Leadership1 distinct publisher3 min readUpdated
A DigiCert CTO argues the human approval step in agentic AI will disappear entirely. If he is right, the control most boards signed off on is going before its replacement is provisioned.
The Board Room · Leadership desk
Compiled by The Board RoomSomething wrong?How this is made
Jason Sabin, chief technology officer of DigiCert, has published an argument that enterprise reliance on human-in-the-loop oversight of AI agents "will fade over time and, I believe, disappear entirely" [1][2]. That matters because the human approval step is the control most deployment approvals rest on, and the substitute Sabin describes is certificate-based machine identity that most organisations have not yet issued.
He is not a neutral witness. DigiCert's business is digital certificate management for web, device and user identity, which is precisely the infrastructure his argument makes mandatory [1].
The dependency he describes is checkable regardless. Anthropic introduced the Model Context Protocol in 2024; Sabin says it has become the default way agents gather data from APIs, databases and file systems, and that there is widespread recognition it lacks strong identity and security [3][4]. OAuth 2.1 is now the mandated authentication framework across MCP server implementations [5]. OAuth was built around human authorization, and every token still needs a person to grant it [6]. The identity layer under the default agent data path therefore assumes the presence of exactly the human that agentic deployment is designed to remove.
The failure mode is not dramatic, which is why it will be missed. Sabin's claim is that before long humans will simply tire of reauthenticating AI agents [7]. Approval fatigue does not show up in a control register as a broken control; it shows up as a standing token, a shared service account, or a scheduled refresh nobody reads. An estimated 78% of IT and security decision-makers have already experienced AI-related incidents or identified AI-related vulnerabilities [8], which leaves roughly 22% reporting neither [9]. The gate is already coexisting with that rate while a human is still nominally in the chair.
The proposed replacement is deliberately unexciting. Public key infrastructure issues digital certificates that authenticate users, devices and services, and has operated at internet scale for decades, including machine identity in IoT [10]. Sabin argues organisations are deploying AI agents faster than IoT ever grew [11], and notes that the IoT industry tried blockchain first, which forced engineers to rebuild protocols and standards for interoperability and added complexity [12]. PKI libraries are freely available and already built into most devices and operating systems [13]. For closed, high-volume identity systems he offers private Merkle Tree Certificates, which batch-issue certificates using hash-based data structures and cut the overhead of traditional certificate authority chains [14].
The harder problem for anyone planning a controlled migration is that the access point is moving. Agents are already bypassing MCP to reach APIs directly, and running inside browser extensions that log in to websites and execute tasks behind users' screens [15]. Sabin notes the HTTP-to-HTTPS transition took internet pioneers about three years [16]; MCP has been in use for roughly a year, about a third of that span [4][17], and is already being routed around.
Three things to establish before the next agent goes live. Whether your agent inventory contains identities at all, or only the credentials of the people who launched them. Whether your audit trail resolves to an agent or to a token a human granted months ago. And who, by name, is expected to reauthenticate agents at volume, because that person's fatigue is now a control assumption.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
PKI lets organisations issue digital certificates that authenticate users, devices or services, and has proven itself at global scale over decades, underpinning trust across the internet and machine identity in IoT.
PKI is open source, and existing PKI libraries are freely available and already built into most devices and operating systems, for example to enable SSL or TLS-encrypted communication.
Jason Sabin is CTO of DigiCert Inc., described as passionate about digital trust, including digital certificate management for web, device and user identity.
In 2024, Anthropic introduced Model Context Protocol (MCP), which sits in front of APIs, databases and file systems to allow AI agents to gather information from those sources.
Sabin writes that many organisations still rely on a human-in-the-loop approach to agentic AI, and that 'that reliance will fade over time and, I believe, disappear entirely.'
MCP has been in use for roughly a year and has become the default way AI agents gather data, but there is widespread recognition that it lacks strong identity and security.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor byline, no citations
The cluster contains exactly one item: a contributed opinion column by the CTO of a certificate authority, published under Forbes' council program. It cites no survey, specification, standards document, deployment, or outside expert. Two descriptive facts (MCP's 2024 introduction by Anthropic; PKI's decades of certificate-based authentication) are safe background, but every claim doing analytical work - the disappearance of human-in-the-loop, the 78% incident rate, agent growth outpacing IoT, agents already bypassing MCP, the scope of the OAuth 2.1 mandate - is unattributed assertion.
No verifiable adoption data
Nothing in the supplied material establishes measurable adoption of the proposed remedy or of the trend it responds to. The piece asserts MCP is 'the default way AI agents gather data', that agents are bypassing it, and that agent deployment outpaces IoT, but supplies no server counts, certificate issuance volumes, customer deployments, or dated releases. No adoption observation could be recorded without inventing facts, so this dimension is left unmeasured.
Claims run well ahead of shown evidence
The framing is absolute and near-term - human oversight will 'disappear entirely', OAuth 'stops working', 'PKI is ready today', agents are already bypassing protocols - while the supporting record is one unsourced statistic and a set of analogies to IoT blockchain failures and the HTTP-to-HTTPS shift. The direction of the underlying problem (agents need verifiable identity) is real and modestly stated elsewhere in the piece, which keeps this short of the maximum, but the certainty and timing claims are substantially overstated relative to anything demonstrated here.
Vendor author advocating own product category
The author is CTO of DigiCert, a commercial certificate authority, and the article's conclusion is that enterprises should adopt PKI, the AI Identity Certificate, and Private Merkle Tree Certificates - the products his company issues - while the incumbent alternative, OAuth, is declared unfit. It runs in a paid-membership contributor channel rather than through independent editorial commissioning, and the commercial interest is disclosed only as a job title. Alignment between the author's revenue and the recommendation is close to total.
Low - uncorroborated vendor opinion
Confidence is capped by structure rather than content: one publisher, one source, one interested author, no adoption measurement, and no contradicting or corroborating voice in the cluster. Only the byline facts and the plainest descriptive background can be held with any assurance; the forecast and the quantitative claims would need independent sourcing before they could carry weight in a decision.
science
OX Security says MCP command execution is a design choice, so server owners own the risk1 distinct publisher
security
The credential store nobody inventoried: MCP servers now hold the keys to everything they touch1 distinct publisher
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
leadership
Anthropic's own telemetry: 93% of permission prompts approved. Budget for blast radius, not reviewers1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026