Zscaler: AI agents are becoming privileged insiders. Zero trust must catch up

AI agents are no longer just answering questions. They access enterprise data, call tools and trigger workflows, making them privileged insiders that operate at machine speed. Zscalerโ€™s Zenith Live 2026 announcements now seem like they were a premonition of things to come. Less than two months later, an autonomous agent linked to OpenAI breached Hugging Faceโ€™s production environment, accessing internal datasets and service credentials.

The incident was an apt illustration of just what AI can do when identity, permissions and runtime controls fall short. This development makes zScalerโ€™s call to arms, to extend zero trust to how agents communicate, access data and act across enterprise systems, an immediate operational requirement.

Identity comes first

Every agent needs its own non-human identity.

An agent should not inherit broad permissions from the employee who launched it. Organisations must know who owns an agent, what it is authorised to do, which systems it can reach and when that authority expires.

This is absolutely critical because an agent asked to resolve overdue invoices may retrieve customer data, draft messages and update records in seconds. If it also has permission to issue credits or change bank details, a vague instruction can become a high-impact error.

Zscaler deals with the identity issue through AI Access Graphs. These map the relationships among users, agents, applications and data, thus helping security teams identify unnecessary access and follow data lineage.

Delegate, donโ€™t hand over

Delegated access must be narrow, temporary and specific to the task at hand. To illustrate, once an employee approves a supplier invoice, an agent should not automatically gain unrestricted approval powers.

Futhermore, security teams must define the data an agent can use, the tools it can call, transaction limits and the actions that require human approval. This approach reflects the core zero trust principle which is that access is continually assessed according to identity and context, rather than granted once and assumed safe.

Zscalerโ€™s AI Broker for Agents deals with this matter by enforcing fine-grained policies over MCP and agent-to-agent interactions, using a central registry to determine what an agent can access.

Preserve the evidence

Traditional logs show that a user accessed a system. But, the era of AI, Agent audit trails need to show more: 

  • the initiating request, 
  • data accessed, 
  • tools invoked, 
  • actions proposed and,
  • the human who approved or rejected them.

That record is vital for containment, forensics and accountability. Without it, security teams cannot reliably identify whether an agent exceeded its scope or reconstruct its path through the environment.

Keep people accountable

Human oversight need not mean reviewing every AI output. Low-risk work, such as report summarisation, can run with automated guardrails. High-impact actions such as moving regulated data, changing access rights or altering financial records, should trigger explicit approval.

Zscalerโ€™s agentic AI controls point towards the right model: discover agents, verify their identities, constrain their permissions and inspect their interactions. The Hugging Face incident makes the imperative clearer. Treat AI agents as privileged insiders before they behave like ungoverned ones.

Kihara Kimachia
Kihara Kimachia

Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.