Zero Trust for AI Agents Starts With Fixing Zero Visibility
Summary
Organizations are deploying AI agents (software systems that act autonomously to complete tasks) faster than they can secure them, with 70% admitting their AI workflows access sensitive data without full oversight. The core problem is lack of visibility: security teams cannot see what AI agents exist, what they can access, or when something goes wrong, making traditional security controls ineffective. Zero Trust principles (security approach that trusts nothing by default and verifies everything) can help, but only if organizations first create a complete inventory of all agents before attempting to enforce access controls.
Solution / Mitigation
The source recommends treating AI agent discovery similarly to how organizations now monitor cloud infrastructure: 'Treat AI and agent spend, along with API-key issuance, as discovery signals.' It also suggests involving 'Finance and procurement' as additional monitoring points to gain visibility into agent deployments. The underlying principle stated is 'You cannot govern what you cannot see,' with the SANS Zero Trust for AI Agents checklist emphasizing that inventory must come before any enforcement controls.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/09/zero-trust-for-ai-agents-starts-with.html
First tracked: September 26, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 82%