistral — to process documents and build an understanding of how distinct AI models interpret complex texts.
These candidate policies were fed to the DIM layer, which was built by telecom transformation specialist Tallence and aligned to the TM Forum’s TMFC020 component standard. The DIM serves as the single enforcement point for the network, acting as a ‘trust layer’ between operational applications and network systems. It also ensures that all access requests, whether human or AI agent, are evaluated against a single continuously updated set of rules. This system guarantees that an AI cannot implement a rule that contradicts existing network policies or human-defined parameters.
Governed intelligence: zero trust in action
Permitting an AI agent to dictate network access policies naturally raises security concerns.
Vodafone’s Krippner is explicit that the goal is “governed intelligence”, rather than “uncontrolled autonomy”. To this end, the Catalyst enforces four strict zero trust safeguards before any AI-generated policy goes live.
First, the system runs a policy dry-run, simulating the proposed changes and logging the outcome without applying it to the live network. Second, a human-in-the-loop approval process mandates explicit validation for any high-risk identity or role changes. Third, a controlled rollout ensures gradual enforcement to limit blast radius. Finally, the system employs negative testing, deliberately injecting conflicting or incomplete data to expose weaknesses in the AI’s decision-making.
“Zero trust is based on the principle that access should never be assumed. It must be continuously verified, context-aware, and policy-driven.”
Thon.
This architecture fundamentally impacts the audit trail. With every access decision tied directly to its policy basis, the system provides near-real-time answers to queries about who accessed what, when, and under which authority.
As Tallence’s Chief Data Officer, Marc Seidemann, noted: “If there’s a request from an engineer that is denied, we can trace why it was denied. What was the legislation? What was the rule that applied for that?”.
Use cases: GDPR and sabotage protection
The Catalyst demonstrated this governance capability through three distinct use cases, moving progressively from static rules to dynamic compliance.
The baseline scenario illustrated standard role-based access control (RBAC) without active compliance overlay. This is a technically correct model but one exposed to human error and high maintenance costs.
The system then demonstrated a GDPR and BDSG data protection use case. When a new compliance rule was ingested, such as stipulating that only EU-based users can monitor sensitive German operational data, the DIM layer automatically restricted excluded users regardless of their prior role access.
The final use case tackled sabotage protection, referencing Germany’s SÜG/KRITIS frameworks. The AI agent classified specific provisioning actions as critical operations, automatically translating the legal requirement into a network restriction that confined access to a predefined closed user group.
Trusted agentic AI for access management, Catalyst use cases
Ecosystem roles and AI context
The success of the Catalyst rested on a clear division of labour among its ecosystem participants.
While operators Deutsche Telekom and Vodafone provided the scale, commercial imperatives, and engineering context, GIP Exyr anchored the technical execution of the TM Forum Open Digital Architecture (ODA) canvas, and Celfocus supported systems integration.
Tallence’s contribution of the DIM layer highlighted a broader strategic push towards on-network AI, with the vendor’s CDO saying that “[The DIM] is still policy-based, so it is deterministic… but it is fed with AI, and it also serves AI. This is the trust layer we rely on. It’s compliance-by-design because you do not state rules manually, you just feed it with an AI, which is intent-based”.
“Trust in AI-driven operations starts with trustworthy identity data. Without that foundation, no automation can be truly accountable.”
Marc Seidemann, Chief Data Officer, Tallence
Tallence views identity as the operational backbone of network AI. This perspective is complemented by its work on Thor AI Voice, a network-native conversational platform designed to run directly on operator infrastructure. This means telcos can bypass external AI platforms by keeping data processing on-network, thus leveraging their unique position as trusted custodians of sensitive customer data.
Business impact and the standards blueprint
For operators, the business impact of this automated, standards-based approach extends well beyond internal efficiency.
While shrinking policy update latency from weeks to a single day is a clear win, the strategic prize is unlocking new revenue streams. By implementing contractually enforceable, fully auditable access controls, operators can best place themselves to qualify for sovereign, defence, and critical infrastructure contracts. This is a revenue segment described by the Catalyst team as “inaccessible to operators” lacking this capability.
Crucially, the project is designed as a repeatable industry blueprint. Anchored in TM Forum standards, specifically ODA, the Digital Identity API (TMF720), and Digital Identity Management (TMFC020), it provides a common framework for the industry to adopt.
The results were compelling enough that Vodafone plans to move straight from the Catalyst to the project phase, skipping a traditional pilot.
As Krippner concluded at DTW Ignite: “As a pessimistic German engineer, I never thought ‘that’s going to work’. And to my surprise, it’s live. And to my second surprise, I don’t need the data centre for the demo. And I don’t need a nuclear power plant to run the demo”.