Virtual Round Table · Jul 22

View the event
Entrust launches an agent identity program to unblock AI pilots stuck short of production
Digital Transformation

Entrust launches an agent identity program to unblock AI pilots stuck short of production

Entrust's new Agentic AI Trust Accelerator convenes enterprises to design the identity and audit infrastructure autonomous agents need, targeting the governance gap that keeps working pilots from clearing risk committees.

PublishedJuly 16, 2026
Read time7 min read
Share

What Entrust announced

Entrust unveiled its Agentic AI Trust Accelerator on July 15, a co-development program built to move enterprise AI agents out of pilots and into live production. The company frames the effort as a joint design exercise: enterprises, financial institutions, cloud and SaaS providers, and systems integrators enroll to build the identity and trust infrastructure that autonomous agents require to operate safely. Enrollment is limited, and Anudeep Parhar, Entrust's Chief Operating Officer for Digital Infrastructure, is leading the initiative. The pitch is aimed squarely at the organizations that have working agents in testing but cannot get past their own risk committees.

Parhar put the problem plainly, saying AI agents are advancing faster than the trust infrastructure needed to govern them. Chief Executive Tony Ball framed the stakes in commercial terms, noting that trust will determine how quickly organizations can move from experimentation to production. We take the announcement as a marker of where the enterprise AI conversation has landed in mid-2026. For most agentic programs, the blocking issue is now the absence of a governance layer that a security team and an auditor can both stand behind when an agent acts on its own. Model capability and integration plumbing are largely solved problems by comparison.

The governance gap the program targets

The program is aimed at a well-documented gap. Entrust cites an IBM study finding that 77 percent of CIOs and CISOs believe AI adoption is already outpacing their governance capabilities, and that 59 percent point to security and compliance as leading obstacles to deployment. Those figures match what we hear across the enterprises we work with. Teams build a capable agent, demonstrate it in a controlled setting, and then stall when they try to grant it authority over production systems that move money or touch regulated data. The demonstration succeeds and the deployment stops at the same predictable point.

The reason the stall is so consistent is that most governance programs were designed for software that people operate. An agent that initiates transactions with no human in the loop breaks the assumptions baked into identity systems, access controls, and audit trails built around named users. Entrust is positioning its accelerator to close that structural gap before an enterprise commits agents to critical workflows. We think the timing is right. The organizations furthest along have discovered that retrofitting trust controls after an agent is live is far more painful than designing them in from the start.

Four foundations for trusting an agent

The accelerator organizes its work around four foundations. Identity means tracing every agent action back to a confirmed human principal and a uniquely identified agent, so that accountability never dissolves into an anonymous process. Authorization means keeping agents inside approved policies and requiring human oversight on critical decisions. Cryptographic trust covers the protection of keys, certificates, secrets, and signing capabilities that let systems verify an agent is what it claims to be. Accountability means producing cryptographically verifiable records that regulators and risk teams can inspect after the fact. Together they describe a control plane specific to non-human actors.

What we find useful about this framing is that it maps cleanly onto questions a risk committee actually asks. Who authorized this action, and can you prove the human chain behind it? Was the agent operating within policy at the time? Can you demonstrate the agent's identity was not spoofed? Can you reconstruct exactly what happened for an auditor? An agentic program that cannot answer all four will not clear a regulated enterprise's approval process. Entrust is essentially selling a structured path to yes on each question, which carries more value to a stalled program than another increment of model performance.

Why identity is the binding constraint

Identity is the foundation the other three rest on, and it is where enterprise infrastructure is weakest today. Existing identity systems were built to authenticate people and, more recently, service accounts and machines. An autonomous agent is a different kind of actor. It can spawn sub-tasks, call other agents, and act continuously, and it needs an identity that captures the human principal on whose behalf it operates. Without that binding, the audit trail has a hole at its center, and no amount of logging downstream can fill it. Entrust's decision to lead with identity reflects where its existing certificate and key-management business already sits.

For a CIO, the identity question determines whether an agentic program is auditable at all. If your organization cannot answer which human is ultimately accountable for a given agent action, then you cannot safely give that agent authority over anything consequential. This is why the accelerator convenes systems integrators and cloud providers alongside enterprises. Non-human identity has to work across the whole stack, from the model host to the SaaS applications the agent touches. We would treat a coherent agent-identity model as the first deliverable of any production agentic program, ahead of expanding the range of tasks the agents are allowed to perform.

What this signals about the market

The announcement fits a clear pattern in the 2026 enterprise market. Vendors are converging on governance and control as the layer where agentic AI will be won, because that is where deployments are stuck. Entrust brings an identity and cryptography heritage to the problem. Other established security and platform vendors are staking out adjacent ground with control towers, policy engines, and audit tooling. We read this convergence as confirmation that the enterprise buying question has moved from what an agent can do to whether an organization can prove what it did. That shift favors incumbents with existing trust infrastructure and regulatory credibility.

The co-development structure is itself worth noting. Entrust is convening customers to co-design the standards alongside integration partners, an approach that acknowledges how immature the category still is. No settled reference architecture exists yet for governing autonomous agents at enterprise scale, and the firms that help define it early will shape the requirements their peers eventually adopt. We would see participation in an effort like this as a way to influence emerging norms while they are still forming, which carries strategic value beyond the specific controls delivered.

How CIOs should evaluate the offer

For technology leaders weighing this program, the first test is fit with existing infrastructure. Entrust's strength is identity, certificates, and cryptographic key management, so the accelerator will deliver the most value to organizations that already treat those disciplines as core and want to extend them to non-human actors. Enterprises in banking, insurance, and healthcare, where auditability is a regulatory obligation, are the natural early participants. We would ask pointed questions about interoperability, since agent identity only works if it spans the model hosts, orchestration layers, and SaaS applications your agents actually touch across a heterogeneous estate.

The second test is whether the program accelerates a decision you have already made or substitutes for one you have avoided. Trust infrastructure removes a real blocker, and it does not by itself establish which agentic use cases are worth the risk. We would pair any evaluation of this accelerator with a hard internal ranking of candidate workflows by value and exposure, so that the governance investment is pointed at agents you genuinely intend to run in production. The organizations that get value from tooling like this arrive with a concrete deployment in mind and a clear view of the approval it has to pass.

Tagged#news#digital-transformation#enterprise#cio#erp#strategy#governance#agentic-ai#identity#security