As autonomous artificial intelligence (AI) systems increasingly assume roles in financial, legal, and operational decision-making, corporate leaders face mounting pressure to adapt governance frameworks to address these new challenges. Traditional risk management models, predicated on predictable software behavior and human oversight, are proving inadequate for managing independent AI agents that operate at machine speed across organisational borders, experts say.

Paul Holt, group vice-president of EMEA at digital trust firm DigiCert, highlights that while most existing corporate risk frameworks expect software to follow explicit instructions, autonomous AI systems can interpret high-level goals, make decisions, and act independently, complicating accountability. Research indicates that 89% of C-suite executives feel unprepared for enterprise-level AI deployment, and only about half of organisations can trace AI-derived decisions back to their underlying models and data sources.

This lack of transparency creates significant governance challenges. For effective oversight, Holt argues that every autonomous agent must have a unique digital identity—akin to a "digital passport"—that establishes verifiable proof of who or what it represents, what permissions it holds, and whether those permissions remain valid. Without such cryptographically verifiable identities tied to specific human owners, organisations struggle to track AI behaviors, enforce trust boundaries, or revoke access when necessary.

Compounding these issues is the proliferation of shadow AI—unofficial AI tools adopted by employees outside formal IT controls, often in departments like marketing, finance, and operations. This widespread, sometimes hidden usage undermines security and governance, as organisations often lack visibility into these agents’ presence and activities. Holt emphasizes that discovery—identifying which AI agents are active, who deployed them, and what resources they access—is a crucial initial step toward robust governance.

Beyond internal tools, increased reliance on external AI models introduces supply chain risks that boards are urged to treat with the same diligence applied to other critical software components. Practices such as maintaining model bills of materials, applying hashing, and cryptographic signing help ensure model integrity throughout distribution and deployment. This forensic “chain of evidence” approach aims to detect tampering and verify provenance, especially important in preventing financial or contractual errors stemming from AI-driven actions.

Legal and reputational accountability remains the responsibility of the organisation—not the algorithms—underscoring the need for operational limits, human approval checkpoints, and tamper-evident audit trails. The use of cryptographic identities linked to individuals provides evidentiary clarity for investigations and regulatory scrutiny. Similarly, with the rise of generative AI, traditional watermarking methods to certify authentic digital content are increasingly insufficient. Instead, approaches like cryptographic content credentials enable verification of content history and manipulation detection, helping protect brand integrity.

The regulatory environment is evolving rapidly, with the European Union’s AI Act mandating strict compliance audits for high-risk AI applications. Despite ongoing executive-level discussions about AI governance in approximately 90% of businesses, formalised programmes have only been implemented in about half. Experts contend that closing this gap requires infrastructure capable of enforcing controls at machine speed.

Holt suggests leveraging domain name system (DNS) technology combined with cryptographically verified agent identities as an effective control point—since AI agents must resolve DNS to access services and data, this can serve as an enforcement checkpoint without requiring bespoke solutions from every application team.

Looking forward, organisations must also prepare for the implications of quantum computing, which threatens to undermine existing encryption standards used to secure AI agent identities and model signatures. Executives are advised to inventory cryptographic assets, adopt post-quantum algorithms, and build crypto-agile systems that can transition smoothly to quantum-resistant standards.

For chief information security officers, the challenge extends to communicating these technical issues to boards in business-relevant terms. Key performance indicators such as agent discovery rates, identity coverage, policy exceptions, revocation latency, and decision traceability provide actionable metrics linking AI governance to risk reduction, regulatory compliance, and operational resilience.

Failing to implement cryptographically verifiable AI governance can lead to substantial financial repercussions, including fraud, legal costs, and lost innovation opportunities when boards impose overly cautious restrictions. Industry observers predict that within the next three years, AI security will be fully integrated into enterprise risk management frameworks, merging with legal, compliance, procurement, and operations functions. Organisations that act proactively to establish verifiable trust frameworks for autonomous agents are likely to gain the confidence needed to scale AI safely and effectively.