Zero trust must now move at agent speed
Summary
Andre Durand, CEO and founder of Ping Identity, emphasizes that enterprises must immediately implement zero trust security for AI agents, not as a future goal. Agentic AI's rapid operational speed drastically compresses risk timelines, requiring real-time permission decisions. Unlike human actions, AI agents can perform thousands of actions in minutes, quickly accumulating access permissions beyond current security architecture capabilities. This velocity demands "just enough, just in time" access and continuous revalidation. Agents need unique identities, not shared human logins, to prevent blurred accountability and reduce risks from embedded API keys. Policy enforcement can occur at API and agent gateways, applying real-time risk signals. The architecture must also prevent agents from rewriting their own permissions and establish frameworks for trusting AI-generated output, potentially via isolated agent-based reviews. Security leaders should evaluate comprehensive agent management lifecycles, focusing on discovery, registration, custodian assignment, and centralized policy enforcement for all agents.
Key takeaway
For AI Architects and Security Engineers deploying AI agents, you must prioritize immediate zero trust implementation. Your existing security models cannot handle the velocity and permission accumulation of agentic AI. Ensure every agent has a unique identity and that authorization is continuously revalidated for each action, not just at login. Implement policy enforcement at API and agent gateways, and establish frameworks for trusting AI-generated output through isolated agent reviews. Moving slowly now will incur significantly higher costs later.
Key insights
Agentic AI's speed demands immediate, granular zero trust implementation with unique agent identities and continuous, real-time access verification.
Principles
- Zero trust demands continuous, per-action verification.
- Agentic AI compresses security risk timelines.
- Each AI agent requires a distinct, unique identity.
Method
Enforce zero trust policies at API and agent gateways, applying real-time risk signals. Provision each agent with a unique identity. For AI-generated output, use isolated, separate agents for review to establish trust in the framework.
In practice
- Assign unique identities to each AI agent.
- Avoid embedding API keys in source code.
- Use separate, isolated agents for output review.
Topics
- Zero Trust Architecture
- AI Agents
- Identity and Access Management
- AI Security
- Real-time Security
- Policy Enforcement
Best for: CTO, VP of Engineering/Data, Executive, AI Security Engineer, AI Architect, Director of AI/ML
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by VentureBeat.