Cisco adapts zero trust for the era of autonomous agents

Agentic AI is supposed to rewrite business strategy from the ground up. It is also creating an identity crisis that organizations don't know how to measure. "Somewhere in your environment right now an AI agent is almost certainly operating without a proper identity, defined owner, or meaningful access controls," says Matt Caulfield, Cisco's vice president of product for identity and head of the Duo Agentic Identity team. Developers are already wiring agents into production systems without involving IT, and the gap between adoption speed and governance capability is widening every quarter.
When IAM's founding assumptions collapse
Traditional identity and access management was built for humans: an identity minted once at onboarding and updated rarely. An autonomous agent, by contrast, pulls its permissions from the runtime context — granting it coarse-grained access to every action it decides to take, at machine speed, often without human approval. The tools that preceded the current wave were designed for service accounts and API keys, static and predictable entities. They cannot enforce policy at the per-action or per-session level, which an independent agent demands.
Zero trust extended to non-human actors
Caulfield argues the choice isn't between speed and safety but building enough trust to eliminate the need to choose. His team at Cisco has applied zero-trust principles to a new, broad class of non-human actors: never grant implicit trust, never give more trust than the task requires, continuously verify the trust already granted. Architecturally, the response is organized around three pillars — comprehensive visibility, strict accountability, and enforcement that operates at the single-action level, not the whole-session level.
Visibility first: shadows in the environment
The first step is bringing autonomous agents into the identity-management fold, and Cisco customers rank visibility as the number-one problem. "You can't trust what you can't see," Caulfield says, noting that "shadow agents" turn up in almost every organization examined — agents a developer spun up to solve a point problem, connected to several internal systems, then left behind without anyone documenting or disconnecting them. Cisco's discovery mechanism leans on its existing systems to deliver a comprehensive architectural answer, one meant to be broader than tools that operate only at the identity-authentication layer.