Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
AI Agents Are Breaking Zero Trust Security, and Nobody Has Fixed It Yet

The government spent years building Zero Trust security on one simple idea: trust nobody, verify everything, give minimal access. Now that model is getting torn up, according to Douglas Cossa, chief information officer for the Intelligence Community.
Speaking Monday at the Defense Intelligence Agency's DoDIIS conference, Cossa said agentic AI, bots that operate on their own to complete tasks, needs the opposite of minimal access. It needs broad reach across data and systems to function.
"The challenge we have is that this new realm of AI has completely spun Zero Trust on its head," Cossa said, according to Breaking Defense. "We went from a model of least privileged access or no access to now giving an AI model and agent everything it needs to be operating independently."
There is currently no unified identity system across federal agencies to track what an AI agent is, who it's acting for, or what it should be allowed to touch, Cossa said. His office is building one, with pilots planned for this fall heading into fiscal 2027.
The Access Problem Is Already Costing Money
IBM's Cost of a Data Breach Report 2026 found the global average cost of a breach hit $4.99 million this year, a 12% jump and a record high, according to Forcepoint's writeup of the findings. IBM's own researchers pointed directly at agentic AI rollouts happening faster than governance can keep up.
The distinction matters. A chatbot that gets manipulated produces a bad answer. An AI agent with database and API access that gets manipulated executes a bad outcome before any human sees it, Forcepoint noted. That is the difference between output risk and action risk, and most companies are still applying old chatbot-era controls to agents that can actually take action.
A global survey of 1,350 security and IT decision-makers by Arctic Wolf, reported by Corporate Compliance Insights, backs this up with numbers. Only 53% of security leaders trust AI to do narrow tasks like blocking a malicious IP address. That confidence drops to about 40% for patching known vulnerabilities and under 30% for letting AI dismiss alerts on its own. Just 14% have made AI central to their security strategy, even though 94% of organizations already use large language models somewhere in their stack.
Security leaders aren't being irrational here. More than a third, 35%, now name AI itself as their single biggest cybersecurity risk, ahead of ransomware and malware for the second year running, according to the Arctic Wolf data. You're handing autonomous systems real permissions before anyone has agreed on how to audit them.
Industry Is Racing to Write the Rules
A new industry group called the Agentic SOC Alliance launched ahead of Black Hat USA 2026 with 15 founding members, including CrowdStrike, ExtraHop, TENEX.AI, Torq, Dropzone AI and LangChain, according to Forbes. Their goal is stopping what Forbes contributor Ron Schmelzer called "agent washing," where vendors slap the term "Agentic SOC" on everything from simple alert summarizers to systems that take live action in production environments, with zero standard way to tell the difference.
Separately, the Linux Foundation's Open Secure AI Alliance, now more than 120 organizations including NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat, released a Request for Comments this week on what it's calling the Shared AI Findings Exchange, or SAFE. The idea is to let companies confidentially share agentic AI incidents and near-misses so the whole industry learns from each failure instead of everyone getting burned separately, NVIDIA said in its announcement.
NVIDIA is also pushing its own technical fixes: an open-source runtime called OpenShell that restricts what an agent can see and do, and signed "agent skill" packages that are scanned for prompt injection risks before deployment.
Microsoft, meanwhile, is expanding its Zero Trust for AI framework with a new assessment tool and a DevSecOps security pillar, building on an announcement it made at RSA Conference 2026. KuppingerCole named Microsoft the top overall leader in Zero Trust platforms this year, according to Microsoft's own announcement.
What Nobody Has Solved Yet
Every one of these initiatives, from the IC's identity pilot to the Agentic SOC Alliance to SAFE, is still in the proposal or early pilot stage. None of them are deployed at scale. The federal government doesn't have its unified identity system yet. Cossa said testing starts this fall.
Okta's federal CSO Sean Frazier and Defense Logistics Agency AI Officer Ruksana Lodi are set to discuss, in a upcoming govciomedia session, how agencies are trying to fold AI agents, applications and machines into one identity architecture, following a White House directive pushing agencies toward continuous, threat-driven security instead of just checking compliance boxes.
The open question is whether any of this catches up before agentic AI gets baked into critical infrastructure at scale. IBM's $4.99 million average breach cost is already a lagging indicator of gaps that industry groups formed this month to fix. Whether the Agentic SOC Alliance's three-layer testing framework or the Linux Foundation's incident-sharing proposal actually slows that number down won't be clear until next year's breach report.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.