Leadership1 publisher3 min readPublished
Human-in-the-loop is being retired, and the assurance burden shifts to machine identity
A DigiCert CTO argues the human approval step in agentic AI will disappear entirely. If he is right, the control most boards signed off on is going before its replacement is provisioned.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Jason Sabin is CTO of DigiCert Inc., described as passionate about digital trust, including digital certificate management for web, device and user identity.
- Sabin writes that many organisations still rely on a human-in-the-loop approach to agentic AI, and that 'that reliance will fade over time and, I believe, disappear entirely.'
- In 2024, Anthropic introduced Model Context Protocol (MCP), which sits in front of APIs, databases and file systems to allow AI agents to gather information from those sources.
- MCP has been in use for roughly a year and has become the default way AI agents gather data, but there is widespread recognition that it lacks strong identity and security.
- OAuth 2.1 is now the mandated authentication framework across MCP server implementations.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
Jason Sabin, chief technology officer of DigiCert, has published an argument that enterprise reliance on human-in-the-loop oversight of AI agents "will fade over time and, I believe, disappear entirely" [1][2]. That matters because the human approval step is the control most deployment approvals rest on, and the substitute Sabin describes is certificate-based machine identity that most organisations have not yet issued.
He is not a neutral witness. DigiCert's business is digital certificate management for web, device and user identity, which is precisely the infrastructure his argument makes mandatory [1].
The dependency he describes is checkable regardless. Anthropic introduced the Model Context Protocol in 2024; Sabin says it has become the default way agents gather data from APIs, databases and file systems, and that there is widespread recognition it lacks strong identity and security [3][4]. OAuth 2.1 is now the mandated authentication framework across MCP server implementations [5]. OAuth was built around human authorization, and every token still needs a person to grant it [6]. The identity layer under the default agent data path therefore assumes the presence of exactly the human that agentic deployment is designed to remove.
The failure mode is not dramatic, which is why it will be missed. Sabin's claim is that before long humans will simply tire of reauthenticating AI agents [7]. Approval fatigue does not show up in a control register as a broken control; it shows up as a standing token, a shared service account, or a scheduled refresh nobody reads. An estimated 78% of IT and security decision-makers have already experienced AI-related incidents or identified AI-related vulnerabilities [8], which leaves roughly 22% reporting neither [9]. The gate is already coexisting with that rate while a human is still nominally in the chair.
The proposed replacement is deliberately unexciting. Public key infrastructure issues digital certificates that authenticate users, devices and services, and has operated at internet scale for decades, including machine identity in IoT [10]. Sabin argues organisations are deploying AI agents faster than IoT ever grew [11], and notes that the IoT industry tried blockchain first, which forced engineers to rebuild protocols and standards for interoperability and added complexity [12]. PKI libraries are freely available and already built into most devices and operating systems [13]. For closed, high-volume identity systems he offers private Merkle Tree Certificates, which batch-issue certificates using hash-based data structures and cut the overhead of traditional certificate authority chains [14].
The harder problem for anyone planning a controlled migration is that the access point is moving. Agents are already bypassing MCP to reach APIs directly, and running inside browser extensions that log in to websites and execute tasks behind users' screens [15]. Sabin notes the HTTP-to-HTTPS transition took internet pioneers about three years [16]; MCP has been in use for roughly a year, about a third of that span [4][17], and is already being routed around.
Three things to establish before the next agent goes live. Whether your agent inventory contains identities at all, or only the credentials of the people who launched them. Whether your audit trail resolves to an agent or to a token a human granted months ago. And who, by name, is expected to reauthenticate agents at volume, because that person's fatigue is now a control assumption.