A Federated Trust Architecture for Autonomous AI Agents: An Enterprise Architecture Extension to Zero Trust
by Mohammad Tawrid Hyder, Chief Researcher, ZenApe Solutions, Senior Member, IEEE
Abstract—The emergence of autonomous artificial intelligence (AI) agents is poised to disrupt enterprise technology markets by enabling self-reasoning software entities to execute critical business functions. Autonomous agents represent a fundamentally different paradigm than conventional applications in that they operate in a dynamic and interactive manner to perform generic tasks. This characteristic creates new security challenges for existing Identity and Access Management (IAM) and Zero Trust Architecture (ZTA) solutions, which have to date focused on controlling and mitigating risks related to trusted and authenticated entities without considering their potential to behave unpredictably or maliciously..
The paper introduces the concept of Federated Trust Architecture (FTA) for managing trust between autonomous AI agents that extends zero-trust principles to runtime behavioral analysis while also facilitating trust exchanges between entities in a federated fashion. Most AI governance literature focuses on high-level policy guidance — such as risk-management frameworks and management-system standards — rather than on the technical mechanisms needed to achieve autonomous system reliability. These frameworks establish important principles for responsible AI use, but generally stop short of specifying how those principles translate into system architecture, which is the gap this paper aims to help close. The article discusses the concepts of decentralized identity, verifiable credentials, trust evaluation, and enterprise governance in the context of autonomous agents.
The contribution of this work is a discussion of an enterprise architecture for autonomous agent management that can be used as a reference for designing and implementing technical and cryptographic solutions for trust management in agentic AI systems.
Index Terms—Agentic AI, Enterprise Architecture, Zero Trust, Trust Management, Autonomous AI Agents, Decentralized Identity, Runtime Governance, AI Security
I. INTRODUCTION
HE enterprise use of artificial intelligence (AI) is entering a new paradigm in which AI-assisted autonomous agents exhibit emergent behaviors. These agents can perform complex tasks such as cybersecurity, procurement, and customer relations with little or no human intervention. Unlike traditional enterprise software, autonomous agents offer security challenges because their behaviors are not fully predictable or prescribe-able [10],[13]. This is because such agents take actions determined by prompts, external data, and tools rather than hard-coded logic. Thus, an autonomous AI agent that was initially authenticated and authorized could turn malicious or malfunction due to tampered external data, tools, prompts, or decision-making logic.
As it stands, information security technologies are mainly concerned with information-centric security, typically through the enforcement of policies that determine which authenticated and authorized entities can access which resources. Identity and Access Management (IAM) policies usually answer the questions “who is requesting access?” and “what is the entity allowed to do?” [1],[4]. However, as discussed in later sections, with autonomous agents, a more pertinent question is “should this agent be trusted based on its behavior?” Thus, this paper proposes a federated trust architecture that extends the Zero Trust security model to incorporate behavioral attributes.
This study’s main contribution is a conceptual design of a trust management system suitable for implementing the federated trust architecture. In later sections, this paper describes related concepts and works, including AI security, Zero Trust Architecture, decentralized identity management, and AI governance. Following that, the research problem is fully described, after which this paper proposes potential solutions. Finally, the enterprise architecture implications of the proposed solutions are discussed, and the paper’s limitations and future research directions are identified.
II. Background and Related Work
A. Autonomous AI agents
Recent developments in large language models have enabled the creation of autonomous AI agents. Using the power of natural language processing, these agents perform reasoning and action to accomplish tasks such as browsing the web, calling APIs, and planning. ReAct is one such approach, interleaving reasoning traces with actions such as web browsing, API calls, and plan execution [12].
Autonomous AI agents have the potential to disrupt the traditional information technology landscape by performing critical operations. However, these technologies also present significant risks that require careful consideration.
