TAMPA — In recent years, the Zero Trust concept of cybersecurity where users and devices are subjected to multiple levels of authentication was thought to be the final answer to protecting data and intellectual property.
But now artificial intelligence (AI) and especially agentic AI — where bots crawl through networks sometimes with a mind on their own to complete assigned tasks — is forcing the Defense Department and Intelligence Community (IC) to rethink how it implements Zero Trust at the enterprise level, according to the IC’s chief information officer.
Because agentic AI is designed to operate autonomously, it may need broad access to data, tools, and systems, making identity and precisely controlled permissions increasingly important to the government’s Zero Trust strategy.
“If users and devices are going to request, store, and manipulate process data, so will AI agents,” said IC Chief Information Officer Douglas Cossa, speaking Monday at the Defense Intelligence Agency’s DoDIIS conference. “The challenge we have is that this new realm of AI has completely spun ZeroTrust on its head, where we went from a model of least privileged access or no access to now giving [an AI] model and agent everything it needs to be operating independently. Those are two different things, and the only way that we’re going to be successful in that is if we start with a common identity system.”










