Enterprises have spent years building security around verifying who a user is. An AI agent complicates that, because the agent carries its own credentials and acts while the person who authorized it is elsewhere. Anyone reviewing the result often needs to know who authorized the agent, what it was permitted to do, where its data came from, and who answers for the outcome. Most of the current effort has gone into watermarking and detection tools that label where an output came from. A label of that kind answers none of those four questions when a decision gets challenged.

Ram Srinivasan is the Managing Director for AI Adoption, AI Integration, and Future of Work Advisory at JLL, the Fortune 500 commercial real estate and investment management firm. He advises enterprise clients on AI adoption, operating model design, and the organizational change that follows both. His 18 years in consulting include a Managing Director post leading JLL's Americas Future of Work practice and a Vice President role at Deloitte Canada. Srinivasan represents his firm as a partner in the World Economic Forum's AI Governance Alliance and is the author of both The Conscious Machine and the upcoming book The Substrate Shift.

"We definitely need an upgrade in the infrastructure surrounding trust verification. It should not slow down the business, it should actually accelerate the business," says Srinivasan. The upgrade he wants covers agents as well as the people who authorize them, and it extends verification past the login check into the whole time the agent is working. However, Srinivasan wants agreement on what the word trust means in a business setting before any of it gets built.

Confidence under uncertainty

In Srinivasan's definition, trust is what one party extends to another when it can't verify everything about them. He applies that to an enterprise relying on an AI agent, since few teams watch every step an agent takes. Provenance markers and audit records, in his account, record those steps so someone can check them afterward. "Trust is an expectation that something or someone is going to behave in the way you expect without having complete certainty," Srinivasan explains. "In simple terms, confidence under uncertainty is what trust is."

Srinivasan finds the same arrangement in a doctor's appointment. A patient usually goes ahead with the appointment without checking the doctor's training or confirming the diagnosis is right. "You don't know exactly what the doctor is going to provide as diagnosis, and you don't know whether it's actually going to be the right diagnosis," he notes. "But you trust it because there's some competence signal there. You trust that they'll act appropriately and you know that they are accountable."

A watermark is supposed to do that job for AI output, giving whoever receives it a reason to trust it without checking how it was made. Srinivasan wants to know whether a mark issued by one company in one country does that job at all. A mark does that job only when the recipient can interpret it. "For something like a watermark or an identity or a provenance verifier to be valid and acceptable, it needs to become a global standard," he says. "It can't just be one country, one company, one region."

Proof that keeps running

Verifying that someone is who they claim to be is an old problem, and Srinivasan traces how enterprises handled it before AI. The oldest answer was knowing someone personally, and banks, courts and universities came next, vouching for people because those institutions had reputations of their own to protect. Documents followed, and at every one of those stages a person could examine the evidence and judge it. "Then you went into the next domain of, 'I trust a document,' so you have a contract, a certificate, an ID, a photograph," he explains. "Notice until this point of time, seeing was believing."

Over time, passwords replaced documents, and then simply being on the office network was proof enough. Anyone who got inside it could move around freely. Remote work and cloud software removed that boundary, and zero trust arrived as a rule that checks every request wherever it comes from. Srinivasan expects agents to strain that rule, since an agent has its own login and keeps its permissions after the job it was given is finished. "You will need zero trust for humans and machines both," Srinivasan says. "You need audit trails, you need provenance verification, you need trust in action. You're going to move from spot trust verification to continuous trust verification."

The record behind an action

Someone checking an agent's work sees only what it produced. Along the way, the agent chose which records to use and which permissions to invoke. The choices survive only if the software was built to record them as they happened. Srinivasan runs through what that record has to contain, and a system can log most of what he lists. "It would be things like who created it, who authorized it, where did the information come from, what changed, what a system or an agent is allowed to do, what is it not allowed to do, can I verify it independently," he says. "Apart from all of the mechanical elements, the most important piece is who's accountable."

Srinivasan hears the same request from real estate clients. They want their usual coffee waiting when they arrive, their desk reserved, and the meeting room they prefer already held. An agent can do all three without much trouble once it has a great deal of information about the client, and the question of who pays when it gets something wrong stays open. "Imagine I authorize an agent to do this. The agent now needs to know, 'Are you at the location that you usually are?'" Srinivasan notes. "What did you order previously? How do I know? Am I accessing the system as you, or am I accessing the system as me, the agent? What if I make a mistake? Who's liable?"

Every one of those questions turns on data the agent can reach, and on whether that data is still accurate. Srinivasan puts the acceptable age of that data anywhere from microseconds to years, depending on the business. He's more interested in what's buried in data a company already has, and he points to ESA's AI sweep of the Hubble archive: in two and a half days, it combed 35 years of images and found more than 800 cosmic anomalies no one had documented. "My question is always to businesses," Srinivasan asks. "Where do you think that type of information resides in your business, where you haven't even thought about it?"

The name on the output

Srinivasan puts the whole question on who takes responsibility for the output. A typewriter, a model, and an agent all produce text a person has to stand behind, and he draws no distinction between the three. In his view, the responsibility belongs to an organization or an individual. "So long as I can be accountable for what's on paper, it does not matter how the words appeared on paper," he says. "If I'm willing to put my name behind it and stand behind what's there, it shouldn't really matter how the text was produced."

Srinivasan expects many companies to make the mistake of adding trust verification to an existing process as one more approval step. He points to recruitment, where candidates use AI to improve their interview performance and recruiters use AI to confirm the candidate is human. "We don't need to reinvent new forms of trust," he adds. "We probably need to reinvent the process so that it fits the new substrate of AI that we have."

A label on an output rarely changes a reader's mind, since the decision to trust the source was made before the label was read. Srinivasan expects the same inside enterprises, where the reputation of whoever signed off decides whether anyone acts on the output. "What's going to become more valuable is reputation," Srinivasan concludes. "The content that you put out carries the weight of your reputation, and that's perhaps more valuable than a watermark."

The views and opinions expressed are those of Ram Srinivasan and do not represent the official policy or position of any organization.