September 15, 2026
AI agents are moving rapidly from experimental software into business systems where they can access sensitive data, communicate with customers, write code, use software tools and take actions with limited human involvement.
But a basic question has not been adequately answered: How does an organization know who an AI agent is, who is responsible for it, what it is authorized to do—and how to stop it if that trust changes?
Lehi-based DigiCert believes the answer can be found in a technology the internet has relied on for decades: cryptographic identity.
On September 15, DigiCert announced the general availability of DigiCert AI Trust Manager, part of the DigiCert ONE platform. The system is designed to discover AI agents operating within an organization, establish verifiable identities tied to accountable owners, define what those agents are authorized to do and provide a mechanism for revoking that authority.
At the center of the approach is what DigiCert calls the AI Passport—a cryptographically signed credential intended to give an AI agent an identity that can travel with it as it interacts with systems beyond its original organization.
The concept addresses a problem that becomes more complicated as AI agents become autonomous and increasingly interconnected.
“You can't kill something you can't identify,” said Mike Nelson, DigiCert's Field CTO who sat down this week with TechBuzz to discuss DigiCert's newly released AI Trust Manager and the DigiCert ONE platform.
For Nelson, establishing identity is therefore the starting point for controlling an AI agent.
“There are agents all over the place that have no identity,” he said. “The first thing that you need to do is you need to provision identity to all agents.”
Applying the internet's trust model to AI
DigiCert has spent more than two decades operating as a certificate authority, providing cryptographic infrastructure used to establish trust between systems on the internet.
Nelson sees a direct analogy between that infrastructure and the emerging problem of AI agents.
When a user connects to a website, certificates and trusted certificate authorities provide a mechanism for the user's device to determine whether the website's identity can be trusted. Those credentials can expire or be revoked when trust changes.
DigiCert is applying similar principles to AI agents.
“We provision certificates to web servers, and it gives them a digital identity that can be trusted when someone's trying to communicate with it,” Nelson said. “And if that digital identity expires or is revoked, it no longer has the ability to securely communicate because it's not trusted anymore.”
AI Trust Manager applies that concept to autonomous software agents. An agent receives a cryptographic identity, that identity can be distributed through trust stores, and organizations can establish policies governing what the agent is permitted to do.
The objective is to create a trust framework that can operate at scale rather than requiring every organization to develop its own mechanism for identifying and controlling agents.
DigiCert describes the AI Passport as a portable credential that establishes an agent's identity and connects it to an accountable owner. Policy-based “visas” then define the agent's permitted activities, including which systems or data it can access, which actions it can perform and how long that authority remains valid.
The distinction between identity and authorization is important.
An agent can have a legitimate identity without having permission to access every system or perform every action available to it. The Passport answers the question of who the agent is; the visa establishes what it is allowed to do.

Beyond the walls of a company
That distinction also explains how DigiCert sees AI Trust Manager fitting into the existing enterprise security landscape.
The company is not positioning the technology as a replacement for identity and access-management platforms such as Okta or Microsoft Entra ID.
Instead, DigiCert describes AI agents as a new category of machine identity that must coexist with existing systems.
“It's not a replacement,” Nelson said. “It's a new type of identity that needs to be managed within an organization.”
The difference, he said, is what happens when an agent leaves the organization's boundaries.
Traditional enterprise identity systems are largely designed to establish and manage trust within an organization's own environment. An AI agent, however, may be instructed to communicate with an outside vendor, access an external service or interact with another organization's systems.
DigiCert's Passport is designed to make that identity portable.

“It's like a global passport that allows you to communicate securely outside of the walls of the organization,” Nelson said.
The receiving organization can independently verify the agent rather than relying on a shared identity provider or a previously established relationship with the organization that operates the agent.
That capability is increasingly relevant as businesses connect AI agents to third-party applications and services.
The 2025 Salesloft/Drift security incident illustrated some of the complications that can arise when a compromised third-party integration is connected to numerous customer environments. According to Google Cloud's threat intelligence reporting, attackers used compromised credentials associated with the Salesloft Drift integration to access data in Salesforce environments.
The broader issue for agentic AI is that trust established in one environment does not necessarily answer the questions another organization needs to ask: What exactly is this agent? Who is accountable for it? What is it authorized to do? And can its authority be revoked?
