AUTO-UPDATED

Who's governing your AI? A trust framework for enterprise agents and models

The rapid proliferation of autonomous AI agents in enterprise environments creates significant security risks, prompting industry leaders like DigiCert to advocate for robust, identity-based governance and cryptographic verification frameworks.

Key Points

  • IBM’s 2026 report indicates that 68% of organizations currently lack the necessary governance to manage AI agents or detect shadow AI deployments.
  • DigiCert’s AI Trust framework utilizes public key infrastructure, DNS, and workload identity standards to monitor agent activity and enforce security policies.
  • Industry experts recommend treating AI agents as workload identities rather than human users, aligning with IETF WIMSE and NIST Cybersecurity Framework 2.0 standards.
  • The framework employs "AI Agent Passports" to cryptographically link agent identities to authorized operations, data sensitivity levels, and accountable human owners.
  • Trusted execution environments, such as Intel TDX or AMD SEV-SNP, are used to maintain model integrity and ensure secure, isolated runtime processing.

Why it Matters

Organizations are currently repeating historical cybersecurity mistakes by prioritizing rapid AI adoption over essential security controls, leaving sensitive infrastructure vulnerable to autonomous agents. Implementing verifiable governance now allows enterprises to mitigate data exfiltration risks and meet regulatory compliance requirements before agentic AI becomes an unmanageable cost and security burden.
Theregister.com Published by Robin Birtstone
Read original