Are Standards Still for Humans or Agents? In Conversation With Lorna Mitchell

Ahead of her Nordic APIs Summit 2026 talk on API standards for agents, TM Forum’s Lorna Mitchell joins us to talk about how — or whether — agentic has changed what good API design looks like.

There are those who believe that the rise of agentic API consumption will change what software development looks like beyond recognition, and some developers (who have always written their code with humans in mind) are understandably worried. But there is another possibility.

The first hot take of many — more of those below! — comes up early in our call with Mitchell, and it sets the tone for the conversation that follows: “If you’ve followed best practices around API design and documentation for the last five years, I believe you’re already AI-ready.”

The reasoning here is sound: if an API is well-documented, structured consistently, and built around established standards, there’s no reason to assume that its consumer being an AI agent rather than a human developer would suddenly change everything. The issue is, rather, that an agent’s lack of human intuition exposes weaknesses that humans have learned to work around.

Below, Mitchell draws on her time in the trenches of API development to outline how better catering for agents (without neglecting humans) doesn’t have to mean reinventing the wheel.

Less Ambiguity, More Context

We kicked things off by asking Mitchell what she considers to be some of the most vital changes to make when an API consumer is an AI agent rather than a human developer:

“Less ambiguity tends to be advantageous for agentic functions. The more details, metadata, and examples we can provide, the better. Fewer endpoints is often a good idea too.”

That last point is interesting because, when we think of AI tools, we tend to think of them as being capable of processing large inputs — and outputting large volumes of content — at a pace that’s impossible for a human to match. But when an AI agent has to “decide” which operation to call, abundance isn’t always a good thing. For a human developer, the difference between:

  • GET /customers/{id}
  • GET /customers/{id}/profile
  • GET /customers/{id}/details
  • GET /customer-information/{id}

…might be annoying but discoverable through documentation. For an agent, ambiguity in naming or descriptions can make multiple operations appear capable of accomplishing the same thing.

Good documentation has always been important but, in the age of agentic consumption, the context (descriptions, schemas, and so on) that surrounds an API is becoming more of a game-changer. Mitchell argues that embracing standards provides agents with “the vocabulary and behavioral expectations they need to operate reliably in unfamiliar domains.”

“Good API docs go a long way,” she states, “but standard description formats open up loads of other routes to existing tools.” Consider how some of the following standards and specifications can contribute to the ecosystem around agentic consumption:

  • OpenAPI → machine-readable descriptions of operations, parameters, and so on
  • JSON Schema → precise descriptions of data structures and validation
  • OAuth → established expectations around authentication and authorization
  • Arazzo → descriptions of workflows involving multiple API operations
  • MCP → a complementary mechanism for exposing tools and context to agents

“There’s plenty of general information about APIs already available in training data,” she continues, “then you can use the context window for specifics.” A standardized machine-readable description can be used, for example, to generate SDKs, tests, validation, and security checks.

AI for Some Things, but Not for Everything

Generally speaking, even though Mitchell seems bullish on the potential of AI when it comes to democratizing development, it isn’t yet in her production pipeline. “There’s a difference in the perspectives of people who want ‘AI everything’ — input, output, production systems, and so on — versus those who want it as augmentation, so the good work they’re doing is faster.”

She continues with another hot take: “I think the people who are vibecoding prototypes and think they’re taking over the world, they’re not the people who are going to get paged at 3 AM for a data breach. You might vibecode specific functions or use AI to implement something more quickly, but you still need people to review it. Development craft and discipline still matter.”

Technology may be changing, but the underlying need for accountability hasn’t. We talk about the risks of AI tools compounding and reinforcing bad practices that are, but shouldn’t be, commonplace. An agent that’s built around information that’s incomplete, outdated, or inaccurate might, for example, end up putting sensitive data at risk or attempt to plug into a poorly designed or undocumented API that a human developer wouldn’t touch with a bargepole.

Mitchell, a longtime OpenAPI Specification maintainer, says that she “isn’t really interested in having more Markdown in the specification file. I’m interested in cultivating the next generation of standards maintainers who are going to think carefully about how the world is moving and how the standard can evolve to support that.” Yes, that means agents, but it also means an awareness of how people are moving “sideways” into the software development space.

“All of the information is out there as basic software knowledge,” Mitchell says, “but some who want to move quickly and think, ‘oh, that doesn’t matter anymore because the agent’s got it.’ And the agent hasn’t got it, or you need to verify that it’s got it.” And there’s a high level of risk associated with setting agents free to work on tasks if you don’t understand what underpins them.

The Case for Boring APIs

There’s an idea in tech that an overreliance on standards and best practices can create homogeneity and result in products becoming — well, boring. The widespread adoption of trends like flat design and Corporate Memphis has resulted in many consumer apps and websites looking very much like one another.

Of course, that idea isn’t unique to tech: in the world of fast food, Wendy’s, McDonald’s, and Burger King all look the same now. As production costs rise and competition becomes fiercer, innovation becomes a much bigger risk, whether you’re developing software or selling burgers.

But, in an ironic twist, it may be the more “boring” APIs and services that are now best-positioned to capitalize on the rapid growth of agentic consumption — when APIs are meticulously documented and carefully defined for specific use cases, clarity and the effective use of standards can improve discoverability and accelerate what agents are capable of.

Even so, there are steps that organizations that are already using specifications and standards effectively can take to add useful context for AI agents. “Use modern versions,” Mitchell suggests. “Add metadata, create versions specific to different capabilities and contexts. Enrich standards with descriptions and examples. Give all the clues to agents that you can.”

It remains to be seen what the balance between agentic and human consumption will look like in five years, or even five months. But the good news is that, to return to Mitchell’s earlier point, almost everything that improves clarity for AI agents also improves clarity for human consumers. As such, there’s really no such thing as “wasted time” when implementing standards effectively.

AI Summary

This article explores Lorna Mitchell’s view that organizations following established API design, documentation, and standards practices may already be well prepared for AI agent consumption.

  • AI agents benefit from APIs with less ambiguity, fewer overlapping operations, clear descriptions, strong metadata, and concrete examples because agents cannot rely on the same intuition human developers use to navigate unclear interfaces.
  • Standards such as OpenAPI, JSON Schema, OAuth, Arazzo, and MCP can provide machine-readable structure, behavioral expectations, workflow context, and mechanisms for exposing tools to agents.
  • Mitchell argues that AI should augment software development rather than replace engineering discipline, emphasizing the continued need for human review, accountability, and an understanding of the systems underlying agent actions.
  • Well-established standards and “boring” APIs may be advantageous for agentic consumption because predictable structures, detailed documentation, and clearly defined use cases improve discoverability and reduce ambiguity.
  • API providers can further support agents by using modern specification versions, adding metadata, providing descriptions and examples, and creating representations suited to different capabilities and contexts.

Intended for API designers, architects, developers, and platform teams preparing APIs and software systems for increased consumption by AI agents.