Two announcements, one day, the same message
On 27 July more than thirty vendors put the core agent security controls into open source under the Linux Foundation, and the workload identity piece of that package was SPIFFE and SPIRE. Adopting the standard that decides what an AI agent is allowed to be became free that morning. By the afternoon, Keyfactor had announced its intent to acquire Cofide, a British company built on exactly those standards, whose entire team is six people. Financial terms were not disclosed and the team and technology join immediately.
Why it matters: the two events look contradictory and are not. One made the specification a public good. The other put a price on the ability to run it. Read together on the same day, they answer a question owners have been asking since agents started appearing in production estates: if the control is standardising, does the problem go away? It does not. It changes which budget line it lands on.
What Cofide actually does
Cofide describes itself as an open-standards identity platform that secures application workloads and AI agents across any cloud environment. In practice it replaces static secrets, meaning the long-lived API keys, tokens and service-account credentials that accumulate in every estate, with short-lived cryptographic identities the workload carries automatically. It builds on SPIFFE and SPIRE for identity issuance, and on OAuth and OIDC for credential exchange. For agents specifically it issues a verified agent identity while preserving the user identity through token exchange across service boundaries.
The part that matters for agents: an AI agent acts on its own initiative, calls external APIs and routinely crosses trust boundaries. A static credential cannot express who asked for the action, only which key was used. Separating the agent's own identity from the delegated authority of the person it acts for is the difference between an audit trail that names a human and one that names a shared secret.
Free to adopt is not free to run
Keyfactor's chief product and technology officer, Gün Akkor, gave the clearest statement of the thesis in the announcement: customers stall on securing their workloads because it is operationally hard, not because the technology falls short. That is a vendor describing its own market honestly, and it happens to be the correct reading of both of the day's announcements. The specification was never the bottleneck. Issuing an identity to every workload, rotating it on a short clock, revoking it when the workload dies and producing evidence that all of this happened is the bottleneck.
The consequence for a budget: when a control becomes an open standard, the licence cost falls toward zero and the operating cost does not move at all. A team that reads a free standard as a free control will fund the pilot and not the run. The vendors are buying the run, because the run is where the durable revenue is, and they are buying it from people who have already done it rather than building it.
Twenty-one days after a billion dollars
Keyfactor took more than a billion dollars from Summit Partners on 6 July. Twenty-one days later, the first visible thing it did with a balance sheet that size was to buy a company with six employees. That is worth sitting with. Nothing about a six-person team implies scarce code; implementations of an open specification are not scarce by definition. What is scarce is the number of people who have operated workload identity in a production estate and know where it breaks.
Yes, but: an acquisition this small is also cheap optionality for an acquirer of Keyfactor's size, and it would be wrong to read it as a considered verdict on the market. The founder, Matthew Bates, previously co-founded Jetstack, which Venafi acquired in March 2020, so this is a second exit in the same layer by the same person. The pattern to note is not the price. It is that machine-identity capability keeps being absorbed into a small number of certificate vendors rather than growing into independent companies.
What to put in next year's budget
Three lines, in this order. First, an inventory: how many non-human identities exist in your estate, how many hold standing credentials, and how many have not been reviewed in the last year. You cannot fund a rotation programme against a number you do not have. Second, the run cost: someone owns issuance, rotation and revocation as a named responsibility, and if that is nobody today it will be nobody after the pilot too. Third, the evidence: NIS2 expects documented access control and vulnerability handling, and short-lived identity produces that record continuously while static secrets produce none.
The bottom line: the standard going open removed your excuse for waiting, not your obligation to resource it. If an auditor asks in twelve months how an agent in your estate proved who it was, the answer will come from whatever you funded this year. A specification that costs nothing to adopt is not the same as a control that costs nothing to hold.
Read next: A Single Message Reached the Host's SSH Keys | An AI Escaped Its Sandbox to Cheat on a Test



