Entrust starts issuing cryptographic identities to AI agents
Every interop protocol assumes you know which agent you are talking to. A legacy certificate authority just made that assumption into a product.
- Entrust launched the Agentic AI Trust Accelerator on July 14, a co-development program building identity and real-time authorization infrastructure for autonomous agents moving from pilot to production.
- Agents get cryptographically bound digital identities from the moment they are provisioned, with purpose-bound permissions, a chain of delegated authority, and immutable proofs of action built on PKI and short-lived tokens.
- Entrust cites an IBM study finding 77 percent of organizations report AI adoption outpacing their governance capabilities.
The oldest business in digital trust is moving into the newest one. Entrust, the certificate authority and PKI vendor, launched its Agentic AI Trust Accelerator on July 14, a co-development program with enterprises and technology partners to build what it calls a trust plane for autonomous AI: verifiable identity, real-time authorization, and cryptographic proof of action. "Trust will determine how quickly companies can move agentic AI from experimentation to production," said CEO Tony Ball.
An identity from the moment of provisioning
The mechanics are classic PKI applied to a new species. Agents receive cryptographically bound digital identities the moment they are provisioned, enabling purpose-bound permissions, a chain of delegated authority tracing every action back to a confirmed human principal, and immutable records of what an agent actually did, built on public key infrastructure and short-lived tokens, per ID Tech's detail. The four focus areas: verifiable identity for people and agents, authorization that keeps agents inside approved policies, a cryptographic layer protecting the keys and secrets agents handle, and regulator-ready accountability. Entrust cites an IBM finding that 77 percent of organizations say AI adoption is outpacing their governance.
The layer every protocol assumes
Agent identity is the missing floor under the whole interop stack. MCP and A2A define how agents talk; neither settles who an agent is, which is why the UN's standards body took up the problem and why gateways like NetScaler's MCP layer exist at all. Entrust arriving with a commercial program, alongside JetStream's verified MCP catalog the day before, says the market is no longer waiting for the standards bodies. The attacks are already here, from hijacked gateways to spoofed tooling, and the vendors who spent 30 years selling certificates for websites have noticed that the web's next billion actors will not be people.