AI and the growing impact on foundational trust systems


Suzanne Prescott
Contributor

Artificial intelligence may be arriving in organisations as a productivity tool, but it is quietly forcing a much bigger conversation underneath: whether the digital systems governments and enterprises rely on were ever designed for a world in which machines are now making, shaping and executing decisions. 

That is the warning from DigiCert chief trust officer Lakshmi Hanspal, who says the global rush to deploy AI is exposing a deeper weakness in the “electricity and plumbing of the internet” – the foundational trust systems that authenticate identity, secure data and verify digital interactions. 

“What we are seeing is AI driving enormous efficiency and productivity, but at the same time introducing the silent erosion of traditional controls that have been in our systems for decades,” Ms Hanspal said on the latest episode of Commercial Disco with InnovationAus.com publisher Corrie McLeod.

For years, cybersecurity has largely been discussed in terms of perimeter defence, privacy compliance and software patching. But Ms Hanspal argues the AI era changes the nature of the challenge entirely. 

As generative and agentic systems become embedded in service delivery, infrastructure, decision support and autonomous workflows, organisations are no longer simply securing users and devices. They are being asked to secure intent, machine identity, algorithmic behaviour and decision provenance – all at a pace traditional governance models were never built to manage. 

This is where digital trust, she argues, moves from a technical control to a strategic operating requirement. 

At the centre of that trust layer sit long-established but often invisible technologies: public key infrastructure, certificate management, domain name systems, identity controls and data governance. They are the mechanisms that allow organisations to know who – or what – is connecting, whether it is authorised, whether data has been altered, and whether systems are behaving as intended. 

Historically, these controls were built around static environments – but AI changes that. 

“The challenge with AI is that identity and intent are no longer fixed,” Ms Hanspal said. “Traditional systems have fixed intent. AI behaviour can change and adapt. That is its strength, but also its risk.”

DigiCert chief trust officer Lakshmi Hanspal. Image: Supplied

This matters acutely in government and critical infrastructure, where AI is beginning to shape frontline citizen services, energy systems, financial networks and connected physical assets. 

Without stronger cryptographic assurance and machine identity, organisations may find themselves increasingly unable to prove where outputs came from, whether systems have drifted from their original purpose, or who is accountable when autonomous decisions create unintended consequences. 

Ms Hanspal believes Australia is better positioned than many markets to confront this challenge, pointing to a growing willingness to align national AI ambition with cyber safeguards, public-private collaboration and international standards. 

She cites the federal government’s emerging AI safety investments, the Australian Signals Directorate (ASD)’s REDSPICE cyber agenda and collaboration with international agencies as evidence that Australia is attempting to build guardrails while still encouraging innovation. 

“What’s exciting is the balance between innovation and governance,” she said. “We need regulation at the speed of technological change. That is the healthy tension.” 

However, she warns that policy settings alone will not be enough if trust infrastructure remains fragmented or bolted on after deployment. 

The real shift, she says, is moving from assumed trust to provable trust. 

This means systems capable of continuously validating not just access credentials, but machine behaviour over time – measuring whether AI remains aligned to approved parameters, detecting unmanaged drift, and preserving audit trails that allow humans to intervene when required. 

In practical terms, this has direct implications for critical national systems now becoming more AI-enabled and interconnected. 

DigiCert is already working with Australian initiatives including the National Energy Public Key Infrastructure (NEPKI) project, which seeks to establish a common trust framework across increasingly complex energy networks involving EV chargers, solar systems, sensors and distributed devices. In environments like these, Ms Hanspal says, the issue is no longer simply whether devices can connect – but whether they can be continuously authenticated, governed and shut down safely if behaviour moves beyond acceptable bounds. 

The same logic is beginning to apply to one of cybersecurity’s looming long-term concerns: post-quantum encryption. 

While much of the corporate market still treats quantum risk as a future issue, Ms Hanspal says organisations are making a mistake if they wait for a dramatic tipping point. 

“This is not a Y2K moment where there is a single date,” she said. “The lead time to modernise cryptography is long, and organisations should be starting now.” 

The ASD has already set expectations for readiness planning by 2026 and implementation pathways by 2030, underscoring that cryptographic resilience is becoming part of the broader trust conversation, not a standalone science project. 

For DigiCert, the implication is clear: in an AI-shaped economy, trust cannot remain an invisible IT function sitting quietly in the background.

It becomes one of the few mechanisms organisations have to preserve accountability, resilience and public confidence as autonomous systems scale. 

Or, as Ms Hanspal puts it, AI may be moving fast – but somebody still needs to know where the kill switch is. 

This article was produced in partnership with DigiCert as part of InnovationAus.com’s Commercial Disco podcast series. 

Do you know more? Contact James Riley via Email.

Leave a Comment

Related stories