Zero Trust in the Age of Artificial Intelligence: Data, AI, and Security

Last update: December 4th 2025
  • AI multiplies both defensive capabilities and risks, rendering traditional perimeter security insufficient.
  • Zero Trust is evolving towards a data-centric model and the control of AI agents with "minimal agency".
  • The combination of AI, Zero Trust, and managed services enables visibility, automation, and real-time response.
  • Success depends as much on technology as on a cultural shift that normalizes digital distrust by design.

zero trust and artificial intelligence

The rise of generative artificial intelligence has been a game-changer in cybersecurity: the same technologies that drive business innovation also enable faster, more credible, and automated attacks . Security teams are now forced to defend hybrid infrastructures, with remote users, cloud services, and connected industrial systems, while regulations tighten and budgets don't always keep pace.

In this scenario, it is increasingly clear that the old "secure perimeter" model is dead and the Zero Trust philosophy has become the new standard . The challenge now is to adapt it to a world where it is necessary to control not only people and devices, but also AI models, autonomous agents, and data flows that move at machine speed between platforms, applications, and clouds.

Why AI is challenging the traditional security model

Artificial intelligence has become a double-edged sword: it strengthens defenses, but also enhances the arsenal of cybercriminals . Today, it's trivial to generate hyper-personalized phishing campaigns, voice or video deepfakes, polymorphic malware , or automated frauds supported by generative AI.

At the same time, organizations are managing increasingly heterogeneous infrastructures : multicloud environments (AWS, Azure, Google Cloud, Oracle), SaaS, their own data centers, industrial OT networks, and thousands of remote workers . All of this with critical data scattered everywhere, complex digital supply chains, and growing regulatory pressure (NIS2, DORA, industry regulations).

Cybersecurity experts agree that the problem isn't the attacks that are blocked, but those that go undetected . Adversaries camouflage themselves within legitimate traffic, exploit stolen credentials , abuse APIs, and rely on AI to move laterally with great stealth, often taking advantage of poorly controlled "trusted" access points.

In the face of this scenario, legacy perimeter-centric architectures — traditional VPNs , flat networks, implicit trust in what's "inside" —

Zero trust model in artificial intelligence environments

From perimeter security to the Zero Trust approach

For years, IT security was based on the metaphor of a walled castle: inside, everything is trustworthy; outside, everything is suspect . Firewalls at the perimeter, VPNs for entry, and once inside, unrestricted access to the internal network. This model falls apart when employees work from anywhere, applications are hosted in the cloud, and data travels between vendors, partners, and IoT devices.

To address this shift, in 2010 Forrester popularized the Zero Trust model, conceptually driven by John Kindervag, with an idea as simple as it is radical: “never trust, always verify .” It doesn't matter if the connection comes “from within” or “from without,” all access must be authenticated, authorized, and continuously monitored.

The basic principles of Zero Trust can be summarized in three pillars: rigorous and independent verification of origin, access with least privilege, and the permanent assumption of compromise . In other words, it is assumed that the network may be compromised and that any user—even an internal one—can become a threat, whether by mistake or maliciously.

Over time, this approach has evolved from a theoretical concept to one with concrete guidelines. The publication of NIST SP 800-207 and the CISA maturity model marked a turning point , providing reference architectures for networks, applications, and data. In parallel, in Europe, NIS2 and ENISA recommendations are driving critical sectors to incorporate strong authentication, segmentation, and continuous access control.

Zero Trust in the Age of AI: When Autonomous Agents Break the Mold

The first wave of Zero Trust was designed with relatively static people and devices in mind : human users, corporate teams, traditional business applications. But AI has profoundly changed this reality.

AI models—especially large language models (LLMs) and autonomous agents— operate dynamically, cross system boundaries, and manipulate sensitive data in a matter of seconds . They can read emails, launch workflows, modify files, interact with APIs, or make decisions without constant human supervision.

  How Google's Quantum Echoes algorithm works

OWASP, in its Top 10 Risks for GenAI and LLM, warns about so-called “excessive agency”: when AI is granted too much autonomy or capacity to act . Agents that send emails on behalf of executives, bots that move money between accounts, assistants that make changes to production systems… Each of these functions opens new attack vectors if not properly controlled.

Human-centric Zero Trust approaches fall short: they don't scale to handle the thousands of decisions per minute made by algorithms . Manually applying least privilege principles to every action of every agent is simply unfeasible. This is where a key evolution emerges: shifting the focus from identity to data.

