The CAC Proved Who Logged In. It Can't Prove Who's There Now.

· MagenTrust Research

The Common Access Card answers who opened the session. Zero trust and agentic AI need a second layer that answers who's still there, and whether they're still human.

Why the Department of Defense's most successful credential needs a second layer, and why that layer shouldn't be another credential.

The Common Access Card is, by almost any measure, one of the most successful identity programs ever deployed. Millions of cards in circulation. Hardware-backed PKI. Phishing resistance that most of the commercial world is still chasing twenty years later. When the DoD mandated smart-card authentication, network intrusions attributable to stolen passwords fell off a cliff. It worked.

But the CAC was designed to answer exactly one question, at exactly one moment: is the person inserting this card the person we issued it to?

That question is still worth asking. It's just no longer the question that matters most.

The moment after authentication

Every point-in-time credential, the CAC included, shares the same structural blind spot. The instant authentication succeeds, the system's knowledge of who is behind the session begins to decay. An hour into a logged-in session, the network's confidence that the cardholder is still the one at the keyboard rests on nothing but inertia.

Historically, that gap was tolerable. The threats that could exploit it, session hijacking, credential sharing, a walked-away workstation, were real but bounded. They required either physical presence or meaningful technical effort, and they didn't scale.

That assumption no longer holds, for two reasons.

The first is operational reality. Zero trust architecture, now DoD policy, with target-level implementation required across the department, is built on the premise that the network is already compromised. "Never trust, always verify" is not a slogan; it's a design requirement that every user, device, and application be continuously authenticated and authorized. A credential check at login, however strong, satisfies the authenticate but not the continuously . The department's own zero trust framework makes this explicit: verification is supposed to be an ongoing state, not a gate you pass through once.

The second reason is the one nobody designed for.

Agents don't insert cards

The zero trust framework draws a careful distinction between Person Entities and Non-Person Entities, humans versus the services, scripts, and machine identities that also operate on the network. That distinction was written when Non-Person Entities were predictable: service accounts, scheduled jobs, API integrations. Things that behaved like machines.

Agentic AI breaks the distinction where it's softest, after authentication. An AI agent operating with delegated access inside a legitimately authenticated session doesn't present a credential of its own. It inherits the human's. From the network's perspective, the session was opened by a verified cardholder, and everything that happens next is attributed to that person. Whether the actions are being taken by Sgt. Smith, by malware riding Sgt. Smith's session, or by an autonomous agent Sgt. Smith launched and stopped supervising three hours ago, the logs say the same thing.

This isn't a hypothetical. Every organization deploying AI assistants, automation, and agentic tooling is creating exactly this ambiguity at scale, on purpose, because the productivity is worth it. The question is not whether agents will operate inside human sessions. They already do. The question is whether the network can tell the difference.

What continuous human verification is, and isn't

The instinctive fix is more authentication: re-prompt more often, add step-up challenges, require the card again. This trades away exactly what makes systems usable, and it still only produces more points in time. A challenge passed at 2:00 p.m. says nothing about 2:04.

The other instinctive fix is biometrics, face, fingerprint, voice. Setting aside the friction, biometrics create a liability the DoD understands better than anyone: a database of immutable personal identifiers is a permanent target. Fingerprints can't be rotated after a breach. The OPM incident is not ancient history in this community.

Continuous human verification takes a different premise. Instead of repeatedly re-proving identity, it continuously observes whether the session exhibits the properties of a present human being, and flags when it stops. It is a presence layer, not another credential. It answers a question the CAC was never built to ask: not "who are you," but "are you still there, and are you still human?

Done right, this layer has three properties that matter for defense environments:

The window is now

The DoD's zero trust deadlines are forcing every component to inventory how it will achieve continuous authentication, and to confront the fact that point-in-time credentials, however strong, can't get there alone. At the same time, agentic AI is being adopted faster than the identity layer can adapt, in defense and everywhere else. The gap between "authenticated session" and "verified human presence" is widening on both ends.

The credential layer had its revolution twenty years ago, and the CAC won it. The presence layer is having its revolution now. The organizations that treat these as complements, hardware-backed identity at the door, continuous human verification in the room, will be the ones whose logs still mean something in an agentic world.

MagenTrust builds continuous human verification infrastructure for the agentic AI era. No CAPTCHAs, no biometrics, no PII. magentrust.ai

MagenTrust home