
The Hashgraph Group (THG) has announced a global partnership with IBM that brings its IDTrust self-sovereign identity platform into the IBM Cloud ecosystem, giving enterprises access to identity infrastructure designed for humans, devices and AI agents.
THG said on September 23, 2026, that IDTrust had been validated and officially listed on the IBM Cloud Catalog. The product is listed by IBM as a third-party offering from The Hashgraph Group under the Blockchain category.
THG said the listing puts verifiable AI-agent identity infrastructure in front of IBM’s enterprise customer base. The company also described IDTrust as one of the first commercial Hedera-powered enterprise applications to become directly purchasable as a software-as-a-service product through a major cloud marketplace, although that characterization comes from THG.
The IBM Cloud listing itself predates the public announcement. IBM’s catalog records show IDTrust with a last-update date of June 25, 2026, confirming that the product was already present in the marketplace before THG announced the wider partnership.
THG has also qualified for IBM Silver Partner status. IBM’s Partner Directory identifies The Hashgraph Group AG as an IBM partner, classifies it as an Independent Software Vendor and Managed Service Provider, and lists IDTrust among its solutions.
Alongside the marketplace listing, THG said it signed a global Embedded Solution Agreement with IBM covering cloud and AI technology. According to THG, the agreement allows technology partners to integrate IBM technology into their own proprietary products and sell a combined solution.
The announcement arrives as enterprises begin dealing with a security problem created by increasingly autonomous software. AI agents can access applications, invoke tools, process information and perform actions on behalf of users or organisations, creating a need to establish which agent acted, who authorised it and what permissions it received.
IBM made a similar case two days earlier. On September 21, the company announced the private preview of Agent Identity in IBM watsonx Orchestrate, describing a model in which an AI agent receives a distinct identity separate from its creator, owner or end user. IBM said its approach is intended to improve traceability, authorisation control and least-privileged access.
IBM’s system connects watsonx Orchestrate with enterprise identity providers such as IBM Verify and Microsoft Entra. The company says an agent can receive a short-lived token scoped to a particular task, while audit records can preserve both the user on whose behalf an action was performed and the agent that executed it.
IDTrust takes a different technical route. THG describes the platform as a self-sovereign identity system built around decentralised identifiers and verifiable credentials, with identity and credential activity anchored to Hedera.
According to THG, IDTrust gives AI agents, devices and humans decentralised identifiers known as did:hedera identifiers. The platform also supports verifiable credentials based on open standards and is designed to provide cryptographically verifiable identity without requiring every verification request to return to a central authority.
The W3C DID Methods registry, published as a September 2026 Group Note, includes hedera among the known DID methods. The registry also makes clear that inclusion is not an endorsement of a particular DID method or its underlying technology.
THG says IDTrust is built around W3C Verifiable Credentials, W3C DIDs, OpenID for Verifiable Credential Issuance 1.0 and OpenID for Verifiable Presentations 1.0. The company also describes the platform as designed to support the EU eIDAS 2.0 framework and to have a path towards post-quantum security as relevant standards mature.
The platform’s AI-agent component includes MCP servers. THG said those servers allow AI agents connected to IBM watsonx Orchestrate to obtain identity credentials, with the goal of making authorisations and actions taken by agents auditable.
THG says every agent deployed through IDTrust receives its own did:hedera identifier, while agent credentials can be approved or revoked through its management portal or mobile application. The company’s product documentation also describes a registry of agent DIDs and an audit trail for agent activity.
Hedera’s role is primarily as a trust and consensus layer rather than a database for storing an organisation’s underlying identity documents. Hedera describes its Consensus Service as a mechanism for creating verifiable, immutable timestamps and ordering events. Its decentralized identity documentation says the service can be used for identity-event logging while personal data remains outside the ledger.
Hedera’s own earlier documentation on decentralized identity makes the same distinction. It says identity artifacts can move through the Hedera Consensus Service while the underlying artifacts themselves are not persisted on Hedera’s network nodes.
THG’s current IDTrust documentation says every actor receives a unique did:hedera identifier registered on the Hedera Consensus Service, while credentials are cryptographically signed and recorded in an audit trail.