Zero Trust focused on data: data as the new control plane

In an AI-dominated environment, what truly matters is no longer just who accesses the data, but what data they access, how they transform it, and with whom they share it . The network perimeter loses its meaning, and the new perimeter becomes the data itself.

Analysts like Forrester, with frameworks such as AEGIS for AI governance, emphasize that security must pivot toward data observability, context, and accountability . This involves enabling innovation with AI, but under controls based on information classification, data lineage, and auditable rules for its use. To protect sensitive information, it is advisable to implement practices and controls that reduce the risk of data leaks and theft.

Specialized platforms combine DSPM (Data Security Posture Management) and AI-SPM (AI Security Posture Management) capabilities to discover where sensitive data resides in cloud, SaaS, and hybrid environments , how it is used, and which AI systems access it. From there, governance policies are applied to detect risky behavior (malicious prompts, exfiltration, unusual activity) and automate blocking or alerts.

This shift transforms Zero Trust into a living, data-driven architecture capable of scaling with autonomous agents and self-learning models. Instead of blindly trusting AI to do “the right thing,” dynamic safeguards are established that limit what it can see and do based on sensitivity and context.

AI as an ally: next-generation SOC and “minimal agency”

AI doesn't just create problems; it's also a key component for sustaining Zero Trust at scale . The sheer volume of current security signals (logs, network telemetry, cloud activity, identity events, etc.) is overwhelming for any human team without automated support.

Cybersecurity vendors are integrating advanced AI into their protection, detection, and response platforms . This ranges from engines that analyze hundreds of trillions of events to uncover anomalies, to intelligent agents in the SOC capable of investigating incidents, correlating alerts, and executing actions without manual intervention.

Leading companies are experimenting with the concept of Agentic SOCs: security operations centers powered by AI agents that work hand-in-hand with analysts . These agents understand the infrastructure context, recommend containment measures, write reports, automate playbooks, and, in some cases, execute responses directly within well-defined boundaries.

The key lies in applying a principle similar to least privilege to AI, but adapted: the "minimal agency" model recommended by OWASP . This restricts not only the data an agent can access, but also the specific actions it can perform. No bot should be given the power to "do everything" in production unless absolutely necessary.

Real-world examples: Zero Trust and AI in banking, energy, industry, and food

The theory is fine, but where Zero Trust proves its worth is in the trenches of critical sectors , where one mistake can shut down a plant, bring down a financial service, or leave millions of users without power.

In the banking sector, concerns revolve around fraud, identity theft, and data breaches . Financial institutions are working to build highly scalable Security Operations Centers (SOCs) that combine massive telemetry, AI-powered analytics, and automation. The goal is to anticipate fraud patterns, block suspicious activity in real time, and shift from a purely reactive to a proactive model. The ability to recover and secure compromised accounts is key to mitigating the impact of these attacks.

  Google launches Gemini 2.0 Flash and Pro with AI improvements for everyone

In the energy sector, players like large electricity companies face a massive exposure perimeter: millions of smart meters, thousands of transformer substations, and field teams accessing central systems . Furthermore, there is often a very strict separation between IT and OT environments, which are frequently considered mutually untrustworthy. Migrating to Zero Trust in this context means achieving unified visibility and distinguishing within the Security Operations Center (SOC) what constitutes an attack from, for example, a scheduled mass device update.

In the manufacturing industry, where production continuity is paramount, Zero Trust is a very tangible reality: if a PLC or robot stops, the impact is immediate . Manufacturers with products that last for decades coexist with legacy OT technologies, insecure protocols, and an ever-increasing cloud connectivity. One of the key challenges is unifying visibility and control over this mix of IT and OT solutions, achieving a single pane of glass that displays everything from the machine network to the customer's cloud.

In food companies with automated plants, the concern is that unauthorized remote access to industrial equipment could directly impact production . The principle is clear: no supplier should access a PLC or robot without a strictly controlled, monitored, and revocable session in real time, with activity recording and permission expiration.

Digital supply chains, LLM and data breach risk

Beyond internal infrastructure, many organizations are discovering that their main weakness lies in the digital supply chain . They work daily with banks, technology partners, integrators, fintech companies, cloud providers, and many others, all connected in one way or another to the company's systems.

Each link introduces a potential entry point: a third party with poor security practices can become the backdoor for a larger attack . This necessitates a thorough evaluation of B2B access, restricting permissions, segmenting environments, and monitoring API-based integrations.

