TL;DR: Traditional Zero Trust frameworks were built for human users and static systems, but AI agents move across platforms, handle sensitive data in seconds, and can outpace controls that rely on identity checks alone, according to Cyera. Data-centric enforcement is now the practical boundary because access governance at human speed cannot reliably govern machine-speed behaviour.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “Rethinking Zero Trust in the Age of AI: Why Following the Data Is the New Trust Boundary”.
Key questions
Q: What breaks when Zero Trust is applied to AI systems using human-centric controls?
A: Human-centric Zero Trust breaks when the actor can move across platforms, access sensitive data, and take actions faster than identity checks, device trust, and manual review can keep up.
Q: Why do AI agents push security teams toward data-centric enforcement?
A: AI agents move, transform, and share information across tools, so the practical control point becomes the data itself.
Q: How should security teams limit the risk from AI agents that have access to production systems?
A: Security teams should scope every agent to the smallest set of actions and resources needed for its task, then remove standing privilege wherever possible.
Practitioner guidance
- Map sensitive data flows for AI use cases Identify where AI systems ingest, transform, and export sensitive information across cloud, SaaS, and internal workflows.
- Define least-agency constraints for AI systems Document which actions an AI system may take, not just which datasets it may reach.
- Classify and monitor data touched by AI tools Apply data classification and monitoring to every AI-connected tool, including embedded SaaS features and internally developed assistants.
Bottom line: AI changes Zero Trust because the actor can cross systems and act faster than identity-first controls can evaluate those actions.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Zero Trust for AI becomes a data governance problem before it becomes an access problem. The article is right to move the trust boundary away from the identity layer and toward the data layer. AI systems can cross application boundaries, transform content, and trigger downstream actions faster than human-paced access governance can meaningfully intervene. The implication is that security programmes built only on user-style access checks will miss the real control plane.
A few things that frame the scale:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations treat Zero Trust for AI as a separate control model?
A: Organisations should treat Zero Trust for AI as an adaptation of the same governance discipline, not a separate philosophy. The difference is that AI requires the trust boundary to follow the data and the permitted action set, while traditional Zero Trust is usually anchored more heavily to identity and device posture.
👉 Read our full editorial: Zero trust for AI fails when data becomes the trust boundary