
Every enterprise roadmap for 2026 seems to include the same phrase: “Deploy AI agents at scale.” It makes sense, given the potential benefits AI agents can deliver. But, many of these roadmaps aren’t asking the harder question, how do you actually trust a system that can act on its own, across your infrastructure, your partners’ systems, and your customers’ data, without a human approving each action?
That question is quickly becoming a defining constraint on agentic AI adoption. It’s not model capability or compute, but trust.
Here’s the thing — most organizations have little trouble spinning up an agent pilot in a contained sandbox with narrow scope and human oversight. Where things get tricky is when agents are moved from the sandbox into a real production environment where the agent needs to authenticate against a partner's API, initiate a transaction, modify a record in a regulated system, or coordinate with other agents it didn't build and doesn’t control.
At that point, three uncomfortable questions surface:
- Who is this agent, really? It’s not about which service account, but which human or business process is it acting on behalf of, provably?
- What is it actually allowed to do right now? Static, provisioned-once permissions don't hold up when an agent's task, context, and risk profile shift by the minute.
- Can you prove what it did, after the fact? To a regulator, an auditor, or a customer disputing a transaction, "It probably did X" is not an answer.
These aren't hypothetical concerns. Research from IBM puts numbers behind the anxiety:
- 77% of CIOs and CISOs say AI adoption is already outpacing their governance capabilities, and
- 59% name security and compliance as the top barrier to moving agents into production.
That's not a few skeptics; it’s a majority of the people accountable for enterprise risk saying the infrastructure hasn't caught up with the ambition.
Governance Is Becoming Continuous, Not a Checkpoint
Part of what makes agentic AI different from prior generations of enterprise software is that governance is not a stop along the path, but a constant requirement. A traditional application gets reviewed, approved, and deployed with fixed permission set. An autonomous agent's behavior can vary task to task, and its authority needs to be evaluated in something close to real time.
Analysts have started framing this evolution explicitly.
“As agentic AI becomes embedded in enterprise operations, governance is evolving from a point-in-time exercise to a continuous discipline. While AI agents increasingly perform tasks traditionally associated with human workers, their autonomy introduces new challenges for oversight, accountability, and risk management,” said Emanuel Figueroa, Senior Research Analyst, Identity Security, Worldwide, IDC. “Organizations, therefore, need more than static controls; they need continuous verification throughout the agent lifecycle.”
The goal isn't to lock agents down, but to be able to operate with confidence that they're authorized, governed, and staying inside defined boundaries, continuously. This matters in the trust context and is requires identity, authorization, cryptography, and audit all working together as a live system.
- Identity — Every agent action needs to trace back to a verifiable human principal and a unique agent identity, not a shared API key that a dozen processes happen to use.
- Authorization — Agents need real-time permission checks against approved policies and delegated authority, with humans kept in the loop for the decisions that warrant it, not blanket access granted once and never revisited.
- Cryptographic trust — The keys, certificates, and secrets an agent uses to authenticate and transact need lifecycle management with the same rigor applied to human credentials, if not more, given the speed and volume at which agents act.
- Accountability — Every consequential action needs a record that can hold up to a regulator or an internal risk team after the fact. This can’t be a best-effort log that might contain the relevant entry, or might not.
None if this is new; it’s more like an old challenge in a new environment that requires applying mature disciplines to a new type of actor — the autonomous agent.
Entrust’s Accelerator: Moving Towards Trust
This is where Entrust’s latest news comes in. The identity security vendor launched its Agentic AI Trust Accelerator, a co-development program built around these four pillars. Rather than shipping a single product and asking enterprises to adopt it wholesale, Entrust is opening the Accelerator to a limited set of enterprise customers, financial institutions, cloud and SaaS providers, and systems integrators to jointly build reference architectures and validated use cases.
“Enterprises need to be able to trust autonomous actions across business processes, partners, and systems,” said Anudeep Parhar, Entrust COO for digital infrastructure. “Whether organizations are experimenting with AI agents, deploying initial use cases, or preparing for broader adoption, they need a trust foundation that can scale with them.”
Entrust’s approach makes sense. Rather than presenting a single finished product as the answer, the company is treating agent trust as an architectural challenge that still needs to be tested against real operating environments. It also acknowledges that enterprises have different platforms, regulatory requirements, business processes, and tolerance for autonomy, and that agent governance is unlikely to be solved by one rigid control model.
The idea is the create reference architectures, validated use cases, and practical controls for identity, authorization, and accountability, which can eventually be extended to other enterprises as well.
There’s no question AI agents can perform useful tasks. The market is now asking whether those autonomous agents can be authorized, constrained, verified, and defended.
The practical takeaway is less about any one vendor and more about what enterprises need to ask today, as they build out their AI agent strategies.
- Can we cryptographically verify which human authorized this agent, and which agent acted?
- Is authorization evaluated in real time, or granted once and forgotten?
- Are the keys and secrets agents use managed with the same discipline as human credentials?
- Could we produce a defensible record of an agent's actions to a regulator tomorrow?
Organizations that can answer those questions today are the ones best positioned to move agents from pilot to production without a governance incident.