Who Gave the Machine Permission?

Posted on September 11, 2026

0


ID gets you to the door, trust decides whether it should open.

For decades, cybersecurity identity has revolved around a deceptively simple question, who are you? Passwords, multi-factor authentication (MFA), certificates, identity and access/privileged management (IA/PM) and eventually Zero Trust were built around establishing identity before granting access, the digital economy is rapidly filling with identities that are not human. Service accounts, application programming interface (APIs), workloads and devices are now being joined by something considerably more consequential, AI agents capable of interpreting, deciding, delegating and acting at machine speed and outside inherent/assumed moral or ethical norms.

Authentication can tell us that an agent is who it claims to be. It tells us remarkably little about whether we should trust what it is about to do. Imagine an AI procurement agent instructing another machine identity to approve a supplier, commit £500k and initiate payment. Every credential could be valid. Every system could be functioning correctly. The transaction could still be catastrophically wrong. The challenge is therefore moving from identity assurance to authority assurance.

A Non-Human Identity (NHI) needs a continuously evidenced trust position answering: What are you? Where did you come from? Who owns you? What are you authorised to do? Why are you doing it? Are you behaving as expected? And ultimately, who is accountable?

That creates an authority chain, Human/Organisation engages/auto-workflows the agent, in so doing delegating authority and the agent takes action. Every link needs to be attributable, constrained, observable and challengeable.

We may therefore be approaching something analogous to the emergence of public key infrastructure (PKI). PKI gave the internet a scalable mechanism for machines to establish identity and secure communications. The agentic economy may require an equivalent machine readable trust infrastructure for authority, allowing one machine to independently determine whether another possesses sufficient current authority and trustworthiness to perform a particular action.

Crucially, that trust must decay. Changed models, dependencies, behaviour, vulnerabilities or purpose should continuously alter the trust position.

Zero Trust taught us to never trust, always verify. Agentic AI may require its successor, never trust merely because you verified the identity, verify the authority behind the action. You need a trusted path from access to accountable action.

Your identity gets you to the door … Cryptography proves you hold the key … Trust decides whether it should open … Authority determines where you may go … Privacy determines what you may learn … Governance determines what you may do with what you learn … Evidence proves you stayed within those boundaries.

The warning for me becomes, when billions of machines begin instructing other machines, the internet’s next great trust problem will not be proving who they are, it will be proving who gave them permission to act and what they can learn or put another way, identities you can trust, information you can protect and outcomes you can prove.