Skip to content
← All termsGlossary

Zero Trust for AI agents

Zero Trust for AI agents applies the rule "never trust, always verify" to software agents. It checks every connection continuously, not once at login. John Kindervag named Zero Trust at Forrester in 2010. Agents need one more check on top: verifying each action the agent takes.

Also called: Zero Trust, ZT, Zero Trust Architecture, ZTA, never trust always verify, Zero Trust for agents

Updated

Why Zero Trust for AI agents matters

Zero Trust is the foundation for securing AI agents. It checks every request, every time, instead of trusting a session once someone logs in. That model works well for people and devices. Agents raise the stakes because they act on their own and move fast.

Where teams get it wrong

Many teams think Zero Trust alone covers their agents. It verifies the connection, but not the meaning of what flows through it. A prompt injection can ride inside a fully trusted channel. So agents need one more check, at the level of each action they take.

A simple example

An agent logs in with a valid token and a healthy device. Zero Trust lets the request through. But inside a document it read, the agent was told to email customer records outside the company. The connection was trusted. The action was not. That is the check agents still need.

Let's figure out what you actually need.

No pitch. No pressure. Every conversation starts with a senior practitioner, not a sales team. We'll tell you straight where you stand and whether we're the right fit. If we're not, we'll point you to who is.