BusinessCybersecurity

Zero trust meets AI building cyber resilience for agents

Sep 17, 2026

Zero trust security is being rebuilt for AI agents in 2026, as non-human identities outnumber humans and breach costs climb across the enterprise.

Author: aruna
Headline Image

Somewhere inside your company right now, an AI agent is probably logging into a system using credentials nobody assigned it specifically, reaching data nobody scoped for its actual task, and taking actions nobody is watching in real time. That is not a hypothetical. It is the default state of most enterprise AI deployments in 2026, and it is exactly the scenario zero trust security was supposed to prevent, just for a population of digital workers the framework was never actually built to cover.

Zero trust has spent years as the standard answer to "how do we secure a perimeter that no longer really exists." AI agents just broke that answer again, because they do not behave like the users or devices zero trust was designed around. They act at machine speed, chain access across a dozen systems in seconds, and spin up sub-agents that inherit permissions nobody tracked. Here is what is actually happening at the intersection of zero trust and agentic AI, and what building real cyber resilience for an agent-driven enterprise requires right now.

Why zero trust was never built for AI agents

Zero trust as a formal model traces back to NIST Special Publication 800-207, which lays out three core principles, verify explicitly, enforce least privilege, and assume breach. The framework's entire premise is that no user or device should be trusted by default based on network location alone, every request gets evaluated against identity, device posture, and context instead.

That model works well when the thing making a request is a human sitting at a laptop or a predictable service with a fixed role. AI agents break both assumptions. An agent can call tools, chain decisions across dozens of systems, and take autonomous action without a human in the loop for every step, which means AI agent identity governance has to extend the same verify-explicitly logic to a population of actors that behave nothing like the ones zero trust was originally designed to police.

The non-human identity explosion nobody planned for

The scale of the problem is what makes 2026 genuinely different from prior years. Research from the Cloud Security Alliance, commissioned with identity platform Aembit and surveying 228 IT and security professionals, found that 68 percent of organizations cannot clearly distinguish between human and AI agent activity inside their own systems. That gap exists even as 73 percent expect agents to become vital to operations within the next year, and 85 percent already report running agents in production environments today, across task automation, research, developer assistance, and even security monitoring itself.

Separate CSA research on non-human identity puts a number on the underlying sprawl, finding that non-human identities including AI agents, service accounts, and API keys now outnumber human identities by more than 90 to 1 in many organizations, with some enterprises reporting ratios above 140 to 1, and that population grew by 44 percent in a single year. That is not a slow-moving trend security teams can plan around gradually, it is a population explosion that has already outpaced most non-human identity management] programs before they started.

Agents are borrowing identities that were never meant for them

The deeper problem is not just how many agents exist, it is what identity they are actually running under. CSA's research found that 52 percent of organizations rely on workload identities for their agents, 43 percent use shared service accounts, and 31 percent simply let agents operate under a human user's own credentials, meaning nearly a third of enterprises cannot even attribute an agent's actions to the agent itself. Nearly three-quarters of respondents, 74 percent, agreed that agents often receive more access than their task actually requires, and 79 percent said agents create new access pathways that are difficult to monitor. Perhaps most alarming, 81 percent agreed that prompt manipulation could cause an agent to reveal sensitive credentials or tokens outright, turning a routine conversation with an agent into a potential [credential exposure attack surface.

Compounding all of this is a governance gap most security teams have not caught up to yet. Broader CSA survey data found that 92 percent of organizations believe their legacy identity and access management tools cannot effectively manage the risks AI agents introduce, and 78 percent have no formally documented policy for creating or removing an agent's identity once it is no longer needed. Just over half, 51 percent, report no clear ownership or accountability for their AI and non-human identity population at all, which means when an agent starts behaving outside its original scope, there is often no one whose job it is to notice.

What breaks when zero trust does not extend to agents

The consequences of that gap are not theoretical. The OWASP Top 10 for Agentic Applications, a peer-reviewed framework built with more than 100 industry experts and released in December 2025, catalogs exactly how these gaps get exploited in practice, including memory and context poisoning that corrupts an agent's stored data to influence its future decisions, insecure communication between chained agents that enables spoofing, and what the framework calls rogue agents, compromised or misaligned systems that keep acting harmfully while still appearing legitimate.

The financial picture backs up why this matters to more than security teams. IBM's 2026 Cost of a Data Breach Report, produced with the Ponemon Institute, found that AI-driven attacks are climbing, led by AI-enabled malware and deepfake impersonation, alongside a new category of AI model inversion attacks that specifically target training data. The prior year's edition of the same report found that 97 percent of AI-related security breaches involved systems that lacked proper access controls in the first place, and that shadow AI, meaning AI tools running without any formal approval or governance, added as much as $670,000 to the average breach cost on its own.

The framework catching up building zero trust for agents

The good news is that the security community is not starting from zero. The Cloud Security Alliance's Agentic Trust Framework, published in February 2026, applies NIST's original zero trust principles directly to agent governance, treating every agent as a distinct, individually authenticated identity rather than a shared credential, scoping its access to the specific task at hand rather than a broad standing role, and continuously validating that access rather than granting it once and forgetting about it.

In practice, that shift looks like replacing static API keys with short-lived, workload-identity-federated tokens whose blast radius shrinks from days to minutes if leaked, and granting permissions just before an agent needs them rather than in advance. The gap this closes is real, separate CSA research found that only 28 percent of organizations can currently trace an agent's actions back to a specific accountable human sponsor across all of their environments, which means in nearly three-quarters of enterprises, an agent acting badly has effectively no owner to answer for it.

What this means for cyber resilience in 2026

If your organization is building or expanding agentic AI right now, the practical starting point is not a new tool, it is an inventory. You cannot apply zero trust principles to an agent identity you have not enumerated, and the data above suggests most enterprises have far more agents, service accounts, and inherited credentials running in production than anyone officially tracked. Once that inventory exists, the goal is matching the level of scrutiny to what each agent can actually do, an agent that only reads a public dashboard needs far less governance than one that can execute code, move money, or touch customer records, and treating every agent identically is itself a version of the same implicit trust zero trust was built to eliminate.

The organizations getting ahead of this in 2026 are treating AI agents the same way they would treat a new class of employee with root access and no manager, worthy of real identity, real scoped permissions, and real accountability, rather than a convenient extension of whatever human happened to set it up. Zero trust was never really about a single technology, it was about refusing to grant trust by default. That principle turns out to matter more, not less, now that some of the identities asking for access are not human at all.

Zero trust securityAI agent securityCyber resilience