Why a Breakout Star in Digital Trust Bets on Cryptographic Control, Not Just Agent Registration

In July 2026, analyst firm ABI Research published an analysis of Garantir’s agentic security announcement. Garantir is a cryptographic services provider, and its GaraTrust platform now covers a fifth pillar of digital trust: security for autonomous AI agents. ABI called Garantir a “breakout star in digital trust” and used the launch to make a broader point about the market: registering an AI agent is not the same as controlling what it does.

In short: ABI Research found that Garantir extended its existing cryptographic portfolio, delegated key and certificate access, signing, and tokenization, to AI agents, rather than building a separate point product. The report’s central argument is that AI agent registries alone are only a first step, and that meaningful agentic security requires fusing agent registration with cryptographic control of agent behavior. ABI credited Garantir with joining those two halves and operating below the application layer, which it framed as a step ahead of much of the field.

The rest of this article walks through what the report covered, the gap it identifies, and where it places Garantir.

What Did ABI Research Say About Garantir?

ABI Research examined Garantir’s move to add agentic security as the fifth pillar of the GaraTrust platform, alongside data security, passwordless authentication, certificate management and PKI, and software supply chain security.

The report is direct that this is not a new point solution or a departure from Garantir’s positioning. ABI reads the announcement as Garantir applying its established cryptographic services, delegated key and certificate access, signing, and tokenization, to a new class of actor: the AI agent. It places that decision inside a wider surge of activity across cryptographic services, identity, and non-human identity, and among standards bodies and national governments moving quickly on agent governance.

Why Do AI Agent Registries Keep Coming Up?

An AI agent registry is an inventory. It records that an agent exists, who created it, and what it is. It does not, by itself, govern what that agent is permitted to do.

Much of the ABI report is spent on registries, because that is where the market’s attention currently sits. The report points to real momentum: Estonia’s proposal to register agents against official government ID numbers, Google’s Agent2Agent protocol and registry, and the IETF’s Agent Name Service proposal. Regulatory pressure reinforces it, with documentation requirements under the EU AI Act and DORA and an August 2026 compliance deadline making agent inventories a practical first step.

What Gap Does the ABI Report Identify?

ABI frames the risk plainly: a registry can create an illusion of security. Knowing an agent exists is not the same as controlling its behavior, and static registries struggle to keep pace with agents that spin up dynamically, chain actions, and even create other agents.

This is the report’s most useful idea for security teams. Inventory and visibility are necessary, but on their own they leave the actual access control problem untouched. ABI argues that registry initiatives have to be fused with corresponding control mechanisms, or they fall short of both the threat and the emerging documentation benchmarks.

How Does ABI Describe Garantir's Approach?

The report credits Garantir with joining the two halves: agent registration coupled with cryptographic control of agent access and behavior.

In ABI’s description, Garantir supports agent registration as a non-human identity through dynamic enrollment and ephemeral attestation, backed by signed, SIEM-verifiable records that tie each agent to a user and a scope. It enables HSM signing of agent actions through a Model Context Protocol wrapper, using just-in-time access, MFA, or quorum approval to delegate short-lived, per-session credentials. Those same step-up controls support a human-in-the-loop model, inserting a required human approval at the point of key access before higher-risk actions can proceed.

Two differentiators stand out in the analysis. First, ABI notes that Garantir built its approach on cryptographic primitives rather than limiting it to SSH-based methods. Second, and more significant in the agentic context, Garantir operates below the application layer. Because an agent effectively is the application, controls that sit at the application layer, such as OAuth-based defenses and gateways, are exposed to the same attacks the agent is. Operating beneath that layer, in ABI’s reading, puts Garantir a step ahead of much of the field.

What Does the ABI Report Recommend for the Market?

ABI closes with guidance aimed at the broader industry, not just one vendor. A few themes matter for anyone evaluating agentic security.

Existing security capabilities still apply, and vendors should extend proven cryptographic methods to agents rather than reinventing them. Hard problems remain, and the report singles out multi-hop delegation, where an agent creates its own agents, as an area current OAuth handles poorly. Standards interoperability is essential, with MCP called out as the first priority for cryptographic providers and OAuth 2.0/2.1, OpenID Connect, SPIFFE/SPIRE, SCIM, and NGAC among the standards that will shape the space. And regulatory alignment is a moving target, with guidance fragmenting across governments and agencies, from Australia’s Agentic AI Addendum to the NIST AI Agent Standards Initiative.

The through-line is consistent: registration and control belong together. In the report’s own image, agents may soon have to register at the front desk, but watching what they do inside the building matters just as much.

The Takeaway

The value of ABI’s analysis is not the compliment. It is the diagnosis. The agentic security conversation is racing toward inventory, and inventory alone will not govern software that acts on its own. The controls that decide what an agent can decrypt, sign, or execute have to live below the model, anchored in hardware, and bound to a verified identity and scope.

That is the problem GaraTrust’s agentic security pillar is built to address. If you are working through how to govern AI agents in your own environment, read the full ABI Research report.

Share this post with your network.

LinkedIn
Reddit
Email