B. Zero Trust Architecture
Zero Trust Architecture (ZTA) is a security model where the default is to not allow access to enterprise resources [1],[18]. This approach requires verifying each access request based on the information about the requesting entity, the resource, and the environment from which the request originates. Traditional enterprise security solutions relied on securing the network perimeter to protect corporate assets. In contrast, BeyondCorp, one of the proposed Zero Trust implementations, secures the corporate data itself and makes it inaccessible to unauthorized users across all network segments [9]. Simply put, while the traditional approach followed the paradigm of “trust the network but verify the host,” Zero Trust security follows the approach of “never trust, always verify.” While zero trust architecture typically refers to verifying hosts, this paper aims to extend the zero-trust paradigm to include verifying the trustworthiness of autonomous AI agents.
C. Decentralized Identity
Decentralized identity technology enables entities to prove possession of verifiable attributes. Notably, decentralized identifiers can be used to issue verifiable claims about autonomous AI agents. Decentralized identifiers apply to both humans and machines. It is essential to recognize that identity is only one component of trust, and decentralized identifiers contribute only one part of the autonomous agent trustworthiness solution [2],[3].
D. AI governance
Various AI governance frameworks address the need to operationalize responsibility and accountability for autonomous systems. For instance, NIST RMFs and ISO/IEC 42001 AI Management System standard provide governance policies for ethical and responsible AI use [5],[8]. Most AI governance literature addresses the technical aspects of achieving autonomous system reliability [22]. In addition, the majority of works address high-level AI governance policies, such as risk management frameworks, without elaborating on specific technical implementations. Emerging regulation such as the EU AI Act increases the pressure on enterprises to operationalize these principles technically, not just procedurally [20].
III. Research Gap
As the background section notes, much of the related work contributes considerably to the objectives of this paper. Namely, as mentioned, prior research has made considerable progress toward addressing the challenges identified for this study [14]. Nevertheless, as will now be explained, there are still some gaps that require further investigation.
First, identity management solutions generally address the authentication needs of an autonomous AI agent, but not its overall trustworthiness.
Second, while Zero Trust solutions generally address the need for continuous verification, such solutions typically evaluate access requests from authenticated identities rather than an agent’s behavior over time, not autonomous agents.
Third, there is a need for the research and development of a reference architecture that would allow for trusting autonomous AI agents.
This paper attempts to address the research question of how organizations utilize a federated trust layer to evaluate and exchange trust information about autonomous AI agents.
IV. Federated Trust Architecture
This paper proposes a 7-layer reference architecture for implementing federated trust management for autonomous agents. An important aspect of this architecture is that it recognizes trust to be a multi-dimensional concept that spans across several domains, including identity, behavior, and governance.
In this paper, “federated” means that no single organization is the sole authority over an autonomous agent’s trustworthiness: trust assessments are produced, exchanged, and relied upon across organizational boundaries under a shared but non-centralized set of rules [3],[11],[15],[19]. Concretely:
- Trust domains: each participating organization is a trust domain with its own identity provider, policy engine, and audit trail. The FTA does not require domains to share infrastructure, only a common trust-exchange format.
- Federation authority: a neutral industry body, a regulator-endorsed accreditation scheme, or a designated lead organization under a bilateral agreement issues the schemas and accreditation criteria that let member domains recognize each other’s credentials, and maintains the revocation list below.
- Issuer/verifier relationships: any domain can issue verifiable credentials and behavioral attestations about agents it operates (issuer); any domain evaluating another domain’s agent (verifier) checks those credentials against the federation authority’s accreditation list rather than trusting the issuing domain unconditionally.
- Trust-exchange protocol: when an agent from domain X requests access in domain Y, domain Y’s Policy Decision Point queries domain X’s Trust Intelligence Layer (Layer 7) for a signed, time-stamped trust assessment, independently verifies X’s accreditation, and combines that with its own local evaluation.
- Governance agreements: joining requires accepting minimum audit-logging requirements, incident-disclosure obligations, and an agreed liability allocation when a federated agent causes harm.
- Dispute handling and conflicting assessments: when two domains disagree, the resource-owning domain’s local Policy Decision Point has final say — the counterpart’s assessment is one input, not a binding verdict, since the domain bearing the risk should retain control.
