Meet our experts at Ping YOUniverse in Austin, TX | September 1-2, 2026

Blog

Identity: The Foundation of the Connected, Autonomous Vehicle

3. August 2026
Identity Security
Chris Kerr

The car is becoming a computer on wheels. As vehicles become connected, software-defined and autonomous, identity is what everything else runs on: the layer that decides which components, services, drivers and back ends can be trusted before anything moves.

For decades, automotive security focused on the physical: the key, the immobilizer, the locked door. That world is gone. A modern vehicle is a distributed system of more than 150 electronic control units, sensors, artificial intelligence systems and cloud services, all talking to each other and to the outside world. Each of those participants needs a verifiable identity, and each of those identities needs to be governed for the life of the vehicle.

This article looks at why identity has moved from a background IT concern to the foundation of connected vehicle security, what regulation now demands, and the six practical steps every manufacturer should take to build identity resilience before an incident rather than during one.

Why Identity Is the Foundation of Automotive Cybersecurity

Four shifts are turning identity into the operating base of the automotive industry. Together they explain why carmakers can no longer treat it as an afterthought.

Every Component Has an Identity: Machine Identity and PKI at Vehicle Scale

Software defined and autonomous vehicles multiply the machine identities that must be trusted. More than 150 control units, sensors, AI systems and services each need a credential that proves what they are, what they are not, and what they are allowed to do. In practice this means running a public key infrastructure (PKI) at a scale most industries never encounter, across the vehicle, the factory and the cloud.

Trust Is the Currency of Autonomy: Why Connected Vehicle Security Depends on V2X

Before acting on a safety message, a vehicle verifies that the other vehicle, the roadside infrastructure or the cloud sending it is genuine. This matters because connected vehicles constantly broadcast information that others act on, such as a hard braking warning, a stalled car ahead or a signal about to change. If a vehicle trusted every message it received, an attacker could spoof a fake hazard and force cars to brake in traffic. This is vehicle to everything (V2X) communication, and it only works if every party can prove who it is in milliseconds. It is Zero Trust applied to the road: never assume, always verify, and grant only the access each interaction requires.

The Driver Becomes a Customer

Connected services, in car payments, personalisation and data privacy put customer identity and access management (CIAM) at the centre of the experience. The person behind the wheel is now an account holder with a profile, preferences, payment details and privacy rights. Getting that identity experience right is a direct driver of brand loyalty and recurring revenue.

Software Never Stops Changing: Securing the Automotive Software Supply Chain

Continuous over the air updates depend on a trusted identity and signing chain that reaches across the original equipment manufacturer (OEM) and its entire supply chain. If an attacker can impersonate a signing service, they can ship code to millions of vehicles. The integrity of that chain is only as strong as the identities that hold its keys.

From IT Concern to Safety and Legal Imperative: What UNECE R155 and R156 Require

When the vehicle is in control, software integrity and identity integrity stop being questions of convenience. They become questions of safety, liability and law.

Safety is security. In an autonomous vehicle, a compromised identity or a tampered update can put lives at risk. Identity integrity is now safety critical, not just an IT matter, and it has to be engineered to that standard.

Regulation is already here. UNECE R155 and R156 make cybersecurity management and secure software update processes a condition of type approval, so a vehicle cannot reach the market without them. In the United Kingdom, the Automated Vehicles Act 2024 is expected to shift liability towards manufacturers and authorised self driving entities as the regime comes into force. Identity evidence is central to meeting both.

The United Kingdom is not alone. Every major automotive region is building a legal framework for the connected, autonomous vehicle, and the cybersecurity and software update obligations run through all of them.

RegionKey frameworkFocus
United KingdomAutomated Vehicles Act 2024Shifts liability towards manufacturers and authorised self driving entities as the regime comes into force
European UnionRegulation (EU) 2022/1426 and Product Liability Directive (EU) 2024/2853Type approval for automated driving systems, plus strict liability extended to software, over the air updates and AI (to be transposed by December 2026)
GermanyAutonomous Driving Act 2021 (amending the Road Traffic Act)Allows Level 4 vehicles in defined areas, with combined driver, keeper and manufacturer liability and a technical supervisor role
United StatesNHTSA oversight plus state level lawsNo single federal act; a patchwork across states such as California, Arizona and Texas
JapanAmended Road Traffic and Road Transport Vehicle ActsPermits Level 3 and Level 4 driving, with a strong emphasis on remote monitoring
Common threadUNECE R155 and R156Cybersecurity management and secure software updates as a condition of type approval across UNECE signatories, the obligations most directly tied to identity

The scale is unprecedented. Manufacturers are managing millions of vehicles and billions of identities, both human and machine, all of which need to be verified, governed and, when necessary, revoked. Approaches that work for a workforce of thousands do not survive contact with a fleet of millions.

Build it in, do not bolt it on. The winners will treat identity as foundational infrastructure, designed in from the first architecture decision rather than added under pressure after launch. Retrofitting trust into a system that was never built for it is slow, costly and rarely complete.

