TAMPA — In recent years, Zero Trust, which requires multiple layers of authentication for users and devices, was considered the definitive solution for safeguarding data and intellectual property.
However, the rise of artificial intelligence, particularly autonomous agentic AI that can independently navigate networks to fulfill tasks, compels the Department of Defense and the Intelligence Community’s chief information officer to reassess enterprise‑level Zero Trust implementation.
Since autonomous AI agents require extensive access to data, tools, and systems, establishing precise identity controls and tightly managed permissions has become critical to the government’s Zero Trust strategy.
IC Chief Information Officer Douglas Cossa noted that, just as users and devices can request, store, and manipulate process data, AI agents will do likewise. He explained that AI has fundamentally altered Zero Trust, moving from a principle of minimal or no access to a model that grants AI agents unrestricted capability to operate autonomously, and that success will depend on establishing a common identity framework.
Enterprises must determine how to establish and control the identity of autonomous bots.
Cossa explained that the government currently lacks a unified identity system across agencies for this purpose. The emerging requirement resembles a digital birth certificate—not only for individuals and devices but also for AI agents that can request, store, manipulate, and process information—forming the basis for defining what autonomous agents are allowed to do.
To address this, the IC CIO office has invested in building an enterprise‑wide identity management service, planning to pilot and test its tools in operational environments this fall as the agency moves toward fiscal year 2027.
A second challenge involves enforcing policy to control what information people, devices, and AI agents can access, while ensuring rapid data flow to authorized users and functions.
Cossa added that cybersecurity should not be viewed as friction that blocks functionality. Instead, implementing Zero Trust—by establishing identity and fine‑grained entitlements that deliver data precisely to the functions that require it—acts as a critical mission enabler.
He said Zero Trust is now defined by identity and policy enforcement with fine‑grained attributes. This definition reflects the Intelligence Community’s approach and will become one of our newest common‑concern services this year.
AI for Cybersecurity in Special Operations
The Intelligence Community is addressing the agentic AI challenge jointly with other stakeholders, and the move toward Zero Trust automation is also reshaping how Special Operations Command approaches network defense.
Admiral Frank Bradley, commander of U.S. Special Operations Command, emphasized that future cyber defenses must not rely on manual log review or trust reconfiguration during crises. Instead, SOCOM envisions networks that can rapidly detect compromises, incorporate contextual factors such as device health, location, and behavior into access decisions, and autonomously respond.
“We need to detect a compromise within minutes, not months, and build systems capable of autonomous defense—agentic defense against agentic offense,” he stated.
Even with improved defenses, Bradley warned that adversaries will increasingly target human frailty—manifested as lapses in discipline, protocol violations, or fatigue from sustained operations.
“The focus will increasingly be on human frailty rather than machine frailty,” he said. “Humans are imperfect, and that is not a defect to eliminate but a condition we must design for.”
Bradley noted that layered defenses, compartmentalized access, and data‑level need‑to‑know restrictions can mitigate the impact of a single human error.


