AI Agents Need a Birth Certificate. The Government Just Said So.

ai digital birth certificate portnox

Schedule a Portnox Cloud demo today.

Contents

For years, zero trust has run on a simple assumption: verify every user and device before granting access, and grant as little access as possible. That model worked when the things requesting access were humans logging in or laptops checking in. It starts to break down when the thing requesting access is an AI agent that was built to act independently, at machine speed, across dozens of systems at once.

That tension just got a very public airing. At the Defense Intelligence Agency’s DoDIIS conference this month, Intelligence Community CIO Douglas Cossa said the quiet part out loud, as reported by Breaking Defense: agentic AI has “completely spun zero trust on its head.” Instead of the old default of least privilege or no access, organizations are now handing AI agents everything they need to operate on their own. Those are two fundamentally different postures, and Cossa was blunt about the only way to reconcile them: start with a common identity system.

His proposed fix has a name that sticks: a digital birth certificate. Not just for people and devices, but for every AI agent capable of requesting, storing, and manipulating data.

Why this matters beyond the Beltway

It’s tempting to file this under “interesting government IT problem” and move on. Don’t. Cossa’s comments land on the exact fault line every enterprise security team is standing on right now, federal or not.

The reason is structural, not political. Zero trust was designed around a stable population of identities: employees, contractors, servers, laptops. You could provision them, badge them, and audit them on a predictable cadence. AI agents don’t behave that way. They get spun up dynamically, sometimes by other agents, often for a single task, and then they’re gone. There’s no HR onboarding flow for a bot that a developer created in a script an hour ago. There’s frequently no directory entry at all.

That’s the gap Cossa is naming. If an organization can’t answer “what is this agent, who or what created it, and what should it be allowed to touch,” then no amount of network segmentation or endpoint hardening closes the hole. The agent is invisible to the very system meant to govern it.

The identity problem comes before the access problem

This is worth sitting with, because it’s easy to jump straight to permissions (“just limit what the agent can do”) without solving identity first. But permissions are meaningless without a durable, verifiable identity to attach them to. You can’t enforce least privilege for something you can’t consistently recognize.

That’s precisely why Cossa framed the fix as an identity system, not an access-control policy. A birth certificate for an AI agent would need to establish, at minimum: what created the agent, what it’s authorized to do, how long it should exist, and how its behavior can be traced back to a human or system of record. Only once that identity is established does the access conversation even start.

This is also where the market is already voting with its wallet. Non-human identity has become one of the fastest-moving categories in security funding and M&A, with billion-dollar deals underscoring how urgently organizations are trying to solve exactly this problem for machine and agent identities. The government’s framing and the market’s spending are pointing at the same conclusion from two different directions.

Where enforcement has to live

A birth certificate is only useful if something can actually check it, continuously, at the moment an agent tries to touch a network, a device, or a resource. That’s the part that often gets lost in identity conversations: issuing an identity is not the same as enforcing what that identity is allowed to do in real time.

This is precisely the layer where network-based access control earns its place alongside identity and access management. IAM and PAM tools are good at defining who and what an identity is and what it’s entitled to. But enforcement, the actual moment-to-moment decision of whether to let an agent onto the network, talk to a device, or reach a resource, has to happen at the access layer, continuously and automatically, because agentic AI doesn’t wait for a quarterly access review.

Put simply: every AI agent is an identity, and every identity needs the same governance discipline applied to human and device identities before it. The Intelligence Community just confirmed, from the inside of one of the most security-conscious organizations in the world, that this isn’t a theoretical concern. It’s the next required layer of zero trust.

The question isn’t whether AI agents need identities. It’s how quickly organizations can build the infrastructure to issue, verify, and enforce them before the gap Cossa described gets exploited instead of governed.

Share

About the Author

Picture of Michael Marvin

Michael Marvin

Michael Marvin is VP of Product Marketing at Portnox, where he leads product marketing, content strategy, PR, and communications. His work spans positioning and messaging, analyst relations, competitive intelligence, and thought leadership — with a focus on making zero trust and network security legible to the people who actually have to buy and deploy it.

About the Author

Picture of Michael Marvin

Michael Marvin

Michael Marvin is VP of Product Marketing at Portnox, where he leads product marketing, content strategy, PR, and communications. His work spans positioning and messaging, analyst relations, competitive intelligence, and thought leadership — with a focus on making zero trust and network security legible to the people who actually have to buy and deploy it.

Related Reading

Compliance & Regulations

Congress Wants a Kill Switch for AI. The Real Fix Is Access Control.

August 19, 2026
Network Access ControlSecurity TrendsZero Trust

We Gave an AI Agent a Login and Watched It Go Rogue. Here’s What Happened Next. 

August 18, 2026
Cyber Attacks

Hackers Just Vished Wall Street’s Biggest Hedge Funds. Here’s the Access Control Lesson.

August 7, 2026

Portnox Gives Enterprises an AI "Kill Switch"

X