Army expands Zero Trust identity requirements to weapons and AI agents

The Army is moving about 5,000 IT systems onto a single enterprise identity and access management platform while extending Zero Trust beyond traditional networks. An Army official said the approach must cover every human and non-human entity that accesses resources, including devices, weapon systems, and AI agents. He described Zero Trust as an ongoing adaptation to evolving threats rather than a one-time purchase or compliance exercise.
EXPANDED:
The Army is shifting roughly 5,000 information systems onto one servicewide identity and access management platform. Many are older systems with accumulated modernization backlogs, so officials are designing several onboarding paths instead of one uniform technical fix. Zero Trust is also moving beyond office networks into battlefield systems, operational equipment, weapons, and AI tools.
David Thompson, who leads E-ICAM at Army CPE C2IN, said identity is central: every person, device, interface, or virtual component seeking resource access must be identified, tied to credentials, and authorized. He framed Zero Trust as ongoing adaptation, not an off-the-shelf purchase or a checklist. Curtis Dukes of the Center for Internet Security said legacy debt remains