“This new realm of AI has completely spun Zero Trust on its head,” Intelligence Community CIO Douglas Cossa told attendees at the DoDIIS 2026 conference in Tampa, highlighting the fundamental conflict between autonomous agents and legacy security: agents need expansive, independent access to function, while traditional models are built to restrict it. Because no unified identity system for non-human users currently exists across agencies, the IC is now proposing “digital birth certificates” for AI agents — a move that signals where agent identity infrastructure is heading.
According to a report by Breaking Defense, Cossa articulated the core problem: “where we went from a model of least privileged access or no access to now giving [an AI] model and agent everything it needs to be operating independently. Those are two different things, and the only way that we’re going to be successful in that is if we start with a common identity system.” The solution he proposed — digital birth certificates for people, devices, and AI agents — would establish a verifiable, foundational identity for non-human actors from the moment of their creation.
This proposal reflects a broader shift across the defense community toward machine-speed resilience. At the same conference, Adm. Frank Bradley, commander of US Special Operations Command, called for systems that can “auto defend — agentic defense against agentic offense,” pushing for compromise detection measured in minutes rather than months. Bradley also reframed the vulnerability surface: “Increasingly, the target will become human frailty rather than machine frailty. Humans are imperfect. That is not a flaw to engineer away. It is a condition that we need to design for.” His point reinforces the case for autonomous agents that can enforce layered defenses and compartmented access at machine speed, reducing dependence on human vigilance during sustained operations.
Currently, the IC lacks any unified identity system across agencies for non-human users. The IC CIO office is investing in an enterprise identity management service that treats agents as first-class entities alongside people and devices. As Cossa put it: “If users and devices are going to request, store, and manipulate process data, so will AI agents.” The goal is a model where identity functions not as a security gate but as core infrastructure — enabling agent interoperability, lifecycle management, and programmable access control across the intelligence enterprise.
The market is already pricing in this infrastructure deficit. Cyera’s $1 billion acquisition of Oasis Security — the largest deal in non-human identity security to date — underscores the commercial urgency behind solving identity and data governance for autonomous agents. As these “digital birth certificates” evolve from government concept toward formal standard, they will provide the scaffolding organizations need to manage increasingly complex agentic workflows.
Under Cossa’s framework, Zero Trust itself is being redefined. “Zero Trust for us has been redefined as identity and policy enforcements of fine-grain attributes,” he said. “That is how we are defining Zero Trust in the Intelligence Community. And that will be one of our newest services of common concern this year.” This shift points toward a future where the provenance and capabilities of an agent are programmatically verifiable at creation, rather than bolted on through retrofitted access controls.
The IC plans to begin operational pilots for its enterprise identity service in fall 2026, moving from conceptual design to practical implementation as the community enters fiscal 2027. The approach offers a potential blueprint for enterprise adoption: integrate agentic AI without sacrificing the visibility and control required for complex, multi-agent environments. As pilots begin, the focus will be on building a scalable system that can accommodate the unique operational requirements of autonomous agents — from cryptographic proof of identity to fine-grained capability scoping and verifiable provenance.