



























Frederik Gregaard, CEO, Cardano Foundation. Navigating blockchain's impact on global finance & governance.

getty
An Al agent executes a seven-figure payment to the wrong supplier. Three organizations point fingers. No log, no credential and no digital trail on record can answer the only question that matters: Who authorized this, and where does liability reside? No one can figure out who's actually responsible.
My background is traditional finance, where identity and trust systems are the bedrock of every transaction. As AI agents start making decisions across organizational boundaries, those same systems are showing their limitations. The governance gap that enterprise leaders are building into their organizations right now—at scale, without fully recognizing it—will determine which companies survive their first major AI incident and which don't.
A June 2025 Gartner, Inc. report projected that by 2028, over one-third of enterprise software will include agentic AI—with up to 15% of day-to-day decisions made autonomously. Many organizations are racing to deploy these systems. Far fewer have asked the harder question: When your AI acts on your behalf, can you actually prove that it's accountable from start to finish in a court of law or under regulatory scrutiny?
Current AI credentials work like a permission slip: They prove that an agent is authorized to act at a given moment. What they don't prove is who granted that authority or who's ultimately accountable when something goes wrong.
At scale, these small, untraceable decisions add up to serious risk. When an AI agent executes a financial transfer, signs a contract or reclassifies a product in a regulated supply chain, regulators and counterparties will question who's responsible. Today's credentials simply can't answer that question.
Courts are already holding companies liable. California's AB 316, effective January 2026, explicitly bars organizations from arguing that an AI system "autonomously caused the harm." The 2024 case against Air Canada set this precedent, as the company was held responsible for misinformation that its own chatbot generated. This is the "AI accountability gap," where the distance between a human instruction and the autonomous output keeps growing with no traceable thread connecting the two.
Fixing this means rethinking how we handle trust. Most digital systems today rely on a "collect and store" model, hoping it'll be useful later. This approach creates delays, data silos and vulnerabilities. Instead, what's needed is infrastructure built around a "request and verify" approach in which verification, privacy and accountability are embedded from the start.
We helped introduce the digital trust infrastructure (DTI), a shared, open infrastructure that lets organizations verify who authorized what, under what conditions and whether those conditions were met—all in real time.
Think of it the way the internet's protocols work for communication. DTI works the same way for trust, providing shared, open infrastructure that any organization can build upon rather than a proprietary solution that creates new dependencies.
However, architecture is only half the equation. Most enterprises aren't organizationally structured to govern AI decisions with the rigor that regulators and counterparties are about to demand. That preparation starts now.
The biggest obstacle is that most organizations will need to overhaul not just their technology but their governance structures, and most aren't set up to do both at once. Here's where to start:
Identify one or two workflows where verification or onboarding is slowest and most error-prone, such as onboarding a new vendor, verifying an employee's credentials across borders or clearing a payment through KYC requirements. Define clear metrics—time to approval, fraud losses and audit effort. These become your pilot proving grounds.
Before any technology is deployed, get clear on the basics. Who issues credentials? Who verifies them? What evidence is retained? Where does liability lie? If those rules only exist in a legal brief and not in a format your systems can enforce automatically, they won't hold up at machine speed.
Keep a log of the data each model is trained on, register what it is and isn't allowed to do, and ensure it can access only the minimum it needs for any given task. If an AI agent is initiating payments or filing reports on your behalf, there should be a verifiable record of who controls it, what it was authorized to do and whether it followed the required steps.
When evaluating vendors, ask one question: Can your system produce a verification record that our partners, auditors and regulators can independently read and trust? If not, move on.
Replace PDFs, emails and screenshots with digital verifiable credentials. Digital credentials allow each party to only share the specific proof a transaction requires so that a supplier can prove it passed sanctions screening on a specific date or an employee can verify a professional license without either side exposing their full record.
Regulation is moving in one direction. The EU's Ecodesign for Sustainable Products Regulation mandates digital product passports for high-impact product categories starting in 2027, with most sectors covered by 2030. These passports require verifiable records of a product's origin, life cycle and ethical compliance—the kind of tamper-proof architecture that DTI is built to provide. For AI systems operating across borders, this becomes a market access requirement.
Every enterprise will eventually face a moment where an AI system makes a consequential error. The organizations that have built traceable, auditable chains of human accountability into their AI operations will answer the regulator's questions in hours. The ones that haven't could spend months in discovery trying to reconstruct an authorization chain that was never recorded.
The gap is real. The infrastructure for closing it is available now. The only variable is whether your organization builds this before or after an incident forces the issue.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。