Verifying your AI agent's identity proves who it is. It can't prove that what it believes is true. Identity answers whether an agent's allowed to act. It says nothing about whether the facts behind that action are real. Most companies bought the first half of this problem. The belief audit below closes the second half, and you can start it this week.
My research agent made up a source overnight. By morning, my other agents had built a full day of work on top of it. Every one of them passed the identity check. Every permission was correct. The information was still fake, and it moved through my house while I slept.
Why isn't AI agent identity enough on its own?
Identity controls answer one question: is this agent allowed to do this? That's real work and it counts. When my agents burned a day, identity was the only reason I could trace the bad source forward and save the good work. But no identity control answers the question that does the damage: is what this agent believes actually true?
Those are two questions, and they need two different tools. Almost all the money so far has gone to the first one. The second one barely has a name yet.
John Kindervag, who created Zero Trust and wrote the foreword to my book, keeps saying it plainly. Identity is crackable. I couldn't get it out of my head in August 2026, signing books at an event in New York City built around that one word.
The room was full of sharp CISOs. Person after person told me a version of the same thing. Their AI agents are already out ahead of them. They know they have to govern them. They don't know how yet. Knowing you need to govern your agents and knowing what that means are two different things.
What is the belief set your AI agents run on?
Your belief set is everything your AI agents treat as true. It's the knowledge base someone built a year ago, the folder of shared docs, the block of instructions pasted into a settings panel, and any live pull from the open web. That pile decides what every agent downstream accepts as fact. In most companies, no human has ever looked at it as one thing.
When I told Michelle Savage, my co-author, about my bad morning, she wasn't surprised. What an AI agent is allowed to believe, she said, is the least governed document in most companies. Nobody signs it. Nobody dates it. Somebody pasted it in because they were closest to the problem, and then everyone moved on.
Michelle's team gives it a name. She calls it the Context Layer, and her team has to use it on their product spaces. Same pile, but with a name, an owner, and a place it lives. That's the whole difference.
You know who has access to your systems. You've spent a year and a budget proving it. You still don't know what your agents believe about your business. Gravitee found in February 2026 that 86% of AI agents shipped with no security sign-off at all, across 919 respondents. The belief set behind those agents got even less review.
How do you run a belief audit in one week?
Five steps. You can start every one of them this week, and most don't need your security team to begin. None of it is a purchase. It's a list, a name, a date, and one good afternoon.
Write down what one chain treats as true. Pick the agent chain closest to a customer. List every place its agents pull facts from. That list is the belief set. Most leaders have never seen it on one page, and seeing it is half the work.
Put a name and a date on each source. For every item, ask who approved it and when. If nobody signed it and nobody dated it, it isn't governed. You'll find agents running with full confidence on a doc no one has opened since last year.
Find the one belief that hurts most if it's wrong. A price. A policy. A legal fact. A discount limit. Pick the single fact that would cost you most if an agent had it backward. Then make one check confirm it against your system of record before the next agent builds on it.
Make every agent show its work. An agent has to attach where each fact came from, as a live link or a record number. "According to industry research" is not a source. A link that opens to a real page is. If an agent can't show where a fact came from, the handoff stops there.
Run the ten-minute test. Take one thing your agents produced last week. Try to trace every claim back to a real, working source. Time yourself. If you can't do it in ten minutes on a quiet afternoon, you can't do it when an auditor or your own CFO is standing over your shoulder.
Do it once and you won't look at your AI agents the same way again.
Where does Zero Trust stop and AI agent governance start?
Zero Trust checks the caller. It re-evaluates every request and continuously verifies the connection: the right identity, the right permission. It was never built to check whether the thing being passed is true. In an agent chain, the request is clean and the content is a lie. Identity waves it through, correctly, because identity was doing its job.
Kindervag's first move is always the protect surface. Name the small, knowable thing you're defending before you buy anything. So name this one. What one agent accepts from another as true belongs inside that protect surface. Almost nobody draws the line there, which is exactly why the damage lives in that seam.
