Federal Intelligence Chief Says AI Agents Need Birth Certificates
Federal Intelligence Chief Says AI Agents Need Birth Certificates
As its name suggests, the Zero Trust cybersecurity concept says users/devices should not automatically be trusted.
However, security experts are now rethinking that approach amid the rise of agentic artificial intelligence (AI), Doug Cossa, intelligence community chief information officer at the Office of the Director of National Intelligence, said this week.
“If users and devices are going to request, store, and manipulate process data, so will AI agents,” said Cossa, whose comments at the Defense Intelligence Agency’s DoDIIS conference were reported by Breaking Defense. “The challenge we have is that this new realm of AI has completely spun Zero Trust on its head, where we went from a model of least privileged access or no access to now giving [an AI] model and agent everything it needs to be operating independently. Those are two different things, and the only way that we’re going to be successful in that is if we start with a common identity system.”
Cossa said the government does not yet have a unified identity system across agencies for establishing and controlling the identity of something like an autonomous bot.
The emerging requirement is essentially a digital birth certificate not just for people and devices, but also for AI agents that can request, store, manipulate and process information. That identity forms the basis for deciding what agents are allowed to do, Cossa said.
He added that his office has invested in the creation of an enterprise service for identity management, with plans to start piloting and testing tools in operational environments this fall as the government moves into its next fiscal year.
In related news, a recent report from the International Monetary Fund (IMF_“Artificial Intelligence and Cybersecurity in the Financial Sector”—argues that AI does not need to invent new kinds of cyberattacks to pose greater threats.
As covered here earlier this week, the IMF found that AI can boost vulnerability discovery and exploitation across shared technologies. In doing so, it can turn weaknesses that once led to isolated incidents into connected disruptions targeting multiple institutions at the same time.
“That is a major development because the question is no longer only whether AI can write better phishing emails or help security teams sort through alerts,” PYMNTS wrote. “The question is what powerful models can do when given tools, credentials, network access or a poorly configured test environment.”
Related Stories
AI News
Splitit CEO Says Payments Firms Must Build for AI, Not Just Use It
46 minutes ago
AI News
Oumi Want Every Enterprise to Build Its Own AI Brain
47 minutes ago
AI News
Anthropic IPO: Five things to know before its Wall Street debut
47 minutes ago
AI News
Musk's SpaceX to build $100bn launch facility in Louisiana
1 hour ago
AI News
Bill Gates issues AI warning on jobs, child development, crime
1 hour ago
AI News
Billionaire investor says he used AI to write critique of former mentee Scott Bessent
1 hour ago
AI News
Foreign AI is unavoidable. Australia’s challenge is in application
2 hours ago
AI News
Claude Cowork finally remembers what you told the app in chat
2 hours ago