The rapid proliferation of autonomous AI agents in enterprise environments creates significant security risks, prompting industry leaders like DigiCert to advocate for robust, identity-based governance and cryptographic verification frameworks.
Key Points
- IBM’s 2026 report indicates that 68% of organizations currently lack the necessary governance to manage AI agents or detect shadow AI deployments.
- DigiCert’s AI Trust framework utilizes public key infrastructure, DNS, and workload identity standards to monitor agent activity and enforce security policies.
- Industry experts recommend treating AI agents as workload identities rather than human users, aligning with IETF WIMSE and NIST Cybersecurity Framework 2.0 standards.
- The framework employs "AI Agent Passports" to cryptographically link agent identities to authorized operations, data sensitivity levels, and accountable human owners.
- Trusted execution environments, such as Intel TDX or AMD SEV-SNP, are used to maintain model integrity and ensure secure, isolated runtime processing.