The approach is intended to separate four parts of an agent transaction: the person requesting an action, the AI agent executing it, the authorisation granted to the agent and the downstream resource being accessed. That distinction is also central to IBM’s own Agent Identity architecture.
IBM says shared service accounts, static API keys and the reuse of user credentials can make it difficult to determine whether a user or agent performed an action. The company identifies three associated problems: limited traceability, overprivileged access and limited control over which agents can act for which users and under what conditions.
THG launched IDTrust in August 2025. At that time, the platform was positioned as an enterprise self-sovereign identity system for individuals, organisations and governments, with planned applications including banking, healthcare, employee authentication, education credentials, government services and digital product passports.
The platform has since expanded to cover machine and AI-agent identities. THG now markets IDTrust for telecommunications, education, financial services, healthcare, IoT and autonomous AI-agent deployments.
THG said IDTrust is already deployed with a leading European telecommunications operator for verified caller identity. The company’s current product materials describe a Verified Caller ID use case in which subscribers can verify the legitimacy of outbound calls.
THG’s product documentation also lists reusable know-your-customer credentials for telecommunications, diploma and student identity credentials for education, reusable know-your-business credentials for financial services, selective disclosure of medical information in healthcare and automated identity credentials for connected devices.
The wider market is moving toward more autonomous enterprise software. Gartner said in August 2025 that 40% of enterprise applications would feature task-specific AI agents by the end of 2026, up from less than 5% in 2025. Gartner also projected that by 2027 one-third of agentic AI implementations would combine agents with different skills, while by 2028 AI-agent ecosystems would be able to collaborate across applications and business functions.
Gartner separately said in May 2026 that 40% of enterprises could demote or decommission autonomous AI agents by 2027 because of governance failures identified after production incidents. The research organisation said failures are particularly associated with treating an agent’s ability to act and the scope of access it receives as the same thing.
Those developments help explain the attention being placed on what THG calls “Know Your Agent”, or KYA. The concept applies familiar identity and access questions to software agents: which agent is acting, who authorised it, what it is permitted to access and whether its activity can later be traced.
THG’s IBM announcement also points to the companies’ existing relationship with the Hedera network. IBM has been a member of the Hedera Governing Council since 2019. THG said the new marketplace relationship gives IBM customers a route to Hedera-anchored identity infrastructure through IBM’s enterprise procurement ecosystem.
IBM’s Partner Directory identifies IDTrust as a third-party solution provided by The Hashgraph Group. The directory describes it as a secure self-sovereign identity platform for AI agents, smart devices and humans, and highlights features including credential interoperability, revocation registries anchored on Hedera and agent governance.
The IBM directory also displays claims associated with IDTrust that include a 90% faster credential-verification procedure, an 85% reduction in identity-related security incidents and a return on investment within six months. IBM states on the same directory that information about listed companies and solutions is provided by the companies and is not validated by IBM unless otherwise noted. Those figures therefore remain company-provided claims rather than independently verified IBM performance measurements.
There is also a compliance distinction that enterprises will need to consider. IDTrust’s product materials describe support for standards and frameworks associated with eIDAS 2.0 and the EU AI Act, but that does not by itself establish that every deployment is legally compliant with those regimes.
THG’s own service documentation places responsibility for identity verification and regulatory obligations on the customer. The platform provider describes itself as technical infrastructure rather than the identity issuer, verifier, trust registry, certification authority or qualified trust service provider responsible for making those legal determinations.
That division is significant. A cryptographic credential can prove that a credential was issued by a particular issuer and that its integrity has not been altered. It does not independently establish that the original identity check was correct or that an organisation’s use of the credential satisfies every applicable regulatory requirement.
The commercial model is also enterprise-focused. Gartner Peer Insights lists IDTrust with enterprise-based custom pricing and currently shows no customer reviews. THG’s service documentation describes contracts that can include implementation, professional services, recurring charges and usage-related fees, with initial 12-month terms and automatic annual renewal unless terminated under the agreement.
THG said the IBM partnership follows other enterprise projects during the past year, including work with Merck Group on digital product passports, a strategic partnership with PwC around carbon-market infrastructure and a collaboration with Teleport on an AI-driven Digital Customs Documentation System for cross-border e-commerce in Southeast Asia. THG said those projects use products from its Hashgraph for Enterprise suite.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.



