Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
SecurityWeek, Thursday, October 1st, 2026
John Kindervag's new book argues zero trust still works against AI-driven attacks, but only if the policy engine is implemented correctly.
Fifteen years after introducing zero trust at Forrester, John Kindervag has published a multi-author book arguing the model remains effective in the AI era, a claim SecurityWeek challenged using incidents such as rogue agents attacking Hugging Face.
The key caveat is correct implementation: the custom policy engine must accurately reflect the organization's security posture and be protected from rogue agents and insider manipulation.
The difference today is that implementation failures can be exploited at machine speed, faster than humans can detect or respond.