ComputerWeekly

Zero-trust was built for people. Nobody told it about agents


For years, zero-trust has run on a simple premise: never trust, always verify. It’s a model built for a world where access is usually requested by a human.

That world is changing fast. In 2026, companies stopped asking what generative AI (GenAI) can do and started putting it to work. Agents increasingly interact with applications, APIs, data and business processes on a user’s behalf, often faster than security teams can track what’s actually been deployed.

Most zero-trust programmes haven’t kept pace. Gartner found that just over 35% of organizations align to existing zero-trust maturity models and even those weren’t designed around the risks AI models, agents and large language model (LLM) interactions introduce. That leaves a widening gap between how secure organisations think they are and how much visibility and control they actually have.

The gap matters because AI doesn’t behave like another application or another employee. An agent can make a decision, call an API, retrieve data and take an action without a human approving each step. A tool an employee picked up independently can sit entirely outside governance.

The answer for chief information security officers (CISOs) isn’t to slow AI adoption. It’s to extend zero-trust to cover it, across three fronts: knowing what AI exists, controlling what it can do, and controlling what it receives and returns.

The first problem: you can’t protect what you can’t see

One of the less glamorous challenges in enterprise AI may also be one of the most important: knowing what AI assets exist across the organization.

Organisations are running internally developed models, third-party AI services, assistants, agents and API integrations, while employees experiment independently with cloud-based and locally installed AI tools. Some of these deployments are sanctioned and governed. A lot of them are not. It’s shadow IT’s AI-era successor, arguably with a far larger blast radius, since an unsanctioned software-as-a-service (SaaS) tool might leak a file, but an unsanctioned agent with API access can extract sensitive data, leak it and then act on it.

The fix is comprehensive, automated discovery and inventory. Not a one-off audit, but a continuous control that identifies new assets, classifies them by risk, and feeds those insights into access, security and governance decisions. Anything unknown should be treated as high-risk until validated and assessed. That also gives CISOs and cyber security leaders measurable indicators instead of vague reassurance: what percentage of AI assets have been discovered and inventories; time to detect new AI asset; how much shadow AI has genuinely been eliminated rather than just documented; percentage of AI assets classified by risk. Sharper questions than simply “do we have an AI inventory.”

The bigger shift: agents need identities and limits

Visibility is the starting point, not the destination. The more consequential change happens when AI stops generating an answer and starts taking an action such as accessing a database, updating a record, calling an external API. Grant an agent more privilege than it needs, and a compromised or misused one quickly turns a contained incident into something much bigger.

This is squarely a zero-trust identity problem: agents should be treated as machine identities, held to the same standard as human users, arguably higher, given they can act autonomously and at speed. But identity alone isn’t enough. The question is what an agent is allowed to do right now, in this specific context, which pushes organisations toward intent-based, policy-driven access controls, contextually validated at runtime and continuously monitored rather than granted once and forgotten.

A service account does a predictable job on a schedule; an agent responds dynamically, and its behaviour can shift interaction to interaction. That’s why the emphasis needs to sit on behaviour rather than static configuration. This includes metrics such as percentage of agent actions validated against policy, detection rate of anomalous agent behaviour and reduction in overprivileged agents, turning an abstract concern about ‘agent risk’ into something a CISO can measure, track and manage.

LLMs need policing and controls on both sides

There’s a third piece often overlooked in favour of infrastructure and identity: the interaction itself. With LLMs, input and output are both attack surfaces. A malicious prompt can attempt to manipulate a model or extract data it shouldn’t have access to. A model’s response can just as easily leak something it should never have disclosed in the first place.

The answer is filtering on both sides of that exchange, validating and masking sensitive content in prompts before they reach the model, and screening responses for sensitive data leakage or unsafe content before they reach a user or downstream system. The mindset that makes this work is the same one that zero-trust has always applied elsewhere: don’t assume a prompt is safe just because it came from inside the building.

That does not mean locking AI down to the point where nobody wants to use it. The point is proportionality, controls that make usage observable, resilient and governed without strangling the value that justified the investment. Success should be measured through outcomes, including the percentage of malicious prompts blocked, the percentage of data leakage incidents prevented and the false-positive and false-negative rates of AI content filters. These metrics provide a clearer view of whether controls are improving security without unnecessarily disrupting legitimate business use.

Where it’s worth pushing back

Extending zero-trust to AI is the right direction, but there’s a risk that ‘AI-specific controls’ become this decade’s version of bolting on a firewall and calling the job done. Inventory, agent identity management and input/output filtering are necessary foundations, but they are not sufficient on their own. An agent can be fully inventoried, properly authenticated and continuously monitored, yet still be authorised to make consequential decisions without human oversight. In that scenario, what appears to be a governance success may simultaneously represent an operational risk. In that scenario, what appears to be a governance success may simultaneously represent an operational risk.

There’s a timing challenge too. The AI security platform (AISP) market remains fragmented and immature. No agreed standards and no consistent terminology, which is exactly why buyers should prioritise hands-on evaluation, scope accordingly and select vendors with independently validated capabilities to ensure investments deliver measurable cyber security outcomes, rather than betting big on any one vendor. Fair advice, but most security teams don’t have a multi-year runway, and boards want an answer to the question “are we exposed, where are the risks, and what is being done about them?” faster than a phased rollout allows. Expect some theatre over the next year: comprehensive dashboards showing agent-policy validation, compliance and governance metrics, produced before the underlying access model has changed.

Zero-trust needs to become an AI operating model, not a bolt-on

The temptation is to treat AI as just another emerging-tech problem and wait for the market to settle. That would be a mistake. The gap between AI adoption and AI governance is widening now, and every quarter of inaction/delay is a quarter of more shadow AI, excessive unscoped agent permissions and unfiltered LLM interactions building up quietly in the across the enterprise.

The more effective approach is to extend existing zero-trust programmes rather than build a parallel one: find where AI introduces assets, identities and behaviours those traditional zero-trust programmes were never designed to see, govern and then systemically close the gaps. Know what AI exists, control what it can do, control and govern what it receives and returns, and measure all three properly.

The security perimeter itself is quietly becoming less human. For decades, security strategies have been built around humans accessing systems. Increasingly, systems are accessing other systems, making decisions and acting on humans’ behalf.

CISOs who get their organisation ahead of this shift will be the ones who recognize that the subjects requiring trust have changed and extend their existing zero-trust principles to effectively govern a world where autonomous agents, models and machine identities are becoming common first-class participants across the enterprise.

Gartner analysts are further exploring how organisations can adapt zero-trust strategies to secure AI at the Gartner Security & Risk Management Summit in London, from 22–24 September 2026.

Niyati Daftary is a principal analyst at Gartner



Source link