- Revocation: a domain that discovers an agent it vouched for has misbehaved must revoke its credentials through the federation authority’s revocation list, which other domains check before relying on a cached assessment.

Fig. 1. Federated Trust Architecture – cross-domain view of seven-layer stack
The 7 layers are as described below:
A. Layer 1: Identity Layer
Identity layer handles the concepts of authentication and serves as a cryptographic root of trust for the other layers. Making use of decentralized identity concepts, this layer enables issuance of verifiable identities to autonomous AI agents, enabling organizations to distinguish between genuine and fake agents.
B. Layer 2: Credential Layer
The credential layer handles the concepts of attestation and verifiable attributes. This layer enables storage of attributes attested by either parties or organizations to describe certain properties of interest about an entity. Some of the attributes stored in this layer may include software provenance, security assessment reports, behaviors permitted, operational capabilities, and compliance certifications, among others.
C. Layer 3: Trust Evaluation Layer
The Trust Evaluation Layer is the layer most distinct from existing IAM and ZTA models: rather than treating trust as binary, it evaluates agents along a continuum, as described below. This layer takes care of the trust evaluation needs of enterprises and organizations ranging from low to high assurance. Unlike the traditional approaches where trust was assumed to be either intrinsic (in-house) or non-intrinsic (third-party), Trust Evaluation Layer makes use of the concept of trust continuum to evaluate the degree of trust that can be placed on autonomous AI agents based on factors such as identity confidence, credential trustworthiness, behavioral analysis, runtime governance, policy compliance, and threat intelligence. This layer’s output feeds directly into Zero Trust Policy Decision Points, giving PDPs a trust signal to draw on when authorizing agent requests. In this way, the Trust Evaluation Layer enables enterprises to make evidence-based decisions when granting or denying requests by autonomous agents [25].
D. Layer 4: Privacy Layer
Privacy Layer handles concepts related to trust assurance, assurance levels, and information camouflage. With respect to information camouflage, it is paramount that organizations protect sensitive and private information about autonomous AI agents. This is especially important given the fact that different organizations have different requirements with respect to information about the autonomous agents they intend to engage with. With respect to trust assurance, this layer ensures that sharing of information about the autonomous agents takes place in a manner that is compliant with data protection laws and regulations.
E. Layer 5: Zero Trust Policy Layer
Zero Trust Policy Layer deals with the concepts and aspects of Zero Trust policies related to autonomous AI agents. Policy Decision Points (PDPs) and Policy Enforcement Points (PEPs) can leverage the information provided by the Trust Evaluation Layer to make evidence-based security decisions.
F. Layer 6: Runtime Governance Layer
Runtime Governance Layer focuses on monitoring of autonomous AI agents to detect any anomalous behaviors. This layer can, for instance, analyze patterns of tools, API usage, and data access behaviors by autonomous AI agents to help in identifying suspicious activities that may require further investigation.
G. Layer 7: Trust Intelligence Layer
Trust Intelligence Layer focuses on auditing, governance, and analytics and provides the necessary inputs for decision making at various levels. This layer helps in ensuring trustworthiness of individual autonomous AI agents as well as at enterprise level. It achieves this by storing and analyzing audit data, logs, and other telemetry data.
H. End-to-End Example
Acme Corp wants to let a procurement agent operated by a supplier, Vendor Co, submit and negotiate purchase orders inside Acme’s procurement system.
- Identity (L1): Vendor Co’s identity provider issues the agent a decentralized identifier and a signed credential naming Vendor Co as operator.
- Credential (L2): Vendor Co attests to the agent’s software provenance and any third-party security assessment it’s passed.
- Trust Evaluation (L3): On the agent’s first request, Acme scores it on identity confidence and credential trustworthiness alone — no behavioral history yet.
- Privacy (L4): Only accreditation status crosses the boundary, not Vendor Co’s internal system details.
