Trending Topics

Zscaler: AI agents are becoming privileged insiders. Zero trust must catch up
AI agents are no longer just answering questions. They access enterprise data, call tools and trigger workflows, making them privileged insiders that operate at machine speed. Zscalerโs Zenith Live 2026 announcements now seem like they were a premonition of things to come. Less than two months later, an autonomous agent linked to OpenAI breached Hugging Faceโs production environment, accessing internal datasets and service credentials.
The incident was an apt illustration of just what AI can do when identity, permissions and runtime controls fall short. This development makes zScalerโs call to arms, to extend zero trust to how agents communicate, access data and act across enterprise systems, an immediate operational requirement.
Identity comes first
Every agent needs its own non-human identity.
An agent should not inherit broad permissions from the employee who launched it. Organisations must know who owns an agent, what it is authorised to do, which systems it can reach and when that authority expires.
This is absolutely critical because an agent asked to resolve overdue invoices may retrieve customer data, draft messages and update records in seconds. If it also has permission to issue credits or change bank details, a vague instruction can become a high-impact error.
Zscaler deals with the identity issue through AI Access Graphs. These map the relationships among users, agents, applications and data, thus helping security teams identify unnecessary access and follow data lineage.
Delegate, donโt hand over
Delegated access must be narrow, temporary and specific to the task at hand. To illustrate, once an employee approves a supplier invoice, an agent should not automatically gain unrestricted approval powers.
Futhermore, security teams must define the data an agent can use, the tools it can call, transaction limits and the actions that require human approval. This approach reflects the core zero trust principle which is that access is continually assessed according to identity and context, rather than granted once and assumed safe.
Zscalerโs AI Broker for Agents deals with this matter by enforcing fine-grained policies over MCP and agent-to-agent interactions, using a central registry to determine what an agent can access.
Preserve the evidence
Traditional logs show that a user accessed a system. But, the era of AI, Agent audit trails need to show more:
- the initiating request,
- data accessed,
- tools invoked,
- actions proposed and,
- the human who approved or rejected them.
That record is vital for containment, forensics and accountability. Without it, security teams cannot reliably identify whether an agent exceeded its scope or reconstruct its path through the environment.
Keep people accountable
Human oversight need not mean reviewing every AI output. Low-risk work, such as report summarisation, can run with automated guardrails. High-impact actions such as moving regulated data, changing access rights or altering financial records, should trigger explicit approval.
Zscalerโs agentic AI controls point towards the right model: discover agents, verify their identities, constrain their permissions and inspect their interactions. The Hugging Face incident makes the imperative clearer. Treat AI agents as privileged insiders before they behave like ungoverned ones.
