ai-cybersecuritytrade-pressNewsThe Broadside2 min read

AI agents strain EO 14028 zero-trust assumptions

Human-speed identity protocols become a liability when autonomous software asks for access at machine speed and changes jobs by the minute.


TL;DR

A NextGov/FCW commentary argues federal zero-trust architectures built after Executive Order 14028 remain anchored in PIV cards, SAML and OAuth, while agentic AI may authenticate millions of times a day and require rapidly changing permissions. Federal agencies, state CISOs, primes and C3PAOs should watch the identity layer, because the easy workaround is treating agents as service accounts. That would scale an already weak audit model into a vast non-human identity population.

The uncomfortable part of the zero-trust-and-AI conversation is that the doctrine is still right. “Never trust, always verify” remains the correct answer. The problem, as Jim St. Clair and Adam McBride argue in NextGov/FCW, is that much of the federal implementation work since Executive Order 14028 assumed a human behind the request: a person with a PIV card, a SAML session, an OAuth grant and permissions that change on human schedules.

Agentic AI breaks that model in several places at once. The source article says an ATARC Identity Management Working Group analysis calculated that 1,000 agents operating at machine speed could generate roughly 7.4 million authentication events per day, about 148 times the volume from an equivalent human population. That is a scaling problem, but the worse problem is evidentiary. If an agent acts, delegates to a sub-agent, changes task scope and touches a system, the incident-response question is not merely whether access was allowed. It is who authorized the action, what authority traveled with it and whether revocation followed fast enough to matter.

The path agencies will be tempted to take is also the one that makes the architecture worse: onboarding agents as service accounts. That uses familiar tooling and avoids a new policy fight. It also imports static credentials, broad standing privileges and thin attribution into a class of identities that may grow far faster than the human workforce. In zero-trust terms, that is not modernization. It is scaling the exception.

This is not an OMB mandate yet, and NextGov’s piece is commentary rather than guidance. But the open policy gap is real enough to name. CISA’s summary of EO 14028 says the order pushed agencies toward secure cloud services, zero-trust architecture, multifactor authentication and encryption, while GAO has already found agencies still working through incident-response logging requirements. Those are human-era problems with human-era volumes. Agent identity turns them into runtime governance problems.

For practitioners, the Monday item is simple: do not let “non-human identity” become a bucket where agents, service accounts and devices go to become somebody else’s audit problem. If agencies are going to deploy autonomous agents, the identity record needs to show what the agent is, who deployed it, what task it may perform, what delegation occurred and when the credential dies. Anything less asks zero trust to verify a machine actor it was never taught to recognize.


Published ·Deep Fathom