 

Identity is all we do

For more than 25 years, iC Consult has secured digital identity for the world's leading carmakers, always vendor-independent, across workforce, customers, machines and the back ends that connect them. We are trusted by the majority of Germany's major car manufacturers, alongside global OEMs and suppliers, including in the United Kingdom.

Six Steps to Build Identity Resilience

Resilience is what enables a manufacturer to keep operating and quickly recover trust when its identity is attacked. These are the six moves every manufacturer should make before an incident, not during one.

1

Treat identity as critical infrastructure

It underpins manufacturing, the supply chain and customers alike, so it deserves the same protection as any production line. Start by giving identity its own risk register and budget line, not a subsection of the general IT security plan.

2

Recognise that recovery is not the same as backup

Assume you will have to rebuild trust from the ground up, and test that you actually can, rather than trusting that a backup will be enough. Run a tabletop exercise that assumes your identity backups are also compromised, and see how long a full rebuild actually takes.

3

Assume privileged access will be targeted

Know and protect your most critical Tier 0 systems before someone else finds them first. Start with an inventory: list every system that can sign software or issue certificates, and check who and what can reach it today.

4

Run identity resilience as an operation, not a project

Monitoring and recovery readiness are ongoing commitments, not a task that is ever finished. Assign it a named owner and a recurring review cadence, the same way you would a safety-critical process.

5

Verify before you trust

Strong identity verification limits the blast radius when something does go wrong. Apply this to every machine and AI identity in the vehicle and the factory, not just human logins.

6

Plan recovery before the incident

The time to design and rehearse your recovery is now, not in the middle of a crisis. Schedule the first recovery rehearsal this quarter, before it becomes urgent.

Mapping the Vehicle to Identity Disciplines

Treating each participant in the vehicle as a governed identity turns an abstract principle into concrete controls. The table below shows how the core identity disciplines apply across the connected vehicle.

Identity disciplineAutomotive exampleWhat it protects
Machine identity and PKICertificates for control units, sensors and V2X messagingOnly genuine components and vehicles can join the conversation and act
Customer identity (CIAM)Driver accounts, in car payments and connected servicesA secure, private and personalised experience that builds loyalty
Privileged access management (PAM)Access to signing services and factory Tier 0 systemsThe keys that sign software and run production stay in the right hands
Identity governance (IGA)Workforce and supplier access across the OEM and its supplier networkThe right people and partners hold the right access, and lose it on time
Non-Human Identity Governance (NHIG)AI driving agents, vehicle software services, APIs, robotics and digital manufacturing systemsEnsures AI systems and other non-human identities are authenticated, governed and accountable, preventing unauthorised actions while maintaining trust in autonomous operations
Secure software supply chainSigning and identity chain for over the air updatesEvery update shipped to the fleet is authentic and untampered

AI Turns Non-Human Identity Governance into a Priority

Artificial intelligence changes what an identity is. The vehicle no longer just runs code, it runs agents that perceive, decide and act, from the AI systems that steer and brake to the software services, APIs, robotics and digital manufacturing systems behind them. Each of these is a non-human identity that can take consequential action, so each needs to be authenticated and governed as rigorously as any human user.

This is where non-human identity governance (NHIG) becomes central. Every AI agent and machine identity should have a verifiable credential, a clearly defined scope of what it is allowed to do, and an audit trail that keeps it accountable. For security and AI governance leaders working towards the EU AI Act, NIST AI RMF or ISO 42001, that audit trail is not optional, it is the evidence regulators and customers will ask for.

Governed well, non-human identities let autonomous systems act with confidence. Left ungoverned, they become the fastest-growing and least visible attack surface in the vehicle. Treating AI as a first-class, governed identity is what keeps autonomous operations trustworthy as the number of these agents grows.

How iC Consult Can Help

Securing the connected, autonomous vehicle is not only a technology problem. It takes the right strategy, deep identity expertise, and the ability to operate at automotive scale. That is what iC Consult brings.

As the world’s largest vendor-independent provider of identity and access management and identity security services, we help automotive organisations:

  • Design identity in from the start, so machine, customer, workforce and supplier identities are part of the vehicle and platform architecture rather than a later addition.
  • Operate PKI and machine identity at scale, issuing, rotating and revoking the credentials that billions of components and V2X interactions depend on.
  • Secure the software supply chain and over-the-air updates, protecting the signing and identity chain across the OEM and its suppliers.
  • Build privileged access and identity resilience, protecting Tier 0 systems and rehearsing recovery, so trust can be restored fast after an incident.
  • Meet regulatory expectations, aligning identity controls and evidence with UNECE R155 and R156 and the emerging automated vehicle liability regimes.


With more than 850 identity experts worldwide, over 25 years of experience and the trust of the world’s leading carmakers, we help you make identity the dependable foundation of everything the vehicle does.

Ready to see where your identity resilience stands? Talk to our identity security experts →

Ready to turn insight into action? Let’s talk about your identity strategy.

Content

Chris Kerr

Related Blog Articles

Explore other Categories