← All speakers

Bio, Work & Ideas

Tobin South

Conference affiliation: WorkOS · 2025

Tobin South works on the Model Context Protocol and AI agents at Anthropic and is a Stanford research fellow studying how autonomous software can act securely on someone else’s behalf. His central problem is increasingly urgent: when agents can access confidential data, negotiate purchases or operate enterprise software, they need verifiable identities, limited permissions and clear accountability to the people they represent.

Raised in Kingaroy, Queensland, South studied mathematics and computer science, worked in Australia’s public sector and startup ecosystem, and founded an early startup. An Australian-American Fulbright scholarship took him to the MIT Media Lab, where he worked in Alex Pentland’s Human Dynamics group and interned with Microsoft Research’s cryptography and plurality teams in 2023. He completed his MIT doctorate in April 2025; his research on private, verifiable and auditable AI systems explored zero-knowledge proofs, secure multiparty computation, trusted execution environments and credentialing as foundations for accountable AI. He also led the privacy-risk and privacy-protection sections of the 2025 International AI Safety Report.

South became Head of AI Agents & MCP at WorkOS in April 2025 after founder Michael Grinich encountered his research on agent identity. There, he brought enterprise authentication, authorization and monitoring to agent-connected applications. He joined Anthropic in December 2025 and continues advising Stanford’s Loyal Agents initiative, a collaboration with Consumer Reports examining whether consumer-facing agents actually protect their users’ interests.

  • Authenticated delegation: South’s agent-authorization research extends OAuth and OpenID Connect with agent-specific credentials, bounded permissions and auditable chains of authority. The framework also proposes translating natural-language instructions into enforceable access controls.
  • Enterprise-ready MCP: A functional tool connection becomes deployable only with single sign-on, provisioning, fine-grained authorization, audit logs, abuse prevention and data-loss protection. In his AI Engineer World’s Fair talk, South used a goat-feeding application and an authenticated merchandise purchase to show how payments and external users expose unresolved problems such as headless authentication, dynamic client registration and transferring permissions between agents.
  • Interoperable agent identity: As first author of an OpenID Foundation white paper, South helped define how autonomous systems can authenticate themselves and carry delegated authority across organizational boundaries without splintering existing identity infrastructure.
  • Consumer loyalty and agent bargaining: Through Loyal Agents and research on automated negotiations, South examines how agents can expose consumers to overspending, unequal bargaining outcomes and conflicts between commercial incentives and their users’ interests.

Read the topics behind these talks

1 conference talk

References