| Edition 17 | 8 September 2026 | Series: The security study |
The architecture arc ended with a question: what does a network full of other people’s software agents have to be defended against? SA3 has an answer in progress, and it has a number. Where SA2 files its 6G drafts by key issue, SA3 files by security area — and the one rewritten ten times in the last week of August is the area about agents on handsets.
| Quarter | Track | Milestone |
|---|---|---|
| Q2 2026 TSG#112 | SA / CT | Rel-21 timeline agreed; TR 38.914 v1.0.0 approved done |
| Q3 2026 TSG#113 | SA / CT | Rel-20 SA Stage 2 complete |
| Q4 2026 TSG#114 | RAN | Rel-20 RAN1 functional freeze |
| Q1 2027 TSG#115 | RAN | Rel-20 RAN2/3 & RAN4-core functional freeze ⚑ freeze |
| Q1 2027 TSG#115 | SA / CT | Rel-20 Stage 3 freeze (SA/CT) · Rel-21 package + 6G work items approved (Stage 1 freeze) ⚑ freeze |
| Q2 2027 TSG#116 | RAN | Rel-20 RAN4 performance |
| Q2 2027 TSG#116 | SA / CT | Rel-20 ASN.1 & OpenAPI freeze |
| Q3 2028 TSG#121 | RAN | Rel-21 RAN1 functional freeze |
| Q3 2028 TSG#121 | SA / CT | Rel-21 SA Stage 2 complete |
| Q4 2028 TSG#122 | RAN | Rel-21 RAN2/3 & RAN4-core functional freeze ⚑ freeze |
| Q4 2028 TSG#122 | SA / CT | Rel-21 Stage 3 freeze (SA/CT) ⚑ freeze |
| Q1 2029 TSG#123 | SA / CT | Rel-21 ASN.1 & OpenAPI freeze |
Transcribed from 3GPP’s published Release 21 timeline (© 3GPP 2026). The highlight stays where the architecture arc left it: SA3 is an SA working group, and whatever this study concludes becomes normative security work on the same SA track.
A#10 Highest security area seen in file names | 16× Draft growth, v0.4.0 to v0.5.0 | r10 Revisions of one agent-security draft in 5 days |
TR 33.801-01 is “Study on Security for the 6G system”. Responsible group SA3, Release 20, status draft, specification rapporteur Todor Gamishev of Orange. It is the security counterpart to the architecture study this newsletter spent Editions 14 to 16 on, and it is a much smaller document.
The version archive says how much smaller, and when that changed. Six files sit in the 33 series folder: v0.0.0 at 112 KB in October 2025, a v0.1.0 that shrank to 89.5 KB later that month, then 124.8, 142.8 and 160 KB through to April 2026 — and then v0.5.0 on 25 June 2026 at 2,549.1 KB, sixteen times its predecessor in one meeting cycle. The architecture study was at 82,720 KB by July. These are compressed Word files with figures inside, not page counts, but the curve has the shape TR 23.801-01 showed: flat while a group argues about what the document is for, then a step when solutions arrive.
Each 3GPP group files its 6G drafts differently, and the filing is a map of how the group thinks. RAN4 files by agenda item, RAN3 by conference block, SA2 by key issue — twenty-four folders, one each. SA3 does none of these. Its drafting inbox is flat, and the structure lives in the file names, which run A#<area>, then KI#<area>.<n>, then a solution.
So a key issue in SA3 belongs to an area and carries the area’s number in its own: KI#3.4 is the fourth key issue of area three. Roughly two hundred drafts were filed into that inbox between 24 and 28 August 2026 — the week of SA3#129, Prague. Seven area numbers appear in them.