Against the Agentic Trust Framework, which the Cloud Security Alliance published in February 2026, identity did its job on my bad morning. The element that failed was data governance. The framework asks five questions of every agent, and the third one is what are you eating and serving. My belief set was ungoverned, so the lie traveled at machine speed and nothing flagged it. Nothing was watching the one thing that was actually wrong.
What rule did I add to my own lab?
After that morning I added one rule: an agent has to show a source that actually opens to a real page, or the handoff stops. Not "looks right." Opens. If the link is dead or off my approved list, the work waits for me instead of moving on. I also pulled local models out of fact-finding entirely. They're good at shape. They're not built for truth.
It's slower. I know it'll hold up some research that was fine. I'll take that trade every time. A held handoff costs me a re-run of a few minutes. The fake source I missed cost most of a day and two documents rebuilt from scratch.
This holds at any size. A rule an agent checks with its own opinion isn't a rule. "Never make up a source" is useless, because an agent that invents a citation doesn't know it did. "Never pass a source that doesn't open to a real page on the approved list" is a rule a second agent can enforce. Write the kind a machine can check.
I run these agents myself, which is how I know the ground is soft. I've written more about what happens when the layer underneath the model is missing and about the agents nobody approved.
What you can do this week
Pick your customer-facing agent chain and list every source its agents pull facts from
Put an owner's name and an approval date next to each source, then flag the ones with neither
Name the single fact in that chain that costs you most if an agent gets it backward
Add a rule that any fact passed between agents carries a working link or a record number
Time yourself tracing last week's agent output back to real sources
Key takeaways
Identity proves who your AI agent is, not whether what it believes is true
The belief set is every source your agents treat as fact, and most companies have never written it down as one thing
Zero Trust continuously verifies the connection, but not the truth of the content moving through it
A rule an agent checks against its own opinion isn't a rule, so write rules a second agent can enforce
The belief audit takes an afternoon and costs nothing to start
Frequently asked questions
Isn't strong identity management enough to govern AI agents?
No. Identity tells you an agent is who it claims to be and that its permissions check out. It can't tell you the facts behind the agent's action are real. My own agents passed every identity check while building a full day of work on a source one of them invented. Identity is necessary. It isn't sufficient.
What's the difference between a belief set and a knowledge base?
A knowledge base is one source. A belief set is all of them at once: the knowledge base, the pasted instructions, the shared docs, and any live web access an agent has. Michelle Savage calls the governed version of this the Context Layer. The point is treating the whole pile as one thing with an owner and a date.
Does Zero Trust already solve this for AI agents?
Zero Trust is the right strategy and it doesn't close this on its own. It verifies the caller continuously and checks whether a request should be allowed. It wasn't designed to check whether the content moving through a verified channel is true. That's why what one agent accepts from another belongs inside the protect surface you're defending.
How long does a belief audit actually take?
The first pass takes an afternoon for one agent chain. Listing the sources is the slow part, and most leaders have never seen that list on one page. Steps two and three are quick once the list exists. The ten-minute traceability test is the one you'll want to repeat monthly.
Who should own the belief audit?
Whoever owns the agent chain can start it. Most of the work is listing sources and asking who approved them, which doesn't need a security team. Bring security in at step three, when you're deciding which fact gets checked against your system of record before an agent acts on it.
What if an agent can't show where a fact came from?
Stop the handoff. That's the rule I run in my own lab now. The source has to open to a real page on an approved list, not just look plausible. A held handoff costs a few minutes to re-run. A fake source that travels costs you a day and the documents built on top of it.
If you want to see where your own agents stand, there's a free self-assessment at verifiedagents.ai that walks you through the framework in about ten minutes.
Your agents will keep passing the identity test you built. They'll pass it the day before the loss and the morning of. The question that catches up with everyone isn't who your agent is. It's what your agent believed, and how far that belief traveled before anyone checked.
