TL;DR: Enterprise demand for secure identity, certificate, and cryptographic trust across humans, machines, and AI systems is driving rising pressure around agentic AI and post-quantum readiness, while 210% three-year revenue growth and a sixth straight Deloitte Fast 500 appearance reflect the trend, according to Keyfactor. The signal for practitioners is that digital trust is moving from infrastructure hygiene to core identity governance.
At a glance
What this is: This is a Keyfactor press release arguing that digital trust, certificate management, and identity assurance are becoming central as enterprises extend governance into AI agents and other non-human identities.
Why it matters: IAM, NHI, and PAM teams should read this as a signal that cryptographic identity and lifecycle controls are now part of mainstream identity governance, not just backend infrastructure.
By the numbers:
- Keyfactor reports 210% three-year growth.
- Keyfactor says it earned recognition on Deloitte’s Technology Fast 500 for the sixth consecutive year.
Context
Digital trust is the set of controls that let systems prove who or what they are before they exchange data or act. In this article, that means certificate management, cryptographic identity, and lifecycle control for machines and AI agents as well as humans.
The governance gap is that many IAM programmes still treat non-human identity as an infrastructure by-product rather than an identity domain. Keyfactor’s release frames AI agents as a forcing function because autonomous systems need verifiable credentials, not just access pathways.
That is a familiar pattern for mature identity teams: once trust mechanisms become operationally critical, they stop being a back-end utility and become a board-level governance concern. The underlying challenge is not new, but the scope is widening fast.
Key questions
Q: What breaks when AI agents are managed like ordinary machine identities?
A: What breaks is the assumption that access scope can be fully understood from provisioning data and quarterly review. Ordinary machine identities are repeatable; agents are not. If teams only review entitlements, they miss context shifts, delegated actions, and credential creation inside the session.
Q: Why does cryptographic identity matter for autonomous systems?
A: Because autonomous systems can make runtime decisions, security teams need more than a login event or application token. Cryptographic identity ties actions to a verifiable subject, which is essential when the system can initiate requests on its own. Without that proof, authorisation becomes guesswork and accountability weakens across downstream services.
Q: How should regulated enterprises govern certificate lifecycle across machine identities?
A: They should treat certificates for services, APIs, workloads, and devices as governed identity assets with defined owners, renewal rules, revocation procedures, and audit records. The key is to connect certificate lifecycle management to identity governance so trust can be proven, changed, and withdrawn in operational time, not just renewed on a schedule.
Q: How do zero trust controls need to change as AI agents become more common?
A: AI agents should be treated as non-human identities with request-level authorization, not as users with special privileges. Their access should be explicit, logged, and revocable, with policy boundaries that limit what they can do if their runtime behavior changes. Otherwise, autonomy turns into unmanaged reach.
Technical breakdown
Cryptographic identity for AI agents
AI agents can only be governed reliably when their actions are bound to cryptographically verifiable identities. In practice, that means treating agent authentication, certificate issuance, and key custody as part of the identity plane rather than the application layer. Without that binding, teams can observe usage but cannot prove which autonomous system initiated a request, rotated a secret, or invoked a downstream tool. The governance problem shifts from login to runtime assurance, because the identity has to remain trustworthy across machine-to-machine exchanges, not just at enrolment.
Practical implication: define how AI agents will be uniquely authenticated before they are allowed to interact with sensitive tools or data.
Certificate lifecycle is the hidden control surface
Certificate lifecycle management covers issuance, renewal, rotation, revocation, and expiry handling for machine credentials. It is often treated as plumbing, but it is really the control surface that limits impersonation and stale trust. When certificate inventories grow faster than manual processes, organisations lose visibility into which identities are active, over-privileged, or overdue for renewal. That creates a trust gap even when the surrounding system looks healthy. The article’s emphasis on scalable digital trust reflects this operational reality, especially where workloads, services, and AI agents need continuous verification.
Practical implication: inventory certificate-bearing identities and tie renewal and revocation to governance, not ad hoc operations.
Zero Trust extends only when identity is verifiable
Zero Trust is only meaningful when the caller’s identity can be asserted with enough confidence to drive an authorisation decision. For human users that may mean SSO and MFA, but for non-human identities it depends on certificates, workload identity, and strong credential governance. The article’s framing shows why AI agent deployment pressures are now colliding with longstanding machine identity issues: if the system cannot prove the agent’s identity, it cannot safely delegate action. That makes cryptographic trust a prerequisite for Zero Trust, not a separate initiative.
Practical implication: align Zero Trust design with machine identity and certificate governance instead of limiting it to human access controls.
Threat narrative
Attacker objective: The objective is to impersonate a trusted non-human identity and use that access to reach systems or data that would otherwise be protected.
- Entry occurs when a workload, service, or AI agent presents a trusted credential that is no longer tightly governed by the organisation’s identity controls.
- Escalation follows when that identity can reuse certificates, tokens, or keys across systems without strong lifecycle oversight or scoped revocation.
