Network APIs for AI Agents: Telecom’s Quiet Trust Play

Network APIs for AI Agents: Telecom’s Quiet Trust Play

August 16, 2026

Network APIs for AI agents are quietly becoming one of the more consequential infrastructure bets in telecom, and almost nobody outside the industry is talking about it. While the trade press spends its attention on GPU shortages, model benchmarks, and whichever hyperscaler announced the latest data center campus, a slower and less glamorous shift has been underway inside the world’s mobile operators: turning core network signals — which SIM card is active, which device just changed, whether a phone number is really attached to the person claiming it — into standardized, sellable APIs. That plumbing, built originally to fight fraud and streamline logins, is starting to look like the identity layer that autonomous AI agents will need to operate safely in the real world.

From carrier plumbing to a trust layer

The vehicle for this shift is the GSMA’s Open Gateway initiative and its underlying CAMARA API framework, first unveiled at Mobile World Congress in 2023. Three years on, the numbers describe a genuinely large-scale rollout that has mostly happened out of public view. As of early 2026, 81 operator groups representing 292 networks and roughly 80% of global mobile connections have aligned around the common API framework, according to GSMA and CAMARA Project data. Thirty-three CAMARA APIs have been tagged and released, with another 40 in development, and 280 API instances have been commercially launched across 85 networks in 50 markets — up from a starting portfolio of just eight APIs in 2023.

Fraud prevention has emerged as the clear early winner. GSMA reports that the industry is now close to protecting two-thirds of the world’s mobile connections with commercial anti-fraud APIs, covering capabilities such as SIM swap detection, device swap detection, and number verification. Europe leads commercial deployment with 98 launched API instances, followed by Asia-Pacific and Latin America; North America, by contrast, trails with only 10 instances so far — a gap worth watching given how much enterprise AI investment is concentrated in the US.

Commercially launched CAMARA network-API instances by region, Q1 2026. Source: CAMARA Project / GSMA Open Gateway.

Why AI agents change the calculus

Identity verification APIs were originally sold as a way to replace weak SMS one-time passcodes with silent, network-level authentication. What has changed in 2026 is the buyer. As autonomous AI agents start filling out forms, initiating payments, and completing tasks on behalf of users with less and less human supervision, the question of how a system knows an agent — or the human behind it — is who it claims to be has become urgent. “They rely on trusted signals,” Chathurangi Wickramasinghe, SVP of Magenta Business API at Deutsche Telekom, said of AI agents in a July 2026 interview. “They need them to carry out their tasks autonomously.” Deutsche Telekom’s own Number Verify and SIM Swap APIs, launched with Vodafone and Telefónica O2 under Open Gateway, are already being positioned this way, including for RCS-based branded communications and pre-transaction fraud checks in financial services.

GSMA’s own materials go further, forecasting that 60% of enterprises will deploy some form of network-powered AI solution by the end of 2026, and pointing to early examples such as ShareID, which onboards users by email while silently verifying their phone number through network APIs and government digital identity — without storing biometric data. It’s a modest, unglamorous use case, and that is precisely why it has scaled faster than more ambitious “programmable network” ideas like guaranteed low-latency slicing.

This also sits adjacent to a more visible trend: Visa’s Trusted Agent Protocol and Mastercard’s Agent Pay, both introduced to let payment networks recognize legitimate AI shopping agents at checkout. Those protocols solve trust at the payment-token layer. Telecom network APIs solve a layer beneath that — whether the device and number behind a transaction are real and haven’t just been hijacked. The two are complementary, and it is not hard to see them converging over the next few years.

The fraud numbers behind the pitch

The commercial case for identity APIs rests on a real and measurable problem, though the picture is more mixed than the “fraud is exploding” headlines suggest. In the UK, Cifas-reported unauthorized SIM swap cases surged 1,055% year-over-year in 2024, reaching nearly 3,000 filed cases. Australia’s IDCARE reported a 240% increase in SIM-swap and phone-porting assistance requests in 2024 versus 2023, with 90% occurring without any victim engagement at all. Yet in the United States, FBI Internet Crime Complaint Center data tells a different story: reported SIM-swap complaints and losses actually declined, from 2,026 complaints and $72.7 million in losses in 2022 to 982 complaints and $26.0 million in losses in 2024. That divergence likely reflects reporting and detection differences rather than the threat disappearing, but it’s a reminder to treat any single fraud statistic with caution — and exactly the kind of nuance that gets flattened in vendor pitches.

Operators are responding by packaging fraud-prevention capability as a product rather than a raw API call. Telefónica, working with Nokia’s Network Exposure Platform and Network as Code, now bundles Number Verification, SIM Swap Detection, Device Swap Detection, and location data into identity-confidence scores, and is shifting billing toward outcomes — such as a completed fraud assessment — rather than per-call pricing. It’s a small but telling sign that operators see this as a durable enterprise product line rather than a developer novelty.

Worldwide CAMARA-based network API revenue, actual vs. forecast. Source: Analysys Mason, “Network APIs: worldwide forecast 2024–2030” (13 June 2025).

The money is real, but still early

Analysys Mason’s June 2025 forecast puts worldwide CAMARA-based network API revenue at $550 million in 2024, growing roughly 14-fold to $7.6 billion by 2030, or about 0.6% of total mobile service revenue. The regional mix is shifting sharply: China accounted for about 94% of 2024 revenue, but its share is projected to fall to roughly 37% by 2030 as adoption scales elsewhere, even as China’s absolute revenue keeps growing. Analysys Mason also flags a second act after 2030, with communication-quality APIs — things like on-demand bandwidth for video calls or cloud gaming — potentially pushing network API revenue toward 5% of mobile services revenue by 2035, an eight-fold jump from the 2030 base case. Separately, EY-Parthenon and Snowflake put the broader telecom data-monetization market, of which network APIs are one part, at $14.8 billion by 2029.

Those numbers are still small next to a telecom industry that generates well over a trillion dollars a year, and operators are candid about the gap between building APIs and getting enterprises to actually use them. “Building APIs is right now not the challenge,” Wickramasinghe said. “But scaling adoption is a challenge. No customer wakes up in the morning and asks for APIs. They have real business challenges they want to solve.” That is arguably the most honest sentence anyone in this space has said publicly this year, and it’s a fair caution against overreading the growth curve.

What to watch next

A few threads are worth tracking as this develops. First, whether outcome-based pricing — like Telefónica’s shift away from per-call billing — becomes the industry norm, since it would make network APIs easier for enterprise buyers and AI platform vendors to budget for. Second, whether North America closes its deployment gap; with only 10 commercially launched instances against Europe’s 98, the region most invested in agentic AI risks having the weakest identity-verification rails to build on. Third, whether CAMARA’s roughly 30 released APIs and 40 in development actually converge into a small number of dominant, well-supported ones, or fragment across regional variants that make cross-border AI agent deployment harder. And fourth, how the emerging telecom trust layer interacts with payment-network protocols like Visa’s and Mastercard’s agent frameworks, since enterprises deploying AI agents will not want to integrate a dozen separate identity systems.

None of this is a headline yet. But the operators, standards bodies, and enterprise buyers already moving on it are effectively betting that autonomous AI systems will need a way to prove that the device, number, and account behind them are real — and that telecom networks, which already know these things better than almost anyone else, are the logical place to buy that proof. That’s a quieter story than the next model release, but it may end up mattering just as much to how trustworthy the AI economy actually becomes.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *