By NHI Mgmt Group Editorial TeamBased on Cyera: “Rethinking Zero Trust in the Age of AI: Why Following the Data Is the New Trust Boundary” (November 25, 2025)

TL;DR: Traditional Zero Trust frameworks were built for human users and static systems, but AI agents move across platforms, handle sensitive data in seconds, and can outpace controls that rely on identity checks alone, according to Cyera. Data-centric enforcement is now the practical boundary because access governance at human speed cannot reliably govern machine-speed behaviour.


At a glance

What this is: This is an analysis of why Zero Trust for AI needs to move from identity-first controls to data-centric enforcement as AI systems outpace human-speed governance.

Why it matters: IAM, NHI, and AI governance teams need to account for AI agents and other non-human actors that can access and transform sensitive data faster than traditional access reviews and device-centric controls can keep up.


Context

Zero Trust assumes identity, device, and privilege controls can be enforced quickly enough to govern access decisions. That model weakens when AI systems and agents cross environments, touch sensitive data, and take actions at a pace that makes human-centric review cycles too slow to matter.

For IAM and NHI teams, the problem is not that Zero Trust is obsolete. The problem is that the trust boundary shifts when the actor is not a person and the control point has to follow the data rather than the login event. This article is about that governance mismatch.


Key questions

Q: What breaks when Zero Trust is applied to AI systems using human-centric controls?

A: Human-centric Zero Trust breaks when the actor can move across platforms, access sensitive data, and take actions faster than identity checks, device trust, and manual review can keep up. The failure is not authentication alone. It is that the control boundary assumes a human-paced decision loop while AI can complete the relevant behaviour before governance catches up.

Q: Why do AI agents push security teams toward data-centric enforcement?

A: AI agents move, transform, and share information across tools, so the practical control point becomes the data itself. Data-centric enforcement matters because it lets teams govern classification, context, and allowed use at the point where sensitive content is actually handled, instead of relying only on identity decisions made earlier in the session.

Q: How should security teams limit the risk from AI agents that have access to production systems?

A: Security teams should scope every agent to the smallest set of actions and resources needed for its task, then remove standing privilege wherever possible. Use short-lived credentials, explicit approval for sensitive actions, and continuous review of what each identity can reach. The goal is to make compromise hard to turn into lateral movement or data exfiltration.

Q: Should organisations treat Zero Trust for AI as a separate control model?

A: Organisations should treat Zero Trust for AI as an adaptation of the same governance discipline, not a separate philosophy. The difference is that AI requires the trust boundary to follow the data and the permitted action set, while traditional Zero Trust is usually anchored more heavily to identity and device posture.


Technical breakdown

Why identity-first Zero Trust weakens for AI systems

Traditional Zero Trust treats identity proofing, device trust, and least privilege as the primary enforcement points. That works when subjects are people or stable systems with predictable access patterns. AI systems are different because they can move between applications, trigger workflows, and handle data in ways that are not fixed at provisioning time. The control problem is not just authentication. It is that authorisation becomes a runtime governance problem when the actor can act, re-route, and transform data within the same session. Practical implication: identity checks alone are not sufficient when the actor's behaviour changes faster than policy review.

Practical implication: shift control design from static access decisions toward runtime data governance.

How data-centric enforcement changes the trust boundary

Data-centric enforcement moves the boundary from the user or agent to the information being accessed, transformed, or shared. In practice, that means security controls need to understand classification, context, lineage, and permitted use at the data layer. This is especially important for AI because the same system may ingest, summarise, copy, or transmit sensitive content across several tools in seconds. The relevant question becomes not only who accessed the system, but what data moved, where it went, and whether that movement matched policy. Practical implication: the governance object becomes the data flow, not the login session.

Practical implication: instrument sensitive data flows so policy follows the content across systems.

Why least agency matters alongside least privilege

The article cites OWASP guidance around 'least agency', which is a useful distinction for AI governance. Least privilege limits what an actor can access, but least agency also limits what the actor can choose to do. That matters for AI systems and agents that can send emails, modify files, or initiate workflows with minimal oversight. In those cases, an access model that only controls datasets will still miss risky actions. The governance challenge is to constrain both data exposure and action scope. Practical implication: review whether your policies govern only access rights, or also the actions an AI system is allowed to take.

Practical implication: pair access controls with explicit action constraints for AI systems and agents.


NHI Mgmt Group analysis

Zero Trust for AI becomes a data governance problem before it becomes an access problem. The article is right to move the trust boundary away from the identity layer and toward the data layer. AI systems can cross application boundaries, transform content, and trigger downstream actions faster than human-paced access governance can meaningfully intervene. The implication is that security programmes built only on user-style access checks will miss the real control plane.

