TAMPA — In recent years, the Zero Trust concept of cybersecurity where users and devices are subjected to multiple levels of authentication was thought to be the final answer to protecting data and intellectual property.
But now artificial intelligence (AI) and especially agentic AI — where bots crawl through networks sometimes with a mind on their own to complete assigned tasks — is forcing the Defense Department and Intelligence Community (IC) to rethink how it implements Zero Trust at the enterprise level, according to the IC’s chief information officer.
Because agentic AI is designed to operate autonomously, it may need broad access to data, tools, and systems, making identity and precisely controlled permissions increasingly important to the government’s Zero Trust strategy.
“If users and devices are going to request, store, and manipulate process data, so will AI agents,” said IC Chief Information Officer Douglas Cossa, speaking Monday at the Defense Intelligence Agency’s DoDIIS conference. “The challenge we have is that this new realm of AI has completely spun ZeroTrust on its head, where we went from a model of least privileged access or no access to now giving [an AI] model and agent everything it needs to be operating independently. Those are two different things, and the only way that we’re going to be successful in that is if we start with a common identity system.”
How does the enterprise establish and control the identity of a non-human user like an autonomous bot?
Cossa said the government does not currently have a unified identity system across agencies for such a task. The emerging requirement is essentially a digital birth certificate not only for people and devices, but also for AI agents capable of requesting, storing, manipulating, and processing information. That identity becomes the foundation for determining what autonomous agents are permitted to do.
Moving in that direction, the IC CIO office has invested in developing an enterprise service for identity management, with plans to begin piloting and testing tools in operational environments this fall as the IC heads into fiscal 2027, according to Cossa.
A second piece of the challenge is policy enforcement by controlling what information people, devices, and AI agents can reach while also ensuring data can move quickly to authorized users and functions.
“We tend to think of cybersecurity as friction prohibiting a function from occurring,” said Cossa. “In reality, if we do Zero Trust how we’ve defined it, which is getting your identity down and doing fine-grain entitlements to get data exactly to the functions that need it, it becomes a key mission enabler.
“Zero Trust for us has been redefined as identity and policy enforcements of fine-grain attributes,” he said. “That is how we are defining Zero Trust in the Intelligence Community. And that will be one of our newest services of common concern this year.”
AI For Cybersecurity In Special Operations
The IC is not tackling the agentic AI challenge alone, though. That same shift toward Zero Trust automation is also changing how Special Operations Command thinks about defending its networks.
Adm. Frank Bradley, commander of US Special Operations Command, said future cyber defenses cannot depend on people manually reviewing logs or reconfiguring trust decisions during a crisis. SOCOM instead wants networks that can detect compromise quickly, incorporate context such as device health, location, and behavior into access decisions, and increasingly respond automatically.
“We need to know we were compromised in minutes and not months, working toward systems that can auto defend — agentic defense against agentic offense,” he said.
Even if those defenses improve, Bradley said adversaries will increasingly shift their focus to what he called “human frailty.” The vulnerability may be a lapse in discipline, a failure to follow protocol, or simple exhaustion after sustained operations.
“Increasingly, the target will become human frailty rather than machine frailty,” he said. “Humans are imperfect. That is not a flaw to engineer away. It is a condition that we need to design for.”
Bradley said layered defenses, compartmented access, and need-to-know restrictions enforced at the data level can help contain the damage caused by a single human mistake.