# Federal Agencies Extend Zero-Trust to AI Agents

Federal agencies deploying autonomous AI need to apply zero-trust controls to AI agents by giving each agent a distinct identity, restricting its permissions to a defined task and duration, and enabling rapid enforcement or revocation. The Social Security Administration has sought industry input on an enterprise AI strategy that includes agentic capabilities, signaling a potential opportunity for firms to shape agency approaches. Contractors should show how these identity, access-limiting, and revocation controls will work in proposed architectures and technical designs.

- SSA’s request for industry input concerns an enterprise AI strategy; the signal does not identify a contract award, value, or solicitation deadline.
- Contractors pursuing federal AI work should be prepared to demonstrate agent-level identity and controls that constrain access by task and duration, with mechanisms for rapid revocation.
- This development connects AI system design with cybersecurity requirements, making zero-trust implementation relevant to technical proposals and agency AI planning.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Artificial Intelligence
**Published:** October 08, 2026

### Government Entities
- Social Security Administration (SSA)
- National Institute of Standards and Technology (NIST)
- National Cybersecurity Center of Excellence (NCCoE)

### Vendors
- Xage Security ()

### Sources
- [The zero-trust controls federal agencies need for autonomous AI | FedScoop](https://fedscoop.com/the-zero-trust-controls-federal-agencies-need-for-autonomous-ai) - FedScoop