Least privilege is necessary but no longer sufficient when the subject can act at machine speed. Least privilege was designed for relatively stable access relationships. AI systems introduce dynamic behaviour, which means privilege at provisioning time does not fully describe what the actor will do at runtime. That makes data lineage, content sensitivity, and allowed action scope first-class governance concerns for NHI and AI security teams.

Least agency is the more precise control concept for AI than identity-centric Zero Trust alone. The article usefully surfaces the gap between access rights and action rights. An AI system that can send emails, modify files, or start workflows has more operational power than traditional identity controls assume. Practitioners should treat permitted action scope as part of the trust boundary, not a downstream detail.

Data-centric enforcement creates a better operational model for autonomous systems, but it also changes the governance unit. Security teams are no longer just certifying who should have access. They are governing what data can be touched, how it can be transformed, and what downstream use remains acceptable. That is a structural shift in identity governance, not a cosmetic update to Zero Trust language.

Following the data is a named concept worth preserving: trust follows content, not session state. That phrase captures the article's core architectural claim. When AI can move faster than human review, trust anchored to the session, device, or identity record degrades quickly. Practitioners should recognise that the enforceable boundary is the sensitive object itself and the policy attached to it.

From our research library:

What this signals

Following the data is the control shift that matters: programmes that still anchor Zero Trust mainly to identity and device posture will struggle to govern AI activity at machine speed. Security teams need to understand where sensitive data moves, because that is where policy has to live if controls are to keep pace with autonomous behaviour.

Zero Trust for AI is best treated as a governance redesign, not a product category. The practical question for practitioners is whether their current control set can constrain both access and action when the actor is an AI system rather than a person.


For practitioners

  • Map sensitive data flows for AI use cases Identify where AI systems ingest, transform, and export sensitive information across cloud, SaaS, and internal workflows. Use that map to decide where enforcement has to sit on the data path rather than only at authentication time.
  • Define least-agency constraints for AI systems Document which actions an AI system may take, not just which datasets it may reach. Include actions such as sending messages, modifying records, and initiating workflows, then treat those permissions as part of governance review.
  • Classify and monitor data touched by AI tools Apply data classification and monitoring to every AI-connected tool, including embedded SaaS features and internally developed assistants. Focus on whether policy can detect unauthorized movement, copying, or transformation of sensitive content.
  • Reassess Zero Trust assumptions for machine-speed actors Review whether your current Zero Trust design assumes a human-paced decision loop. If it does, update monitoring, policy enforcement, and approval logic so they can respond to AI behaviour in real time.

Key takeaways

  • AI changes Zero Trust because the actor can cross systems and act faster than identity-first controls can evaluate those actions.
  • Data-centric enforcement gives security teams a more reliable boundary by tying policy to sensitive content, movement, and use.
  • Least privilege still matters, but AI governance also needs least agency so actions are constrained alongside access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIAI systems acting as non-human identities can exceed intended access scope when controls lag runtime behaviour.
Recommendation — Limit AI system privileges to the minimum data and actions required for each use case.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI systems exceeding the identity and privilege assumptions Zero Trust depends on.
ASI09 — Human-Agent Trust ExploitationLeast agency and human oversight gaps are central to the trust problem described.
Recommendation — Constrain agent identity scope so runtime actions cannot exceed approved privilege boundaries. Limit human-facing trust assumptions by restricting what AI systems can ask users or do on their behalf.
NIST Zero Trust (SP 800-207)Continuous Monitoring — Continuous MonitoringThe article argues that verification and monitoring must move with AI behaviour in real time.
Recommendation — Apply continuous monitoring so policy decisions track AI behaviour as it changes.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article questions whether human-era entitlement models can govern machine-speed AI access.
Recommendation — Review entitlements for AI systems to ensure authorizations match actual runtime use.

Key terms

  • Data-centric zero trust: A zero trust model that treats the data itself as the primary control boundary. Rather than relying mainly on network location or device trust, it asks whether a subject, workload, or AI system should access specific data for a specific purpose under current policy.
  • Least Agency: The agentic equivalent of least privilege, the principle that AI agents should be granted only the minimum level of autonomy necessary to complete their designated task, and no more. Coined in the OWASP Top 10 for Agentic Applications 2026.
  • AI Security Posture Management: A governance approach for discovering and tracking AI assets such as models, agents, datasets, vector stores, and related infrastructure. It becomes useful only when inventory is connected to runtime exposure and the identity that can actually reach the data.
  • Runtime Data Governance: Runtime data governance is the enforcement of policy over data while it is being created, accessed, and transmitted in a live session. In the browser, this means controlling which scripts, agents, and page elements can interact with sensitive information, rather than depending only on backend controls or static consent settings.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org