{
  "id": 7573886,
  "title": "Who's governing your AI? A trust framework for enterprise agents and models",
  "url": "https://urgent.news/2026/09/15/whos-governing-your-ai-a-trust-framework-for-enterprise-agents-and",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-15T15:00:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/15/sponsored-whos-governing-your-ai-a-trust-framework-for-enterprise-agents-and-models/5294237"
  },
  "original_language": "en",
  "account": "Rapid advancements in artificial intelligence have brought about a burgeoning issue known as shadow AI, where organizations deploy AI agents without proper governance. These autonomous, non-deterministic agents can creatively solve tasks but also pose significant security risks, such as executing unauthorized actions or spreading to sub-agents. According to IBM's 2026 Cost of a Data Breach report, 68% of organizations lacked governance to manage AI or detect shadow AI, up from 63% the previous year. Additionally, just 38% of organizations required IT approval to deploy AI compared to 45% in the prior year.\n\nTo tackle this challenge, DigiCert has developed an AI Trust framework that utilizes public key infrastructure, DNS, and attestation to address key governance questions for enterprises. The framework aims to answer five critical questions:\n\n1. What agents are your employees using?\n2. What regulated data is flowing to them?\n3. Whose credentials do they hold?\n4. Can a compromised agent be stopped immediately?\n5. Can an incident be reconstructed with a tamper-evident trail?\n\nOne of the primary hurdles organizations face is the lack of visibility into the agents they deploy. Developers often build or acquire agents internally without notifying higher-ups, and these agents might spawn sub-agents with reduced permissions. To address this, DigiCert recommends treating agent identity as a separate workload identity problem rather than an extension of human IAM. This approach aligns with industry recommendations from IDC and NIST, advocating for runtime attestation and short-lived credentials.\n\nDigiCert's AI Trust framework employs DNS as a governance tool for agentic AI, leveraging the DMARC standard to verify agent legitimacy. By publishing an agent policy record in DNS, organizations can ensure that only authorized agents are granted access. This DNS-based verification can also block unauthorized communication between agents, providing a tamper-evident trail for incident reconstruction.",
  "summary": "SPONSORED FEATURE: DigiCert wants to hand every agent a passport, complete with an expiry date and a named human owner",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Who's governing your AI? A trust framework for enterprise agents and models",
        "url": "https://urgent.news/2026/09/15/whos-governing-your-ai-a-trust-framework-for-enterprise-agents-and-7576546",
        "published": "2026-09-15T15:00:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}