working wikily
Smarter ways to work
AI & Automation ·

WinMagic Pitches Unified Identity for AI Agents

WinMagic unified AI agent identity architecture uses endpoint verification for users, devices, workloads, and machine identities.

By Working Wikily Newsroom
Hands typing on a laptop beside a glowing humanoid robot and floating data dashboards.
Image: WInMagic

WinMagic is arguing that AI agents should use the same trust architecture as people, devices, service accounts, and cloud workloads, rather than creating a separate identity system. The cybersecurity company points to a 2025 survey reporting 82 machine identities for every human identity, with 70% of respondents viewing identity silos as a root cause of cybersecurity risk. Its approach centers on verifying the actor, platform, and security conditions at the point of access. WinMagic says its MagicEndpoint product can work alongside existing identity and access management systems.

Identity Beyond Human Users

AI agents can access data, call application programming interfaces, use enterprise tools, and act for people or other systems. WinMagic’s proposal is that each actor should have a trusted witness at the point of access that can verify who is acting, what platform they are using, and the conditions of that access.

The company’s position aligns with work by the National Institute of Standards and Technology and its National Cybersecurity Center of Excellence, which is exploring standards-based methods to identify, manage, authorize, and audit software and AI agents. A February 2026 concept paper proposes extending existing identity standards rather than creating new infrastructure.

“Identity is what you verify before you give access. Online, it cannot be the user alone. It has to be the actor, on a platform, under a defined set of conditions. Once you define identity that way, there is no reason to build a new architecture for a new actor.”

Thi Nguyen-Huu, President and CEO at WinMagic

Identity And Authorization Differ

WinMagic distinguishes identity verification from authorization. The release describes tokens as tools designed to carry authorization, or what an actor is permitted to do, rather than confirm identity at the moment access is requested.

Under the company’s model, identity is checked in the communication channel at access time. The verifier can assess whether the approved actor is present, authorized, and operating on a platform that still meets the required security conditions.

“Adding a specialized control for every environment can look like progress, but it creates more policies and exceptions to manage.”

Thi Nguyen-Huu, President and CEO at WinMagic

Endpoint Based Verification

WinMagic says a unified architecture does not require every environment to use the same credentials, policies, or security conditions. Organizations can select signals for each use case while applying a consistent decision process for whether access should continue.

In connected environments, the endpoint can evaluate local conditions while external systems supply authorization and risk signals. In disconnected or air-gapped environments, the endpoint takes on more responsibility. If required conditions change, the company says the Live Key, which is protected in device hardware, is unavailable for the next connection.

“A unified architecture does not mean every environment works the same way. The conditions change; the principle does not. Access continues only while the conditions that justified it still hold. Until now, the only way to approximate that was a timer, which is a guess about the future.”

Thi Nguyen-Huu, President and CEO at WinMagic

One Architecture For Access

For people using devices, WinMagic identifies the endpoint as the trusted witness. It says the endpoint can distinguish between an authorized user on an approved device, an unauthorized actor, and a legitimate person without permission, reducing the need for repeated password prompts or portable tokens.

MagicEndpoint uses this model alongside current identity and access management systems. The company says mutual Transport Layer Security enables machines to prove possession of cryptographic keys during a connection, while the endpoint can hold the key and vouch for a verified user.

“We keep building new identity systems every time a new actor appears. The witness we need is already at the source. The endpoint is already there when the actor acts on the platform. We do not need another identity silo. We need one architecture, and an endpoint allowed to vouch.”

Thi Nguyen-Huu, President and CEO at WinMagic

From an announcement by WInMagic.

More in AI & Automation