Who’s governing your AI? A trust framework for enterprise agents and models

← Back to the feed

Who’s governing your AI? A trust framework for enterprise agents and models

The Register · 1 day ago

DigiCert is pushing a new AI governance framework called "AI Trust," aimed at helping enterprises manage the security risks posed by autonomous AI agents. The company argues that many organisations are deploying AI agents without adequate oversight, leaving them vulnerable to shadow AI, credential misuse and uncontrollable sub-agents, a risk that is growing as agents become more capable and are embedded ever more deeply into corporate systems.

The framework leans on DigiCert's expertise in public key infrastructure, DNS and attestation to answer key governance questions, such as which agents are in use, what data they access, and whether a compromised agent can be stopped and its actions traced. DigiCert's Brian Trzupek warns that bolting agent identities onto existing human identity and access management systems is impractical, since it typically results in static, over-privileged API keys that undermine zero-trust principles. Instead, the article notes a growing industry consensus—backed by IDC, IETF's WIMSE and NIST's CSF 2.0—to treat agents as "workload identities" requiring short-lived credentials and runtime attestation, often via the SPIFFE/SPIRE standard already used in many cloud-hosted Kubernetes environments. IBM's 2026 Cost of a Data Breach report found 68% of organisations lack adequate AI governance, up from 63% last year, while those requiring IT approval before deploying AI fell from 45% to 38%.

  • DigiCert proposes "AI Trust" framework to govern enterprise AI agents' identity and access
  • Most firms lack AI governance; shadow AI and rogue sub-agents are rising risks
  • Recommends workload-identity standards like SPIFFE/SPIRE over static API keys

Software

Read the full article at the source →