generative AI automation

Secure AI agents require zero trust, starting now

Zero trust isn't a future checkpoint anymore, it's the only way to keep up when agents act in milliseconds.

4 min readVentureBeat
Secure AI agents require zero trust, starting now

The timeline for trust has collapsed, and most enterprises are still moving at the speed of annual reviews. Andre Durand's argument at Ping Identity is not a warning about the distant future; it is a description of the present danger. When an AI agent can execute a thousand actions in the time it takes a human to approve one, the old model of granting broad access at login and hoping for the best becomes a liability you can no longer afford to carry. This is the same uncomfortable reality that surfaced when AI Agents Shared User Images, Highlighting Data Security Concerns, where autonomous systems acted in ways no one had fully anticipated. The lesson is consistent: agents do not wait for you to catch up, and neither should your security architecture.

The practical shift here is from managing identities to managing decisions. Durand is right to frame zero trust as "just enough, just in time," because that phrase cuts through the vendor noise and gets to the operational core. What matters is not whether a user or agent is logged in, but whether the next action they are about to take is authorized in that precise moment. This is a fundamental change for most IT teams, who have spent decades building perimeter-based systems that assume once you are inside, you are trusted. That assumption is now not just outdated; it is dangerous. The accumulation of slivers of permission across thousands of agents is the quiet killer, and it is the kind of exposure that traditional security tools were never designed to measure. If you are waiting for a single catastrophic event to justify a zero-trust overhaul, you have already missed the point. The catastrophe is already happening in small, repeated approvals that no one is watching.

The uncomfortable truth is that humans are no longer the primary actors in this story, and that requires a new kind of humility. Durand's point about agents needing their own identities, rather than borrowing human logins, is not a technical nicety. It is the only way to maintain accountability when something goes wrong. If an agent is acting under a cloned human identity, you cannot tell who made the decision, and you certainly cannot audit it. The same logic applies to the shared secrets and API keys embedded in source code, a habit that is both convenient and indefensible at agent speed. We would tell any security leader reading this to stop treating agent identity as an extension of human identity and start treating it as a first-class citizen in your IAM strategy. The frameworks Durand describes, where one agent's output is reviewed by another agent that cannot communicate with the first, are not overengineering. They are the logical answer to the 97% success rate problem. If you cannot trust the output, you must trust the process that validates it, and that process has to be automated because human review will be the bottleneck that kills your velocity.

The specific takeaway here is not to buy a new product or adopt a new standard overnight. It is to ask a harder question: where is the policy enforced in your environment right now, and can it move at the speed of a single API call? If the answer is no, you are already behind. The window Durand describes is narrowing, not because vendors are pushing urgency, but because the cost of retrofitting security onto agentic workflows after they are widespread will be exponentially higher than building the right foundation today. Watch how your organization handles the next agent deployment, not the one after a breach. That is where the real test of zero trust will happen, and it will not be announced. It will be a single request that should have been denied, and the question is whether your systems are ready to say no.

From VentureBeat

Enterprises need to treat zero trust security architecture as an immediate requirement for AI agents rather than a long-term goal, says Andre Durand, CEO and founder of Ping Identity. Zero trust, the security model built on the assumption that no user, device, or system should be automatically trusted, requires continuous verification before every action rather than a single check at login. Agentic AI has profoundly compressed the risk timeline enterprises must manage, demanding that permission decisions be evaluated in real time.

type: embedded-entry-inline id: 1Ieiy1KhHNWZE5KVqNdA1G

Read the original at VentureBeat