DigiCert has officially launched the DigiCert AI Trust Manager, a significant addition to the DigiCert ONE platform. This innovative tool enables organisations to efficiently manage AI agents, ensuring each has a verifiable identity and appropriate authorisations. The Trust Manager also allows authorities to be revoked swiftly via a kill switch should trust be compromised.
AI agents are increasingly integrated into operations, accessing sensitive information, utilising software tools, and making critical decisions autonomously. However, traditional enterprise security systems are often not equipped to manage the rapid movements of these agents across various applications and networks effectively.
Enterprise security systems
Emerging risks associated with AI were highlighted in a recent DigiCert survey, conducted in July 2026. Among 1,001 IT and cybersecurity leaders, 78% reported experiencing an AI-related security incident or identifying a vulnerability over the past year. Amit Sinha, CEO of DigiCert, remarked, “For more than two decades, DigiCert has provided the cryptographic infrastructure that helped the internet scale. We are now bringing that proven trust model to AI agents so organisations can verify who they are, who owns them, and what they are authorised to do.”
Traditional Identity Systems
Conventional identity systems typically function within a single organisation, much like employee badges
Conventional identity systems typically function within a single organisation, much like employee badges. The DigiCert AI Trust Manager centres around the DigiCert AI Passport, a cryptographically signed credential confirming an agent’s identity and connecting it to an accountable owner. Policy-based “visas” specify access permissions regarding systems, data, and authorised actions, including the duration of these permissions.
Since the DigiCert AI Passport is portable, other systems and organisations can verify it independently. If an agent initiates a prohibited action, DigiCert’s automated kill switch will block it and revoke permissions immediately, safeguarding against potential risks.
Capabilities of DigiCert AI Trust Manager
The DigiCert AI Trust Manager empowers enterprises to:
- Identify and account for AI agents within the network, whether acquired or developed internally.
- Define and enforce specific access limits, determining what systems, data, and actions an agent may access and for how long.
- Extend trust across different organisations, enabling independent verification without the need for the same identity provider.
- Adapt to changing trust levels by updating credentials or revoking permissions based on policy changes or risk assessments.
New class of autonomous systems
Grace Trinidad, Research Director, AI Security and Trust at IDC, noted that enterprise AI procurement now prioritises verifiable security controls. Identity verification, attestation, and revocation are key to building trust and pointing at resolving prevalent security issues, she said. Ajitha Choudary, Vice President of Global Security Engineering & IAM at UKG, added that as AI agents are increasingly integrated into workflows, maintaining clear identity and accountability is crucial. "DigiCert AI Trust provides a promising framework for extending digital identity principles to these autonomous systems," she stated.
The DigiCert AI Trust Manager is part of a broader AI trust architecture, which integrates cryptographic verification for AI agents, models, and content. It enhances existing cybersecurity systems, enabling portable verification of an agent’s identity and authority across different operational contexts.
DigiCert, a pioneer in intelligent trust, announces the general availability of DigiCert AI Trust Manager, part of the DigiCert ONE platform. The new solution helps organisations discover and manage the AI agents they own or operate, establish each agent’s verifiable identity and ownership, define what it is authorised to do, and revoke that authority with a kill switch when trust changes.
AI agents can access sensitive data, use software tools, write code, make decisions, and complete transactions with limited human involvement. Yet most enterprise security systems were not built to govern autonomous agents moving across applications, clouds, and organisations at machine speed.
Enterprise security systems
The risks are already emerging. In a July 2026 DigiCert survey of 1,001 IT and cybersecurity leaders, 78% said their organisations had experienced an AI-related security incident or identified an AI vulnerability during the previous year.
“For more than two decades, DigiCert has provided the cryptographic infrastructure that helped the internet scale,” said Amit Sinha, CEO of DigiCert. “We are now bringing that proven trust model to AI agents so organisations can verify who they are, who owns them, and what they are authorised to do.”
Traditional identity systems
Traditional identity systems work like employee badges, establishing trust within a single organisation. At the centre of DigiCert AI Trust Manager is the DigiCert AI Passport. It’s a portable, cryptographically signed credential that verifies an agent’s identity and connects it to an accountable owner. Policy-based “visas” define which systems, data, and actions the agent may access, as well as how long that authority lasts.
Because the DigiCert AI Passport and its permissions travel with the agent, other systems and organisations can independently verify them without relying on the same identity provider. A receiving organisation can deny the agent access within its own environment. If the agent attempts a prohibited action, DigiCert’s automated kill switch blocks it and, under policies set by the agent’s owner or passport issuer, can immediately revoke its authority at the source and quarantine it before harm occurs.
DigiCert AI Trust Manager allows enterprises to:
- Find and identify agents: Discover AI agents that were purchased, built internally or operating within the business, and connect each one to an accountable owner.
- Set clear limits: Define the systems, data, and actions an agent may access, and how long its permission remains valid.
- Extend trust across organisations: Allow other systems and companies to independently verify an agent without requiring both parties to use the same identity provider.
- Respond when trust changes: Update credentials, expire permissions, or revoke an individual agent or groups of agents upon policy, risks, or any other changes.
New class of autonomous systems
"Enterprise AI buying has moved from trust to proof. Buyers are ranking verifiable security controls as their top priority and name unverifiable vendor claims as their top frustration,” said Grace Trinidad, Research Director, AI Security and Trust, IDC. “Cryptographic identity, attestation, and revocation for agents, models, and MCP servers are the machinery that produces this proof, which in turn produces trust, and DigiCert is pointing the identity discipline the internet already runs at scale at exactly that problem."
“As AI agents become more embedded in enterprise workflows, establishing clear identity and accountability will be essential to deploying them responsibly at scale,” said Ajitha Choudary, Vice President of Global Security Engineering & IAM at UKG. “We see DigiCert AI Trust as a promising approach to extending proven principles of digital identity to this new class of autonomous systems. The ability to verify an agent’s identity, define what it is authorised to do, and maintain visibility into its actions could give organisations the foundation they need to adopt agentic AI with greater confidence.”
DigiCert AI Trust Manager is part of DigiCert’s broader AI trust architecture, which applies cryptographic verification across AI agents, models, and content. It complements existing identity and cybersecurity systems by providing a portable foundation for verifying an agent’s identity and authority wherever it operates.