Why Zero Trust Must Extend to AI Workloads
Zscaler, Wednesday, September 23rd, 2026
Zscaler argues static firewalls and IP-based policy can't secure AI workloads' traffic volume and identity needs.
Zscaler argues that AI workloads break conventional network security, which enforces policy based on pre-defined, known communications that no longer describe how AI systems behave.
Security teams face an unworkable choice between locking down egress and constraining AI capability, or opening the network broadly and accepting unacceptable audit risk. Many enterprise firewalls were sized for human-speed traffic, and AI orchestration layers running parallel inference calls can overwhelm inspection infrastructure, tempting teams to bypass inspection for exactly the traffic that needs it most.
IP-based enforcement also can't distinguish between two AI agents on shared infrastructure with different access rights, and prompt injection now functions as the AI-era equivalent of phishing.