Back
Amit Sinha
Chief Executive Officer, DigiCert, Inc.

RSAC 2026: DigiCert: Building Crypto-Agile Trust for AI and Quantum Safety

🎥 Feb 01, 2026 📺 Dark Reading ⏱ 10m 👁 75 views
DigiCert's Amit Sinha explains how organizations must rethink trust architecture to manage AI agents, non-human identities, and post-quantum cryptography deadlines.
Watch on YouTube

About Amit Sinha

In a July 2026 interview with ETCIO, Amit Sinha discussed DigiCert's AI trust architecture and the concept of "agent passports" for autonomous AI systems. Sinha argued that as AI agents move from simple assistants to autonomous operators, enterprises need verifiable digital identities, strong authentication, and policy-led access before allowing agents to interact with sensitive systems. He described agent passports as a way to establish who created an agent, how it was trained, what it is authorized to access, and which actions it can take. Sinha also discussed DigiCert's work on confidential computing and content trust. He noted that DigiCert has been working with Google on third-party attestation for confidential computing environments, explaining that the company brings the same core third-party attestation used in certificate issuance to AI workloads running in cloud infrastructure. Additionally, he mentioned DigiCert's content trust platform, which uses the C2PA standard to provide media provenance for AI-generated videos and images.

Source: AI-verified profile updated from Amit Sinha's recent appearances. Browse all interviews →