| Area | What its August drafts are called |
|---|---|
| A#2 | Xn handover forward security; a new solution on RAN mobility, under KI#2.2 |
| A#3 | Multiple NAS security termination points; a dedicated NAS security context — KI#3.1 through KI#3.6 |
| A#4 | Certificates, at KI#4.1 and KI#4.5 |
| A#6 | “Security Aspects of In-band Exposure” |
| A#8 | Four new key issues, all on AI agents running on the UE |
| A#9 | Two update files and nothing that names its subject |
| A#10 | Privacy for sensing; authorisation and revocation for sensing service consumers |
Where the areas came from is on the same server. SA3’s email-discussion folder for FS_6G_SEC keeps files from November 2025, each named “New Security Area on” something: core network security, network exposure, secure UE identifiers, security architecture, interconnect and roaming, the data framework, security visibility and configurability, user consent, sensing, security monitoring, AI/ML security, low-layer security. Their document numbers are placeholders — S3-25xxxx — written before numbers were allocated. A group drafting its own table of contents in public, a year before the drafts above.
Edition 16 ended on KI#19, SA2’s 6G Network for AI, promising this edition would name the attacker. Area 8 is where SA3 is doing that, and its August drafts read as a checklist of what a subscriber identity provides and an agent identity does not: “New key issue on UE AI agent authentication”, “New key issue on UE AI agent authorization”, “Secure UE AI agent ID assignment/(pre)configuration”, and “Transmission Security for UE AI agent”.
That last one is the busiest document in the inbox. It arrives as S3-263600 on 27 August and reaches r10 at 10:02 on 28 August — ten revisions in two days, six of them between 08:22 and 10:02 on the final morning. Nobody outside the room knows what changed between them; the sequence shows only that agreement did not come quickly.
A phone has a SIM, a subscription and one identity the network trusts. An agent on that phone has none of those, and four separate key issues now exist to give it some.
Vesa Lehtovirta of Ericsson surveyed SA3’s 6G work on 28 April 2026 and described it as three overlapping areas: generation-independent topics, baseline connectivity security, and new capabilities beyond connectivity. SA3, he writes, has begun “exploring how to evolve security for a future shaped by artificial intelligence (AI), integrated sensing and communication (ISAC), network exposure, post-quantum cryptography and new ways of connecting people and things”, and the shift he describes runs from boundary defence — “attackers are assumed to act at these boundaries” — to assuming “breaches may already exist or could occur at any time”.
Read that as an expert’s summary, not the document’s structure. It names no TR, and its three areas are not the numbered areas above. The echo of Tao Sun’s Connectivity and Beyond connectivity split for SA2 is ours to notice, and worth nothing more than noticing.
A company view sits in the study’s own email discussion. A Qualcomm paper filed to the August 2025 conference call proposes forward and backward security by design in RAN mobility, per-service user-plane termination, verification of messages sent before the AS Security Mode Command, separate security anchors at home and visited networks, and a device appraisal policy gating service access. Areas 2 and 3 look like descendants of the first two. It is a proposal, from one company, and a year old.
What this edition could not read, and what that costs
Only one rapporteur is named above, and that is a gap, not a choice. Edition 14 established that a study has two records — specification and work item — which can name different people, neither wrong. The specification record read cleanly. The work item record for FS_6G_SEC, UID 1090044, did not: twice the portal returned a different work item entirely, FS_5GSTAR at UID 880011, a 2020 study on AR glasses. So no work-item rapporteur here, and no start or end date for the study.
No document in this edition was opened. Every file named is a Word document, and Word documents on the 3GPP server refuse to serve, as they have all series. Area numbers, key-issue numbers, revision numbers and titles are read from file names, sizes and timestamps.
A#10 is the highest area number visible, not a count of areas. No draft in the window carried A#1, A#5 or A#7. That is silence in one folder over one week, and nothing else.
The November 2025 list is a list of proposals. Files titled “New Security Area on” are requests to create areas; nothing says which were adopted, merged or dropped, and the numbering above cannot be mapped onto them from outside.
The meeting attribution is ours. SA3#129’s dates — Prague, 24 to 28 August 2026 — come from the primary calendar, and the drafts’ timestamps fall inside them; the folder carries no meeting label. That calendar also returned no row for SA3#131, which may be a fetch artefact.
Sources
Daily Dose of 6G — tracking 3GPP Release 20's 6G study phase, one study at a time. Timeline after 3GPP's published Release 21 schedule.