Added to this is a growing concern with the use of external LLMs: the risk that internal information could end up "feeding" public-private models without control or traceability . Strategic documents, customer data, or proprietary code can be inadvertently leaked when used as context in AI tools without proper safeguards.

Zero Trust applied to AI here implies establishing strong DLP (Data Loss Prevention) controls , regulating what can be sent to which models, requiring data residency, and, where possible, opting for private deployments or "walled gardens" where the organization has real control over what is trained and what is not.

Implementing Zero Trust with AI: practical steps and challenges

Implementing a Zero Trust strategy isn't simply a matter of installing a couple of tools; it's a strategic, technical, and cultural journey . Even so, some practical steps can be defined to get off to a good start.

The first step is visibility: inventorying assets, data, identities, and flows . It's essential to know what systems exist, what critical information they handle, who (or what AI agent) accesses them, and from where. Data discovery and classification tools help identify "crown jewels" in public clouds, SaaS, and on-premises environments.

Next comes risk assessment and policy definition: classifying business processes according to impact, defining who can access what and under what conditions . This includes granular access policies, network segmentation, defining OT/IT "zones," API protection, and clear rules on the use of AI services.

Implementation is typically phased: starting with identity (phishing-resistant MFA, Single Sign-On, modern privilege management), followed by ZTNA/SASE for access, and later, microsegmentation and deep data protection . Each phase is accompanied by continuous monitoring to adjust policies and prevent overly restrictive measures from crippling business operations.

  5 Surprising Things You Didn't Know About Artificial Intelligence

Throughout this journey, familiar obstacles arise: resistance to change, technical complexity, a legacy system difficult to adapt, and fragmented tools . Training, change management, and consolidation on integrated platforms (SSE, SASE, observability suites) are essential levers to avoid becoming victims of success.

AI, smart authentication, and managed services

AI is also reshaping authentication. Instead of relying solely on passwords or static factors, modern systems employ adaptive, risk-based authentication . They analyze location, device, usage patterns, typing speed, and even mouse behavior to determine whether a request is legitimate or suspicious.

This type of AI-powered authentication is a perfect fit for Zero Trust: each login attempt is dynamically evaluated, potentially requiring additional factors, limiting permissions, or blocking access altogether when the risk is high. All of this happens almost transparently to the legitimate user, who experiences less friction when behaving as usual.

Another area where AI shines is in automated response: if a device starts exfiltrating data, a malicious agent moves laterally, or a user downloads anomalous volumes of information , detection engines can isolate the endpoint, revoke tokens, close sessions, and launch investigations almost instantly.

For many organizations, especially medium-sized ones, building this level of sophistication internally is complicated. This is where managed cybersecurity services come in, offering 24/7 SOC, advanced monitoring, AI-powered access management, and security automation without forcing the company to build everything from scratch.

Cultural change: the “Zero Trust generation” and the digital divide

Beyond technology, Zero Trust demands a cultural shift in how trust is understood in digital environments . It's not about "distrusting people," but about accepting that every system can fail and that the best way to protect users and businesses is to never assume that anything bad will happen.

Interestingly, younger generations who have grown up using social media, online video games, and digital services since childhood are quite familiar with environments where trust must be earned and the rules are strict . This group is beginning to be called, somewhat ironically, the “Zero Trust Generation.”

At the other end of the digital divide, some of the more senior staff may perceive security measures as unnecessary obstacles or as a sign of personal distrust . The key here is to clearly explain the purpose of each control, show real-life incident cases, and reinforce that the goal is to protect both the organization and its employees.

Multi-factor authentication, access segmentation, or continuous verification cease to be seen as "annoyances" when it is understood that a single click on a malicious email can activate extremely sophisticated AI-supported attacks , with serious economic, legal, and reputational consequences.

Looking to the short and medium term, everything suggests that Zero Trust and Artificial Intelligence will continue to converge, becoming two sides of the same coin : AI as the engine for observing, analyzing, and responding to what happens in real time; and Zero Trust as the framework for limiting, verifying, and governing what people, machines, and models can do. Organizations that manage to balance autonomy and control, protecting data without stifling innovation, will be the ones best positioned in a digital environment where trust is no longer given freely, but rather crafted.

What is Zero Trust Architecture?
Related articles:
What is Zero Trust Architecture: pillars, design and best practices