Agentic AI turning Zero Trust cybersecurity 'on its head' - Breaking Defense
Agentic AI raises an important security question: How should organizations authenticate and govern autonomous, non-human users? This Breaking Defense article explores why identity management, fine-grained permissions and policy enforcement are becoming central to Zero Trust strategies as AI agents gain greater autonomy. Read it for perspective on a cybersecurity issue likely to grow alongside agentic AI. Connect with Five Nines IT Solutions Inc. to discuss how these trends may influence your organization's technology strategy.
How is agentic AI changing the way organizations think about Zero Trust?
Agentic AI systems are designed to operate autonomously, moving across networks, requesting data, and using tools to complete tasks without constant human direction. That behavior doesn’t fit neatly into traditional Zero Trust models that focus on least-privilege access for human users and devices.
According to Intelligence Community CIO Douglas Cossa, this new class of AI has effectively turned classic Zero Trust “on its head.” Instead of starting from a stance of minimal or no access, organizations often need to give AI agents broad access so they can operate independently. That creates tension with long-standing security principles.
To adapt, the Intelligence Community is reshaping Zero Trust around two pillars:
- Identity as the foundation: Treating AI agents as first-class identities, not just background processes, and giving them clearly defined, verifiable digital identities.
- Fine-grain policy enforcement: Using detailed entitlements and attributes to control exactly which data and functions each AI agent can reach, rather than broad, static permissions.
In this reimagined model, Zero Trust becomes less about blocking activity and more about enabling the right AI-driven functions to access the right data, under tightly controlled conditions.
What is a digital birth certificate for AI agents, and why does it matter?
The Intelligence Community is exploring the idea of a “digital birth certificate” for AI agents as a way to establish and manage their identities across agencies.
Today, there is no unified identity system for non-human users like autonomous bots. As AI agents begin to request, store, manipulate, and process data at scale, that gap becomes a core security risk.
A digital birth certificate would:
- Uniquely identify each AI agent from the moment it is created.
- Record key attributes such as its purpose, owner, and authorized environments.
- Serve as the basis for permissions—what data it can access, what tools it can use, and what actions it can take.
Cossa’s office is investing in an enterprise identity management service to support this approach, with plans to pilot and test tools in operational environments as the Intelligence Community moves into fiscal year 2027. The goal is to make identity the starting point for any decision about what an AI agent is allowed to do.
How are defense organizations automating cyber defense against agentic threats?
US Special Operations Command (SOCOM) is rethinking how it defends networks in an environment where both attackers and defenders are using agentic AI.
Adm. Frank Bradley emphasized that future defenses cannot rely on humans manually reviewing logs or reconfiguring trust settings during a crisis. Instead, SOCOM is working toward networks that can:
- Detect compromise in minutes, not months, by continuously monitoring for anomalies.
- Incorporate context—such as device health, location, and behavior—into access decisions.
- Respond automatically, enabling what Bradley called “agentic defense against agentic offense.”
At the same time, SOCOM expects adversaries to focus more on human frailty—lapses in discipline, protocol failures, or simple exhaustion—rather than purely technical flaws. To design for that reality, they are emphasizing:
- Layered defenses that don’t rely on a single control.
- Compartmented access so that one mistake doesn’t expose everything.
- Need-to-know restrictions enforced at the data level to contain the impact of human error.
Together, these shifts show how defense organizations are using automation and fine-grained controls to reimagine Zero Trust for a world where both machines and people are active participants in cyber operations.

Agentic AI turning Zero Trust cybersecurity 'on its head' - Breaking Defense
published by Five Nines IT Solutions Inc.
Your business needs a solid technology platform upon which to build and operate. Despite all the hoopla, big monitors and fast computers are simply not enough. You need to consider the foundation and the underpinnings that make IT safe and reliable for your business.
Five Nines IT Solutions is here to blow away the smoke and to give you the straight goods. We'll help you find the weaknesses, plug the gaps, shore up your defences and keep an eye on things so that you can focus on your business. When you're ready, we'll work with you to move to the next level.
Five Nines delivers a team of IT professionals to work with you, your staff and your infrastructure. From strategic solution design and implementation through service and ongoing support, we combine best-of-breed hardware and software solutions with superlative technical expertise to provide you with the very best results.
Once everything is up to snuff, working well and helping you make money, the Five Nines offers "Help Desk as a Service" to watch your back as you move forward. With over a hundred highly-trained help desk mentors working from locations throughout Canada, top-notch support is available 24/7/365 to ensure you get the most out of your investment in technology.