DigiCert is attempting to provide a portable answer to those questions.
First, find the agents
There is another problem that comes before identity: organizations need to know which AI agents they have.
Nelson said many security executives cannot yet answer basic questions about their organizations' AI agents.
“Do you know what agents are operating within your organization?” he asked. “Do you know what they're doing? Do you know what systems they're accessing? Should they be accessing those systems?”
The rapid adoption of AI has created an inventory problem for enterprise security teams. Employees can acquire AI tools, organizations can build agents internally, and software vendors can introduce agent capabilities into existing applications.
As a result, an enterprise may have agents operating across its environment without having a comprehensive inventory of them.
DigiCert therefore puts discovery at the beginning of its AI trust model.
AI Trust Manager is designed to discover agents, establish an inventory and associate agents with accountable owners. Once identified, agents can receive cryptographic identities and be governed according to organizational policies.
That creates a progression that DigiCert views as fundamental to AI governance: discover the agent, establish its identity, define its authority and monitor what it does.
If an agent begins operating outside its defined policies, organizations can intervene.
The kill switch
Revocation is a particularly important part of DigiCert's approach.
The company's argument is straightforward: cryptographic credentials are useful not only because they establish trust, but because that trust can be withdrawn.
“If something goes wrong, there is a kill switch,” Nelson said. “We do that all the time with public certificates.”
Under DigiCert's model, an agent whose authority has been revoked can no longer use its credential to communicate or perform actions that depend on that trusted identity until trust is reestablished.
Nelson said DigiCert has experience revoking certificates at internet scale when credentials have been compromised or improperly issued.
The AI-agent application is different, however, because agents may be interacting with many systems and organizations simultaneously.
That makes the ability to establish a portable identity particularly important. Without an identity that can be independently verified, a receiving organization has fewer mechanisms for determining whether an agent should continue to be trusted.
The objective isn't simply to stop an AI model. It is to control the individual autonomous agents operating on behalf of people and organizations.
That distinction could become increasingly important as governments and businesses debate how AI systems should be controlled.
A new machine identity
DigiCert AI Trust Manager is part of a broader AI trust architecture the company says will apply cryptographic verification across AI agents, models and content.
The company is essentially arguing that the emergence of autonomous AI does not require abandoning established principles of digital trust.
Instead, the internet's existing trust infrastructure provides a model.
“Cryptography is in our DNA,” Nelson said. “We've been doing it for a lot of years.”
The challenge is applying those principles to a new kind of machine.
A conventional server performs a defined technical function. An AI agent can be given a goal, determine how to pursue it, communicate with other systems and take actions along the way.
That autonomy creates a different security requirement.
Businesses need to know not only whether a machine is authentic, but whether an autonomous system is operating within the authority it has been given.
DigiCert's approach combines those concepts into a single framework: discovery, cryptographic identity, policy and revocation.
The company says the system is generally available following a beta preview announced in April. DigiCert has also identified organizations including UKG as early participants in its AI trust efforts, with UKG Vice President of Global Security Engineering & IAM Ajitha Choudary describing verifiable identity, authorization and visibility as important foundations for deploying autonomous AI.
DigiCert's broader thesis is that AI adoption is moving faster than the security infrastructure needed to govern it.
A July 2026 DigiCert survey of 1,001 IT and cybersecurity leaders found that 78% said their organizations had experienced an AI-related security incident or identified an AI vulnerability during the previous year.
The statistic encompasses both incidents and vulnerabilities, rather than representing a single category of confirmed breaches, but it reflects the security concerns accompanying rapid AI adoption.
For DigiCert, the answer is not to slow AI development or attempt to eliminate autonomous systems.
It is to give them an identity.
“Any time something is performing that level of function, it needs an identity and it needs governance,” Nelson said.
That concept may become increasingly important as AI agents move from operating inside individual companies to interacting across the broader digital economy.
The internet already has a system for deciding which machines can be trusted to communicate.
DigiCert is betting that the same basic idea can provide a foundation for the next generation of autonomous software.
Learn more at digicert.com/ai-trust-manager.
Check out the July 7, 2026 TechBuzz article for more details about the 2026 DigiCert survey.
Additional Resources about DigiCert's AI Trust Manager can be found below:
DigiCert's New Trust Architecture for AI Whitepaper