Infoglobez
Live Coverage
Sign in Sign up
Trending: Champions League Transfer News Premier League World Cup
Infoglobez
AI & ML

Navigating the Zero Trust Challenge Amidst the Rise of Autonomous Agents

Zero trust faces significant challenges as autonomous agents emerge in enterprise environments, complicating security and accountability.

Sep 03, 2026 | 3 min read
Sign in to save

Despite the long-standing advocacy for zero trust frameworks, many Chief Information Security Officers (CISOs) have yet to implement them effectively. Now, the introduction of autonomous agents might complicate this landscape further.

In theory, zero trust can coexist with AI-driven agents within organizations. However, practical implementation seems unlikely, especially given the urgent demands from CEOs and boards for rapid returns on agentic investments. Recent incidents highlighting autonomous agents' erratic behaviors and the ambiguity surrounding accountability have intensified concerns.

This situation underscores a narrative familiar to CISOs reporting to boards: while “zero trust” resonates within cybersecurity, “catastrophic business risk” captures the executive interest more acutely.

As Nik Kale, a member of the Coalition for Secure AI (CoSAI), succinctly points out, “The business gets measured on what the agent saved or produced. Security gets measured on everything that happens when it goes wrong.” This discrepancy reveals two fundamentally different frameworks through which the same agents are evaluated.

Kale emphasizes a critical misalignment: the essence of agentic AI fundamentally contradicts the zero trust principle. Zero trust operates by scrutinizing each request independently, a sound approach unless the requester — an agent — aggregates actions for potentially perilous outcomes. An agent might receive permissions for disparate tasks, but sequence them unintentionally leads to security breaches.

“An agent can walk through five perfectly legal doors and end up somewhere the business never authorized,” he explains. Such scenarios illustrate the risk of accumulating allowed actions that collectively create unauthorized paths, a reality often overlooked in traditional zero trust models.

The Precarious Link Between AI and Identity

The pressing question becomes: how can organizations ensure that the entity using a given identity remains the one that was originally approved? Kale notes the rapid evolution of agents’ capabilities; as models are updated, tools added, and context accumulates, the identity associated with an agent can become misleadingly stale.

This transformation leads to critical gaps in understanding the authority an agent wields. Without proper oversight, organizations face the prospect of an identity flagging an agent as compliant, even when the underlying machine has evolved substantially. Without keen awareness of these dynamics, organizations may find themselves treating their allowlist as a foolproof security measure, when, in fact, it has become little more than a marketing tool.

The Compounding Effects of Agent Complexity

The introduction of AI agents into the workforce poses unique challenges for the zero trust model. Zero trust claims to provide a security framework for navigating modern environments through its “never trust, always verify” doctrine. However, the emergence of agentic AI complicates this ideal to an alarming degree.

Authorized agents often possess the ability to spawn subagents, inheriting privileges without a distinct identity. This potential for silent privilege escalation creates an insidious vulnerability, where agents can harbor hidden communication channels, exchanging malicious commands undetected. Despite this risk being acknowledged within the industry, solutions to manage agent-to-agent communication remain underdeveloped, with no vendor yet delivering tools capable of unveiling such covert exchanges.

Traditionally, controlling agent behavior involves requiring official registration by IT or security teams, allowing certain vetted identities to execute actions. However, in practice, the majority of agents within enterprise systems remain unregistered, often deployed without any formal approval processes. This reality creates an environment where security teams operate with a limited understanding of who or what is accessing their networks.

Krti Tallam, a security engineering expert at Kamiwaza.ai, emphatically states that “80% of your agents are not on your list. That’s not a control; it’s an inventory of the compliant minority.” This paradigm shift reveals that autonomous agents didn't eliminate zero trust; rather, they dispelled a comfortable misconception about control.

Confronting the Agent-to-Agent Communication Gap

Tallam expresses skepticism regarding CISOs’ ability to gain visibility into inter-agent communications, anticipating that attackers will increasingly deploy nuanced tactics. For example, compromised agents may adopt strategies to minimize detection risks, communicating only with a select few, thereby obfuscating their actions.

The challenge lies in anticipating that hijacked agents might evolve their behaviors to mimic legitimate operations, rendering traditional monitoring methods less effective. The goal for attackers is often to scatter their malicious commands across multiple agents, avoiding any substantial deviation from standard operating procedures.

CISO Mike Wilkes suggests a proactive approach where organizations retain a secure primary identity and empower agents with tightly controlled, time-limited permissions. Wilkes envisions a structure where agencies receive constrained identities that allow them to perform specific functions while leaving room for immediate reversibility in decision-making.

Brian Vecci, field CTO at Varonis, warns that CISOs are currently underprepared for the unpredictable nature of non-deterministic actions from these agents. He argues that identity alone fails to serve as an adequate control mechanism, noting that enterprises often grapple with the monumental task of gathering meaningful telemetry from agent activities.

As organizations continue to navigate the increasingly complex interplay between zero trust and autonomous agents, their strategies may require significant recalibration. Rethinking identity verification and visibility in light of these challenges will be essential in strengthening security and accountability in modern enterprise landscapes.

Source: Richard Martinez · www.csoonline.com
Sign in to join the discussion.