You can run just about anything over AX.25 since it's just the data link layer in the OSI model. You could run HTTP on top of IP on top of AX.25 with TLS/SSL message encryption turned off so you don't run afoul of FCC rules. The authentication would still be there but everything would be in the clear. You could also run IPsec with just the authentication field in the header, no encryption. Even if you didn't want to get that deep into the layers, you can always just pgp sign your messages on packet radio. Depending on the signature length, it could take several extra seconds to send the pgp signature at the typical 1.2Kb/s!
Decreasing the complexity of the stack is a good move forward. The speeds of packet radio require a custom protocol that limits overhead but leaves options for authentication and message signing. Some hams have been using packet radio at wifi frequencies which basically creates a wireless WAN with much higher data rates, making any of the authentication methods much quicker.