- Zero Trust Policy (L5): Acme’s PDP combines the trust score with a policy like “external procurement agents may create draft POs under $10,000 without human approval” to decide whether the PEP allows the request.
- Runtime Governance (L6): Acme watches for anomalies — e.g., the agent suddenly querying a pricing database it’s never touched.
- Trust Intelligence (L7): The outcome updates a running trust record, which Acme can share back to the federation so other organizations evaluating the same agent benefit.
V. Enterprise Architecture Alignment
This section positions autonomous-agent trust management as an enterprise capability by mapping the FTA onto TOGAF’s architecture domains. As such, this paper aligns the proposed architecture with enterprise architecture frameworks such as TOGAF Architecture Domains [6],[21].
A. Business Architecture
At the business architecture level, the Federated Trust Architecture (FTA) mainly focuses on addressing the problem of enabling autonomous AI agents to carry out their functions within enterprise systems. For instance, some of the business functions where autonomous AI agents can be used include autonomous procurement, AI cybersecurity operations, and intelligent workflow management among others. The above functions imply that the FTA can enable organizations to develop policies that will govern the deployment of autonomous AI agents.
B. Data and Information Architecture
The Data and Information Architecture handles the storage and management of information about the autonomous AI agents. In the context of the FTA, such information includes identities, credentials, behaviors, and other relevant data elements related to the agents [21].
The notions of privacy and assurance levels are paramount in this architecture domain because organizations will likely be required to release as little information as possible while still being able to make accurate trust decisions. By relying on verifiable credentials and other related technologies, the FTA can facilitate the implementation of information assurance principles by enabling organizations to utilize technologies that allow them to perform privacy-preserving computations.
C. Application Architecture
The Application Architecture domain deals with the enterprise application portfolio and the key applications that can be leveraged to support the FTA. As a federated trust architecture, the FTA would primarily rely on cloud applications such as identity and credential management systems, trust evaluation services, and policy enforcement services among others.
D. Technology Architecture
The Technology Architecture domain focuses on technology infrastructure including servers, cloud technologies, service meshes, and other relevant technologies that can be used to host the FTA.
E. Security and Governance Architecture
The Security and Governance Architecture domain handles security aspects and governance procedures, including those that can be leveraged to host the FTA. Some of the areas that can be explored in this domain include the Zero Trust Network Architecture, Service Mesh security controls, and Application Programming Interface (API) Gateways among others [7].
VI. Discussion
Autonomous AI agents are changing enterprise technology markets by automating tasks that previously required human judgment and initiative. The discussion above suggests that IAM and Zero Trust Architecture (ZTA) solutions will be essential in securing autonomous AI agents but will require extended trust evaluation capabilities to ensure that such agents are performing legitimately. This is an important point because IAM/ZTA solutions typically operate on a trust binary where trust is either present or absent. This approach breaks down when applied to autonomous AI agents because these entities exhibit emergent properties during runtime, thereby making it challenging to distinguish between legitimate and malicious behavior [29], [30].
A critical shortcoming of existing IAM solutions is their inability to account for the possibility that an entity that has been authenticated and authorized could be compromised, malfunction, or be manipulated. In other words, authentication and authorization only address the question of who an entity is and what it is allowed to do, not whether it will do what it is supposed to do. This is particularly true for autonomous AI agents, where authenticity does not guarantee legitimacy because of the possibility of prompt injection, data poisoning, tool compromise, and prompt injection, among other attacks. By contrast, the FTA recognizes that trust is not a binary but a spectrum and therefore provides a framework for evaluating the degree to which autonomous agents can be trusted [17],[27].
VII. Limitations
The paper makes several suggestions for future research, including the following:
A. Trust model calibration
The FTA concepts presented in this paper can be applied to many different domains, including cybersecurity, financial transactions, and general enterprise functions. Variations in the type of application would likely dictate differences in trust evaluation criteria and levels of assurance.
B. Trust initialization for new agents
Autonomous AI agents will typically have a limited operating history during their initial deployment period, which might impact trust assessment.
