ChannelLife Australia - Industry insider news for technology resellers
Australia
DigiCert adds identity controls for NVIDIA AI agents

DigiCert adds identity controls for NVIDIA AI agents

Wed, 30th Sep 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

DigiCert has added support for the NVIDIA Open Agent Safety Platform, focusing on identity controls for autonomous AI agents.

Its DigiCert AI Trust Manager is being integrated with NVIDIA OpenShell, the runtime at the core of the platform, to help organisations verify which AI agent is acting, what authority it holds and when that authority should be withdrawn.

The announcement reflects a wider push by technology vendors to address governance and security concerns as AI agents begin taking on tasks across business systems with greater autonomy. Those concerns include proving an agent's identity, limiting its permissions and creating records of its actions for audit purposes.

NVIDIA OpenShell is designed to place controls around autonomous agents by denying actions by default and enforcing policy outside the agent process. Every decision to allow or deny an action is recorded, while monitoring can be isolated from the host environment through NVIDIA Sentry on BlueField-4, which uses NVIDIA DOCA. NVIDIA Vera provides compute for CPU-heavy agent workloads.

DigiCert's role centres on identity and authority. AI Trust Manager can help organisations discover and manage the AI agents they own or operate, tie each one to a verified owner and define what systems, data and actions it may access.

Identity layer

A central part of the system is what DigiCert calls an AI Passport, a cryptographically signed credential that travels with the agent and is intended to verify identity independently of any single identity provider. Policy-based permissions, described as visas, are attached to define what the agent may do and for how long.

The model is aimed at a problem likely to grow as agents move between companies, cloud services and software environments. In those cases, organisations may need a way to validate the identity and authority of an external agent without requiring all parties to use the same identity system.

The system can also revoke an agent's authority and quarantine it if the agent attempts a prohibited action or if trust conditions change. DigiCert describes that function as an automated kill switch governed by policies set by the owner or passport issuer.

The companies are positioning the arrangement as complementary rather than overlapping. NVIDIA's platform is intended to enforce the operating boundary around the agent, while DigiCert focuses on proving identity and carrying authority controls beyond that boundary as the agent interacts with other systems.

Audit focus

DigiCert outlined four areas of initial support: identity that can be used by policy engines; verification of agents, models and MCP servers before execution; stronger audit trails through cryptographic evidence tied to policy decisions; and a trust model that can work across company boundaries.

The verification element also includes signing software components and associating them with an AI Bill of Materials, intended to show what is being deployed before it runs. That is relevant for organisations trying to build controls around increasingly complex AI stacks made up of models, agents, runtimes and connected services.

Amit Sinha, Chief Executive Officer of DigiCert, said the issue is becoming more urgent as AI agents take on practical work inside companies.

"AI agents are starting to do real work across business systems, and that means companies need to know exactly which agent is acting, what it's allowed to do, and when to stop it," said Amit Sinha, Chief Executive Officer of DigiCert. "NVIDIA helps create the boundary around the agent. DigiCert helps establish who that agent is and what authority it has. Together, that gives enterprises a much clearer way to put autonomous AI to work with control and accountability."

The emphasis on public key infrastructure, or PKI, is notable because it draws on a well-established internet trust model rather than a framework built specifically for AI. DigiCert argues that the same mechanism used to verify websites, devices and software can be extended to autonomous agents that need to prove identity across different organisations.

Sinha said that becomes more important when agents begin dealing with one another outside a single company's identity environment.

"As agents begin interacting with other agents beyond company lines, identity cannot depend on every participant belonging to the same identity system," he said. "We need a trust model that can cross those boundaries. PKI solved that problem for the internet at scale, and we believe the same foundation has an important role to play in establishing trust for autonomous agents."

Initial support begins with NVIDIA OpenShell, placing the first phase of the work at the runtime layer where agent actions can be controlled and observed.