Transcript (17 segments)
T
Terry Sweeney0:10
Welcome back to the Dark Reading News Desk. I'm Terry Sweeney, contributing editor to Dark Reading, and joining me now is Amit Sinha with DigiCert. Amit, thank you so much for joining us.
A
Amit Sinha0:19
Teddy, it's a pleasure to be back on your show.
T
Terry Sweeney0:23
Well, it's nice to look over and see a familiar face. We appreciate you doing this again. Safe to say that AI has dramatically accelerated, especially with the creation and use of automated identities, bots, and these non-human identities that really seem to be dominating so much of conversations in the industry these days. With all that in mind, how should organizations rethink trust architecture? There are templates floating around out there, zero trust, some differences of opinion about whether that's applicable in this non-human identity world, but I'll stop talking and see where you are on this topic.
A
Amit Sinha1:10
Yeah, Teddy, so enterprises were already struggling with machine identity management, right? The ratio of machines to humans in a typical organization is already 100 to 1. The rate at which data centers are being built is unprecedented. And machine identities are typically digital certificates. What's also happening is on the public internet side, these certificates are going from 398 days to 47 days. So, they're shrinking by a factor of 8x. Yes, so you have raw machines exploding, the digital passports that give machines these identities are shrinking, and enterprises have a huge problem of managing and automating the life cycle, otherwise it leads to outages and very expensive manual processes. And we haven't even started talking about agentic AI. So, your 100 to 1 machine identities will probably be 1,000 to 1 with all these agents taking actions on your behalf. So, this is a time for the trust foundations to really get upgraded for AI, for quantum safety, and that's what DigiCert's been doing with our customers. We are helping them become crypto agile to embrace this world of AI and quantum.
T
Terry Sweeney2:30
Well, as we look at the horizon, it's clear to see that machine-to-machine interactions are only going to increase exponentially, as you pointed out. Are organizations underestimating the systemic risks in identity and the crypto management strategies that are going to have to evolve with it?
A
Amit Sinha2:49
I think there's a growing awareness. The two big topics at RSA are how do I trust AI and is quantum going to destroy our digital trust fabric and how do we prepare for that? On the AI side, I'd say as organizations embrace agents, agents need durable, immutable digital passports. You know, when you join my organization, you come with a real identity and that's validated. And based on that identity, I give you authorizations and permissions to access different resources. But if I don't like you, I can revoke it and you're out of the organization. When agents get into an organization, we need to start thinking about what's the durable identity, right? They just can't assume my identity and keep doing actions on my behalf. By next year, I'll probably have six agents working for me. Where's my kill switch? Where's my governance? Where's my audit trail of what actions they've taken on my behalf? So, DigiCert, we look at the AI trust problem in two buckets, right? On the agent side, we are enabling organizations with durable cryptographic identities. We've solved the machine identity problem. We know how to name machines, that's DNS. We know how to give them digital passports, that's PKI. And standards are evolving to enable the same mechanisms for AI agents, where they have durable identities that can then be the basis of zero trust policies.
T
Terry Sweeney4:13
Well, I want to go back to the word you used, immutable. Are these AI agents externally immutable as well? Is it possible they could be tampered with to redirect them for more malicious means?
A
Amit Sinha4:28
Yeah, you know, we know how to do that for software. When you download a piece of Apple software on your iPhone, that entire package is signed and tamper-proof. Your OS checks and makes sure that this is the original Apple software before it runs it. We need to have that same kind of identity and authenticity around AI agents. If Nvidia releases a Nemo agent, they better sign it. They better produce an AI bill of materials that says, 'Here's how this was trained. Here are the capabilities.' And have evidence that it's not been tampered with or fine-tuned after the fact, right? And that's what we're trying to bring to organizations as they are embracing trustworthy AI.
T
Terry Sweeney5:10
Attackers are also using AI to automate reconnaissance, impersonation, and credential abuse. What are your thoughts around how enterprises need to evolve to address the next-level nature of these threats?
A
Amit Sinha5:28
I mean, it's a great question. The phishing attacks are getting more sophisticated. It's very easy for someone to fake my voice or fake a video and send a compelling message to an employee to take an action. All that then points to how do we trust AI content, right? Again, at DigiCert, we've been doing this with software, with documents. You know, you can sign a PDF document and it holds up in a court of law. It can't be tampered with. We believe the same mechanisms need to extend to media so that you can have trustworthy media. We live in a world of zero trust media. You'll just assume everything is fake unless it comes with a signed, stamped seal that says, 'Here's the content provenance. Here's who created it. Here were the subsequent changes applied.' And you can verify that this is from the original source, only then do you trust it. So, that helps reduce phishing and impersonation and fake attacks. But that's a huge training cycle. We barely got employees trained on not clicking on bad links and now we need to train them on being able to recognize what's real and what's fake. And for that, you need cryptography to come to the rescue. And what DigiCert's done is we've worked with industry leaders and we are now a certificate authority for the content provenance initiative. You'll start seeing media that is signed with a tamper-evident seal of record.
T
Terry Sweeney7:02
Well, let's talk about quantum. The post-quantum deadlines are tightening. From where you sit, are companies taking the timeline seriously? And are there any tells around who's being smart about their post-quantum approach? What are you seeing there?
A
Amit Sinha7:21
That's a great question, Teddy. Look, I've been screaming about this topic for 3 years and I feel like this year the world has moved from quantum is an academic topic to what can we really do about it. The deadline to retire asymmetric cryptography is 2029. The reality is if most organizations start today and super prioritize it, they still run out of time. Because this is like a Y2K times 10 event, where it touches all your digital assets. In terms of where we are, 45% of the top websites have enabled quantum safe key exchange. And because these NIST standards that DigiCert worked with various bodies are now available, quantum safe authentication and encryption is available today, but it is a massive upgrade to infrastructure, to software. You might have a document that you signed that's supposed to live for 10 years, it needs to be put in a quantum safe envelope again, right? So, it is a systematic problem and what DigiCert's doing is we're helping people become crypto agile. It starts with, 'Here's an inventory of all my assets within my organization, machines, software, documents, content, etc.' Once you have the inventory, you do automation, classical cryptography automation. And by the way, that's needed for the 47-day mandate anyways. Over the next 3 years, certificates are shrinking, so you need to automate all of this, even with classical cryptography. And that timeline aligns with quantum upgrade. So, once you have crypto agility, you have the ability to swap classical algorithms with quantum safe ones.
T
Terry Sweeney8:59
Thanks for that, Amit. Take us out with some thoughts around what you see as the strategic mind shift that's going to be required to deal with this intersection of AI, identity, and long-term cyber resilience.
A
Amit Sinha9:14
That's a great question. I think we're looking at the foundational trust fabric. That's PKI, that's DNS, that's certificate life cycle management. This is going through a once-in-a-30-year upgrade cycle to prepare for the onslaught of all these machines, these AI agents, right? And then, the foundational algorithms that guarantee us this digital trust need to be upgraded to quantum safety. So, this is a 3 to 5-year sustained tailwind for us as a business like DigiCert, but it's also a massive opportunity for organizations to really upgrade their trust fabric, which would be essential to embrace AI and become quantum safe.
T
Terry Sweeney10:01
All right. Well, I always learn something from you. Thanks so much for the meta view of AI, quantum, and identity. So much going on here. You've helped us make a lot more sense of it. Thanks for joining us on Newsdesk today.
A
Amit Sinha10:16
Thank you, Terry. I always enjoy our conversations.
T
Terry Sweeney10:19
We've been talking with Amit Sinha of DigiCert. This has been Terry Sweeney for the Dark Reading Newsdesk. Thanks for joining us for this segment. We'll see you next time.