C. Industrial and regulatory alignment
While foundational identity concepts such as verifiable credentials and decentralized identifiers are being standardized, similar work is needed to harmonize concepts concerning AI agent trust assessment and assurance.
VIII. Future Research Directions
Future research should be devoted to exploring ways of operationalizing the concepts described in this paper. Some interesting directions include:
A. Cryptographic Trust Protocols
A follow-up technical paper could describe cryptographic protocols that might be used to implement the ideas in this paper. Particular areas of potential value might include zero-knowledge trust verification, post-quantum secure agent authentication, and privacy-preserving reputation systems [26].
B. Automated Trust Decision Support
Future research could also look at ways to design automated trust decision systems, for instance, by employing machine learning algorithms to perform some of the functions described in this paper in an automated way [16],[24].
C. Industry Use Cases
It will be important to analyze potential industry applications of the FTA concepts in more detail, for instance, by looking at ways to apply them in Kubernetes-based AI workloads and enterprise service meshes.
IX. Conclusion
This paper describes a federated trust architecture that enables the management of trust between autonomous AI agents [24]. By extending Zero Trust to the runtime behaviors of autonomous agents, this paper facilitates organizational assurance of the trustworthiness of such agents. By building on concepts like decentralized identifiers and verifiable credentials, this paper’s trust architecture enables organizations to collaborate while safeguarding data privacy, and enterprise governance interests.
This paper’s contribution is a conceptual architecture — not yet a validated or implemented system — for evaluating agent trustworthiness; Sections VII and VIII outline what remains to be demonstrated before it can be considered proven in practice. This work will be continued in future research by further developing the concepts introduced in this paper in order to arrive at the technical architecture.
References
- National Institute of Standards and Technology (NIST). Zero Trust Architecture. NIST Special Publication 800-207, August 2020. [Online]. Available: https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf
- World Wide Web Consortium (W3C). Decentralized Identifiers (DIDs) v1.0. W3C Recommendation, July 2022. [Online]. Available: https://www.w3.org/press-releases/2022/did-rec/
- World Wide Web Consortium (W3C). Verifiable Credentials Data Model v2.0. W3C Candidate Recommendation, 2024. [Online]. Available: https://www.w3.org/TR/vc-data-model-2.0/
- National Institute of Standards and Technology (NIST). Digital Identity Guidelines. NIST Special Publication 800-63, September 2025. [Online]. Available: https://www.nist.gov/identity-access-management/projects/nist-special-publication-800-63-digital-identity-guidelines
- National Institute of Standards and Technology (NIST). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST SP 1270, January 2023.
- The Open Group. The TOGAF® Standard, 10th Edition. The Open Group Standard, 2022.
- International Organization for Standardization (ISO). Information security, cybersecurity and privacy protection — Information security management systems. ISO/IEC 27001:2022.
- International Organization for Standardization (ISO). Information technology — Artificial intelligence — Management system requirements. ISO/IEC 42001:2023.
- Ward, R. and Beyer, B. “BeyondCorp: A New Approach to Enterprise Security.” ;login:, USENIX Association, Vol. 39, No. 6, Dec. 2014, pp. 6–11.
- Greshake, K., et al. “Not what you’ve signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection.” Proceedings of ACM AISec, 2023.
- SPIFFE/SPIRE Technical Community. Secure Production Identity Framework for Everyone Specifications. CNCF Incubating Project Documentation, 2024.
- Yao, S., et al. “ReAct: Synergizing Reasoning and Acting in Language Models.” International Conference on Learning Representations (ICLR), 2023.
- Xi, Z., et al. “The Rise and Potential of Large Language Model Based Agents: A Survey.” arXiv preprint arXiv:2309.07864, 2023.
- Zou, Z., et al. “BlockA2A: Towards Secure and Verifiable Agent-to-Agent Interoperability.” arXiv preprint arXiv:2508.01332, 2025.
- Hardjono, T. “Federated Authorization over Access to Personal Data for Decentralized Identity Management.” IEEE Communications Standards Magazine, Vol. 3, No. 4, 2019, pp. 32–38.
