Zero Trust Has A Big AI Agent Problem Ahead
CSO Online, Thursday, September 3rd, 2026
Agentic AI breaks zero trust's per-request model by chaining individually authorized actions into unapproved outcomes.
Zero trust verifies each request, but autonomous agents can walk through several legitimately permitted doors and land somewhere the business never approved.
Practitioners quoted say the framework cannot tell whether an approved agent is still the same agent after new tools, expanded memory or delegated authority are added, so the badge on Friday may not match what was approved Monday.
One estimate holds that roughly 80% of enterprise agents are not on any inventory, and agent-to-agent messages hidden in images create visibility gaps CISOs cannot see into. Suggested fixes include cryptographic delegation modeled on OpenPGP, rate limits, transaction boundaries and reversible decision frameworks.