Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Who's governing your AI? A trust framework for enterprise agents and models

The Register ·
Who's governing your AI? A trust framework for enterprise agents and models

Experienced IT leaders know that shadow IT is a persistent problem, but rapidly evolving AI and the proliferation of agents mean the potential threat - and cost - is greater than ever.

AI agents are non-deterministic, autonomous, and adaptable.

They excel at solving tasks in creative ways, often to the surprise of their creators.

We've seen agents write blogs that criticize project maintainers that refused their pull requests.

Another one hacked a McKinsey chatbot to gain read/write access without asking for permission.

And agents are getting smarter all the time.

As an industry veteran, DigiCert's senior vice president of product Brian Trzupek sees an old pattern.

"When the promise of the technology is so good, people are willing to throw security out the window, and they just want to get to that promise real fast." CISOs should be worried about allowing these agents into their infrastructure without strict controls, but it's happening anyway.

IBM's 2026 Cost of a Data Breach report found that more organizations lacked governance to manage AI or detect shadow AI, at 68 percent compared to 63 percent last year.

The number requiring IT approval to deploy AI had fallen to 38 percent from 45 percent.

DigiCert is trying to solve this problem with its own approach to AI governance called AI Trust.

The framework, outlined in this white paper, builds on what the company is good at: public key infrastructure, DNS, and attestation.

The AI governance questions CISOs should ask AI Trust uses these tools to help organizations answer five AI governance questions: · What agents your employees are using · What regulated data is flowing to them · Whose credentials they hold · Whether a compromised agent can be stopped immediately · Whether an incident can be reconstructed with a tamper-evident trail Almost every enterprise fails at the first hurdle, warns Trzupek.

Developers build agents or buy them from vendors and deploy them internally without asking.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›