- Groth, J. “On the Size of Pairing-Based Non-interactive Zero-Knowledge Arguments.” Advances in Cryptology – EUROCRYPT, pp. 305-326, 2016.
- Microsoft Zero Trust Team. Evolving Zero Trust for AI-Driven Enterprise Workloads. Microsoft Technical Whitepaper, 2024.
- Rose, S., et al. Zero Trust Architecture: NIST Reference Framework Implementation Guide. NIST Special Publication 1800-35, 2023.
- Hussain, M., Pal, S., Jadidi, Z., Foo, E., Kanhere, S. “Federated Zero Trust Architecture using Artificial Intelligence.” IEEE Wireless Communications, Vol. 31, No. 2, pp. 30–35, April 2024. DOI: 10.1109/MWC.001.2300405.
- European Parliament and Council. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, July 2024.
- Zachman, J. A. “A framework for information systems architecture.” IBM Systems Journal, Vol. 26, No. 3, pp. 276-292, 1987.
- Kampik, T., et al. “Governance of Autonomous Agents on the Web: Challenges and Opportunities.” ACM Transactions on Internet Technology, Vol. 22, 2022.
- Open Policy Agent (OPA) Community. Open Policy Agent Documentation: Unified Policy Enforcement. CNCF Reference, 2024.
- Kairouz, P., et al. “Advances and open problems in federated learning.” Foundations and Trends in Machine Learning, Vol. 14, No. 1–2, 2021.
- He, P., et al. “Attention Knows Whom to Trust: Attention-Based Trust Management for LLM Multi-Agent Systems.” arXiv preprint arXiv:2506.02546, 2025.
- National Institute of Standards and Technology (NIST). Post-Quantum Cryptography Standardization Program: Standardized Algorithms. NIST FIPS 203/204/205, 2024.
- Microsoft Security Research. The Zero Trust AI Adoption Guide: Managing Autonomous Agents in the Enterprise. Microsoft Blueprint Series, 2025.
- Gartner Inc. Architecting the Trust Fabric for Agentic AI Systems. Gartner Research Report G00793421, 2025.
- MITRE Corporation. MITRE ATLAS (Adversarial Threat Landscape for Artificial Intelligence Systems). Technical Documentation, 2024.
- OWASP GenAI Security Project. “OWASP Top 10 for Agentic Applications.” OWASP, Dec. 2025. [Online]. Available: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/

Mohammad Tawrid Hyder (Senior Member, IEEE) is a cybersecurity researcher and security architect with an academic background in computer science and technology. He received the B.Sc. degree in computer science and technology from Dalian University of Technology, Dalian, China, in 2005, and the M.Sc. degree in engineering, with a major in computer application technology, from Dalian University of Technology, Dalian, China, in 2008. His major fields of study include embedded and distributed systems.
He has held technical and leadership positions in cybersecurity, cloud security, application security, security architecture, and security research across technology organizations. He has worked with IBM, Hewlett Packard Enterprise, Datacom, Ricoh, and other technology organizations, with experience spanning cloud platforms, identity and access management, security operations, application security, and enterprise security architecture. He currently works as a Security Researcher, focusing on cybersecurity research, artificial intelligence security, zero-trust architecture, post-quantum cryptography, decentralized identity, and resilient cloud security. His research interests include quantum-resistant decentralized identity, AI-driven cybersecurity, autonomous AI-agent security, privacy-enhancing technologies, zero-trust architectures, and post-quantum cryptography.
Mr. Hyder is a cybersecurity researcher with professional interests spanning cloud security, application security, identity and access management, artificial intelligence, and emerging cryptographic technologies. He has contributed to research and professional activities related to cybersecurity, decentralized identity, quantum-resistant technologies, and enterprise security architecture. His current research focuses on developing future-proof digital trust architectures that combine decentralized identity, post-quantum cryptography, artificial intelligence, and zero-trust security principles.







