READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

AI Agents Are Breaking Zero Trust Security, and Nobody Has Fixed It Yet

AI Agents Are Breaking Zero Trust Security, and Nobody Has Fixed It Yet
The government's cybersecurity model was built to lock down people and devices, not autonomous AI agents that need broad access to do their jobs. Federal officials, tech giants, and 120-plus companies are now scrambling to build new identity and permission systems before agentic AI outruns the defenses meant to contain it. This is a real problem with real money behind it, not vendor hype.

The government spent years building Zero Trust security on one simple idea: trust nobody, verify everything, give minimal access. Now that model is getting torn up, according to Douglas Cossa, chief information officer for the Intelligence Community.

Speaking Monday at the Defense Intelligence Agency's DoDIIS conference, Cossa said agentic AI, bots that operate on their own to complete tasks, needs the opposite of minimal access. It needs broad reach across data and systems to function.

"The challenge we have is that this new realm of AI has completely spun Zero Trust on its head," Cossa said, according to Breaking Defense. "We went from a model of least privileged access or no access to now giving an AI model and agent everything it needs to be operating independently."

There is currently no unified identity system across federal agencies to track what an AI agent is, who it's acting for, or what it should be allowed to touch, Cossa said. His office is building one, with pilots planned for this fall heading into fiscal 2027.

The Access Problem Is Already Costing Money

IBM's Cost of a Data Breach Report 2026 found the global average cost of a breach hit $4.99 million this year, a 12% jump and a record high, according to Forcepoint's writeup of the findings. IBM's own researchers pointed directly at agentic AI rollouts happening faster than governance can keep up.

The distinction matters. A chatbot that gets manipulated produces a bad answer. An AI agent with database and API access that gets manipulated executes a bad outcome before any human sees it, Forcepoint noted. That is the difference between output risk and action risk, and most companies are still applying old chatbot-era controls to agents that can actually take action.

A global survey of 1,350 security and IT decision-makers by Arctic Wolf, reported by Corporate Compliance Insights, backs this up with numbers. Only 53% of security leaders trust AI to do narrow tasks like blocking a malicious IP address. That confidence drops to about 40% for patching known vulnerabilities and under 30% for letting AI dismiss alerts on its own. Just 14% have made AI central to their security strategy, even though 94% of organizations already use large language models somewhere in their stack.

Security leaders aren't being irrational here. More than a third, 35%, now name AI itself as their single biggest cybersecurity risk, ahead of ransomware and malware for the second year running, according to the Arctic Wolf data. You're handing autonomous systems real permissions before anyone has agreed on how to audit them.

Industry Is Racing to Write the Rules

A new industry group called the Agentic SOC Alliance launched ahead of Black Hat USA 2026 with 15 founding members, including CrowdStrike, ExtraHop, TENEX.AI, Torq, Dropzone AI and LangChain, according to Forbes. Their goal is stopping what Forbes contributor Ron Schmelzer called "agent washing," where vendors slap the term "Agentic SOC" on everything from simple alert summarizers to systems that take live action in production environments, with zero standard way to tell the difference.

Separately, the Linux Foundation's Open Secure AI Alliance, now more than 120 organizations including NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat, released a Request for Comments this week on what it's calling the Shared AI Findings Exchange, or SAFE. The idea is to let companies confidentially share agentic AI incidents and near-misses so the whole industry learns from each failure instead of everyone getting burned separately, NVIDIA said in its announcement.

NVIDIA is also pushing its own technical fixes: an open-source runtime called OpenShell that restricts what an agent can see and do, and signed "agent skill" packages that are scanned for prompt injection risks before deployment.

Microsoft, meanwhile, is expanding its Zero Trust for AI framework with a new assessment tool and a DevSecOps security pillar, building on an announcement it made at RSA Conference 2026. KuppingerCole named Microsoft the top overall leader in Zero Trust platforms this year, according to Microsoft's own announcement.

What Nobody Has Solved Yet

Every one of these initiatives, from the IC's identity pilot to the Agentic SOC Alliance to SAFE, is still in the proposal or early pilot stage. None of them are deployed at scale. The federal government doesn't have its unified identity system yet. Cossa said testing starts this fall.

Okta's federal CSO Sean Frazier and Defense Logistics Agency AI Officer Ruksana Lodi are set to discuss, in a upcoming govciomedia session, how agencies are trying to fold AI agents, applications and machines into one identity architecture, following a White House directive pushing agencies toward continuous, threat-driven security instead of just checking compliance boxes.

The open question is whether any of this catches up before agentic AI gets baked into critical infrastructure at scale. IBM's $4.99 million average breach cost is already a lagging indicator of gaps that industry groups formed this month to fix. Whether the Agentic SOC Alliance's three-layer testing framework or the Linux Foundation's incident-sharing proposal actually slows that number down won't be clear until next year's breach report.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
Breaking DefenseAgentic AI turning Zero Trust cybersecurity ‘on its head’
center
ForbesAgentic SOC Alliance Wants To Set Rules For AI Cyber Defense
unknown
blogs.nvidiaAI Leaders Propose SAFE Guidelines for Cybersecurity Transparency
unknown
corporatecomplianceinsightsCyber Leaders Wary of Giving Agentic AI Too Much Authority
unknown
microsoftAdvance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps | Microsoft Security Blog
unknown
govciomediaHow Federal Agencies Are Securing Agentic AI with Identity and Zero Trust
unknown
forcepointTreat Every AI Agent Like a Privileged Human Account