Rethinking Zero Trust: Why AI Agents Require a “Digital Birth Certificate”
For decades, the zero-trust security paradigm has been anchored by a simple rule: verify every user and device, and enforce the principle of least privilege. This framework is highly effective when managing human logins or standard corporate endpoints. However, it quickly deteriorates when introduced to agentic AI—autonomous programs designed to operate independently, at machine speed, across a web of interconnected systems simultaneously.
This escalating friction was recently thrust into the spotlight. At the Defense Intelligence Agency’s DoDIIS conference, Douglas Cossa, CIO of the Intelligence Community, openly addressed the elephant in the room. As reported by Breaking Defense, Cossa admitted that agentic AI has “completely spun zero trust on its head.” Rather than defaulting to restricted access, enterprises are outfitting AI agents with broad capabilities to fulfill their autonomous tasks. To bridge these two conflicting security postures, Cossa proposed a definitive solution: a unified identity framework.
His proposed fix is as memorable as it is necessary: a digital birth certificate. This concept must extend beyond human users and hardware to encompass every AI agent capable of requesting, storing, or manipulating data.
A Structural Enterprise Crisis, Not Just a Government Problem
It would be a critical mistake for private enterprises to dismiss this as merely an isolated public-sector dilemma. Cossa’s observations highlight a structural vulnerability that every corporate security team is currently facing.
Traditional zero-trust architectures were engineered for static populations—employees, contractors, servers, and laptops. These entities undergo predictable lifecycles of provisioning, auditing, and offboarding. AI agents, conversely, defy these rules. They are generated dynamically (sometimes autonomously by other agents) to execute hyper-specific tasks, and then they vanish. There is no standard HR onboarding process for a bot spun up via a developer’s script an hour ago, leaving it entirely absent from conventional active directories.
This is the exact vulnerability Cossa is highlighting. If an organization cannot clearly define what an agent is, who deployed it, and what its operational boundaries are, traditional defenses like network segmentation become obsolete. The agent remains a ghost, effectively invisible to the governance systems designed to police it.
Identity Must Precede Access Control
Security teams frequently attempt to solve the access problem first by simply trying to restrict what a bot can do. However, assigning permissions is futile without a persistent, verifiable identity to anchor them to. You cannot effectively enforce least privilege on an entity you cannot consistently recognize.
This is precisely why Cossa framed the solution as an identity system rather than a standard access-control policy. An AI agent’s “birth certificate” must establish several core attributes before any access is granted:
- Origin: Who or what system created the agent?
- Authorization Scope: What specific tasks and systems is it permitted to interact with?
- Time-to-Live (TTL): How long is this agent authorized to exist before it expires?
- Accountability: How can its actions be definitively traced back to a human operator or system of record?
The broader cybersecurity market is already voting with its wallet on this issue. Non-Human Identity (NHI) management has surged as one of the fastest-growing sectors for venture funding and acquisitions. Billion-dollar deals underscore how urgently the private sector is scrambling to secure machine and agent identities. Government framing and market spending are rapidly converging on the exact same conclusion.
The Necessity of Real-Time Enforcement
Establishing an identity is only half the battle. An AI’s birth certificate is useless unless systems can continuously verify it the exact moment the agent attempts to interact with a network, endpoint, or dataset. Issuing an identity and enforcing its boundaries are two very different operational challenges.
This is where network-based access controls must seamlessly integrate with Identity and Access Management (IAM) and Privileged Access Management (PAM) platforms. While IAM and PAM define the entity and its entitlements, the actual enforcement—the split-second decision to permit or deny access—must occur continuously at the network layer. Agentic AI operates far too rapidly to be governed by static, quarterly access reviews.
The Road Ahead
Ultimately, every AI agent is an identity, demanding the exact same rigorous governance historically applied to humans and hardware. The US Intelligence Community’s stance confirms that securing non-human identities is no longer a theoretical exercise—it is a mandatory evolution of the zero-trust model.
The defining question is no longer whether AI agents need identities, but how rapidly organizations can deploy the infrastructure needed to issue, verify, and enforce them before these invisible gaps are actively exploited by threat actors.
About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


