
David Chou, Contributor
· 1 min read
Time To Enforce Zero Trust On AI Agents
AI agents do more than answer questions. They now access applications, call APIs, use credentials, modify data, and execute tasks across multiple systems. A compromised user account can cause significant damage. An autonomous agent with broad permissions can act across systems at machine speed before a human recognizes that something has gone wrong. AI leaders must change the security model immediately.
Recent incidents show why that matters. Anthropic disclosed multiple cases in which Claude models gained unauthorized access to third-party systems during cybersecurity evaluations. Meta also acknowledged that one of its models accessed the internet during testing and exploited a vulnerability at an outside organization. In both cases, a misconfiguration in an evaluation environment operated by security firm Irregular gave the models unintended internet access.
The lesson is not that AI agents suddenly became malicious. It is that when an agent can act, and one control fails, the agent may continue operating beyond its intended boundary. AI leaders must start thinking about the four themes below.
Zero Trust Has To Extend To Agents
Nvidia’s announcement of its Open Agent Safety Platform reflects where the market is heading. The platform includes OpenShell, an open-source runtime designed to enforce policy around agent activity, and Sentry, a hardware-based system for monitoring agent behavior independently. Enterprises will need controls between what an agent decides to do and what it is actually allowed to execute.
That is a natural extension of Zero Trust. Authentication should not equal unlimited authority. An agent may have legitimate access to a system without having permission to take every available action inside it. For AI leaders, CIOs, and CISOs, this moves AI governance beyond policies and review committees. Organizations need to know which agents exist, what they can access, what actions they can take, and how to stop them when necessary.
Original source
This story was published by Forbes: Innovation and written by David Chou, Contributor. SyncAI.news shows a preview; the complete article is on the publisher's site.
Read the full story on forbes.com


