Who's governing your AI? A trust framework for enterprise agents and models
- ID
- 24699
- Status
- summarized
- Published
- 15 Sep 2026, 11:00 PM
- Fetched
- 15 Sep 2026, 11:32 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/15/sponsored-whos-governing-your-ai-a-trust-framework-for-enterprise-agents-and-models/5294237
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 4.5
- Created
- 15 Sep 2026, 11:33 PM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
DigiCert's sponsored pitch for its AI Trust framework argues enterprises are losing visibility over AI agents, citing IBM's 2026 Cost of a Data Breach report showing 68% of organizations lack AI governance (up from 63%) and only 38% require IT approval to deploy AI (down from 45%). The framework uses PKI, DNS, and attestation to answer five governance questions: what agents employees use, what regulated data flows to them, whose credentials they hold, whether a compromised agent can be stopped immediately, and whether incidents can be reconstructed with a tamper-evident trail.
Why it matters
The practical takeaway is the sub-agent authorization gap: agents spawned inside tools like Claude Desktop or OpenAI Codex can spawn sub-agents that do NOT inherit the parent's rights, creating a delegation path that bypasses your access controls. If you are building or deploying agents, you need to instrument agent identity, credential scoping, and kill-switch capability before this becomes an incident—not after. The five governance questions are a usable checklist even if you never buy DigiCert's product.
Discussion angle
The sub-agent delegation problem is real and under-discussed: when an agent inside Claude Desktop or Codex spawns a sub-agent, whose permissions does it get? Walk through how you would scope credentials and enforce a kill switch across agent chains in your own stack.