Lakshmi Hanspal at DigiCert explains the importance of layering trust into AI-generation as a part of winning the war on deepfakes
AI is moving quickly into core business processes, while the controls needed to establish trust are struggling to keep pace. As organisations use AI to create content, inform decisions and increasingly take actions on their behalf, identity, authenticity and accountability have direct consequences for fraud, data protection, operational resilience and reputation.
In my own experience leading security for <a href="https://myappsplus.com/amazon-deal-makes-the-razer-kishi-v3-pro-xl-easier-to-grab-at-159-99/” title=”Amazon deal makes the Razer Kishi V3 Pro XL easier to grab at $159.99″>Amazon Devices and Services, and now as Chief Trust Officer at DigiCert, the pattern is consistent: the moment a system can act on our behalf, it needs a verifiable identity of its own, or it becomes a target-rich environment.
Consider a finance team receiving an urgent video message that appears to come from the chief executive while AI agents elsewhere in the business have permission to interact with procurement or financial systems. The risks are different, but both depend on the same weakness: the business may be asked to act without sufficient evidence that the person, content or machine is genuine and authorised.
DigiCert’s 2026 AI Trust Outlook suggests this is already more than a theoretical concern, with 78% of organisations reporting an AI-related security incident or identified vulnerability. Detection, employee awareness and fraud monitoring remain important, but they cannot address the problem alone. As synthetic media becomes more convincing and AI gains greater autonomy, businesses also need ways to make legitimate content and machine activity independently verifiable.
Proving what is authentic
Deepfakes expose an uncomfortable gap in the way organisations communicate digitally. Companies can invest heavily in protecting their systems and executive identities while giving customers, employees and business partners relatively few ways to verify whether a video, image or other digital asset genuinely came from them.
A simple distinction between “real” and “AI-generated” is increasingly unhelpful because AI is already part of legitimate business and creative processes. AI-generated material produced and approved by a company can be authentic, just as genuine content can be manipulated or misattributed. Establishing where something came from and what has happened to it since is much more useful.
Cryptographic provenance can provide that evidence, recording the origin of content and whether it has subsequently been altered. Open standards such as the Coalition for Content Provenance and Authenticity (C2PA) allow that evidence to remain useful as content moves between applications, organisations and platforms. Establishing provenance close to the point of creation, particularly when it can be linked to a verified device or trusted system, gives businesses a stronger basis for demonstrating authenticity than trying to reconstruct it once material is already circulating.
This does not mean provenance can determine whether a statement is factually correct or prevent authentic material being presented out of context. Its value is more specific: establishing origin and integrity so that people do not have to rely solely on appearance when deciding whether content is genuine.
Giving AI agents an identity and boundaries
As AI moves from creating content to taking action, the same underlying issue becomes more consequential. Agents can retrieve information, communicate with applications and perform tasks on behalf of employees, with potentially significant productivity benefits. Greater autonomy also means greater delegated authority, making it important to understand what an agent is, what it can access and who remains accountable for its behaviour.
Security teams have already been through a similar change in thinking with zero trust, moving away from the assumption that a user or device is trustworthy simply because it sits inside the corporate network. An AI agent should not receive broad trust simply because the organisation deployed it or because it possesses a valid credential. Its identity needs to be tied to clearly defined authority. Organisations need to think of this as securing for identity and intent, not identity and access alone; an agent can hold a perfectly valid credential and still act outside the intent its owner authorised. This is precisely the scenario I ask security leaders to war-game before they scale agentic deployments.
Thinking of an agent as having a digital passport makes this easier to visualise. A passport establishes identity without granting unrestricted access, and an AI agent similarly needs a verifiable identity with boundaries around the systems, information and actions available to it. Those permissions should change, expire or be revoked as its role and the associated risk change. When I sit down with a customer’s security team, the first question I ask is whether they can name every agent operating in their environment, identify who owns it, and state exactly what it is permitted to touch. Too often the honest answer is no, and that is how risk quietly accumulates.
Human accountability also needs to survive the move towards greater autonomy. Organisations should know who owns an agent and be able to reconstruct what it did and under whose authority, yet our research found that only 53% can fully trace AI decisions back to the models and source data that produced them. That becomes a more serious gap when an AI system moves from recommending an action to executing it. It’s a trust gap as much as a technical one. An organisation that cannot reconstruct why an agent acted will struggle to defend that decision to a regulator, auditor or customer, however sound its original intentions were.
Keeping control of data
For European businesses, agent governance also intersects with sovereignty. Models and agents can depend on cloud services, APIs and datasets spread across different providers and jurisdictions, so a seemingly simple task may involve sensitive information travelling through a complicated chain of infrastructure.
Where a database is hosted is only part of that picture. Businesses need to understand where information is processed, which external services their agents can communicate with and whether those interactions remain within corporate policies and regulatory obligations. Better visibility into those dependencies also makes it easier to respond to regulatory change, move workloads between providers and give customers confidence about how their information is handled.
As AI becomes more autonomous, sovereignty therefore becomes less about a single infrastructure decision and more about maintaining control as identity, data and actions move across a transaction.
Turning trust into business value
Closing the AI trust gap has an obvious defensive value. Executive impersonation can enable fraud and damage reputation, while an overprivileged or compromised agent could expose sensitive information or make unauthorised changes at machine speed. But treating this solely as another security problem misses why trust matters to AI adoption itself.
Businesses are unlikely to give AI access to their most valuable data and processes if they cannot establish what is acting, limit its authority and investigate what happened afterwards. Confining AI to low-risk activities may reduce exposure, but it also limits the productivity and commercial value organisations hope to achieve.
This is the shift I encourage boards to make. Instead of a fear-based posture that treats AI purely as a risk to contain, they need to adopt a trust-based one where verified identity and provenance let the business extend AI further, with evidence to back the decision rather than just permission to try.
Identity, provenance, authorisation and accountability give businesses greater confidence to extend AI into more valuable processes without surrendering control. The enterprise AI trust gap is the distance between what organisations want AI to do and their ability to verify and govern those activities. Closing it will determine how much responsibility businesses can realistically give AI while protecting the customers, data, operations and reputation on which its value ultimately depends.
Instead of a checkbox before deployment, trust must be treated as the infrastructure that lets you deploy AI at all.
Lakshmi Hanspal is Chief Trust Officer at DigiCert
Main image courtesy of iStockPhoto.com and MF3d