- Impact comes when the trusted identity is used to access downstream services or data as if it were legitimate, extending the blast radius of that compromise.
Breaches seen in the wild
- Deloitte breach claim 2025: A hacker called 303 claims to have leaked GitHub credentials and source code from Deloitte US consulting; Deloitte has not confirmed it.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Cryptographic trust is now an identity governance issue, not a niche infrastructure concern: once AI agents and machines can act at production speed, certificate and key governance become part of the access model itself. The article reflects a broader market shift in which identity assurance is no longer limited to humans. Practitioners should treat digital trust as a core identity discipline, not a tooling add-on.
AI agents force a redefinition of non-human identity scope: the problem is no longer only service accounts and workload credentials. Autonomous and semi-autonomous systems need identities that can be issued, scoped, monitored, and retired with the same seriousness as privileged machine accounts. That widens the governance surface and raises the cost of leaving machine identity fragmented across teams.
Certificate sprawl is the practical manifestation of identity sprawl: when every service, workload, and agent can hold a credential, visibility becomes the deciding control. The article’s emphasis on scaling trust signals that inventory and lifecycle discipline will matter more than isolated hardening projects. Practitioners should expect identity governance to increasingly depend on cryptographic asset management.
Agentic AI makes trust assumptions more brittle, not less: the assumption that identity is static enough to catalogue breaks down when systems are continuously instantiated, delegated, or re-authenticated at runtime. That is a governance problem because review, attestation, and offboarding all depend on a stable identity record. The implication is that identity programmes must move closer to issuance-time control and continuous trust verification.
Digital trust is becoming the common language across human, machine, and autonomous identity programmes: that convergence matters because it collapses old boundaries between IAM, PKI, PAM, and workload identity. The organisations that align those domains will govern access more coherently than teams that keep certificate management separate from identity operations. Practitioners should plan for a merged governance model.
From our research library:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- Read next: NHI Lifecycle Management Guide
What this signals
Cryptographic trust is now the control plane for AI identity: as agents begin to act across systems, identity programmes have to move from human-centric authentication to verifiable machine and agent credentials. The organisations that keep certificate governance separate from identity governance will struggle to answer a basic question: which actor actually performed the action?
Identity review cycles are the wrong mental model for autonomous actors: access review assumes a privilege survives long enough to be recertified, but agentic systems can acquire and release access in ways that make static review insufficient. That is why 69% of security leaders say identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
For practitioners
- Map AI agents into the identity inventory Create a distinct class for AI agents, then track their certificates, keys, owners, and permitted actions alongside other non-human identities.
- Bind certificate lifecycle to access governance Require renewal, rotation, and revocation events to flow through identity governance so certificates are not treated as unmanaged infrastructure artefacts.
- Define trust boundaries for autonomous systems Set rules for where cryptographic identity is sufficient, where step-up verification is needed, and where an agent should be blocked from acting.
- Collapse machine identity silos Unify service accounts, workload credentials, and agent identities into a single governance model so ownership and review do not fragment by platform.
Key takeaways
- Digital trust is becoming a core identity governance domain because AI agents and machine identities now need the same assurance discipline as human users.
- Keyfactor’s growth and Fast 500 recognition illustrate market demand for scalable certificate and cryptographic identity controls, not just infrastructure automation.
- Practitioners should unify AI agents, workloads, and service identities under one lifecycle model so trust decisions stay auditable and revocable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centers on verifiable identities for agents, workloads, and machines. |
| NHI-07 — Long-Lived Secrets | The release highlights certificate and cryptographic trust lifecycle pressure. | |
| NHI-05 — Overprivileged NHI | Agent identities need scoped access or they expand blast radius quickly. | |
| Recommendation — Use NHI-04 to require strong, verifiable authentication for every non-human identity. Use NHI-07 to shorten credential lifetimes and reduce standing trust for machines and agents. Use NHI-05 to constrain agent and workload permissions to the minimum needed. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Certificate and key lifecycle control is central to the article’s trust model. |
| Recommendation — Apply IA-5 to govern issuance, rotation, and revocation of machine authenticators. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The release ties trust to who or what can act across systems. |
| Recommendation — Map non-human identity permissions to PR.AA-05 and review authorisations continuously. | ||
Key terms
- Digital Trust: Digital trust is the set of cryptographic and identity controls that allow systems, users, and services to verify each other reliably. It includes PKI, federation, certificates, and authentication foundations that must remain adaptable as technologies and threat conditions change.
- Certificate Lifecycle Management: The governance of digital certificates from issuance through renewal and revocation, ensuring certificates are valid, monitored, and rotated before expiry. Expired certificates are a leading cause of outages and unplanned security gaps.
- Cryptographic Identity: Cryptographic identity is a trust model in which authentication depends on verifiable keys, certificates, or signed assertions rather than shared secrets alone. It is essential for machines and agents because it gives the organisation a stronger way to prove identity and revoke access quickly.
- Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org