Join our Newsletter — 33% off our NHI Course

Zero trust for AI and data-centric control - are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Traditional Zero Trust frameworks were built for human users and static systems, but AI agents move across platforms, handle sensitive data in seconds, and can outpace controls that rely on identity checks alone, according to Cyera. Data-centric enforcement is now the practical boundary because access governance at human speed cannot reliably govern machine-speed behaviour.

Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “Rethinking Zero Trust in the Age of AI: Why Following the Data Is the New Trust Boundary”.

Key questions

Q: What breaks when Zero Trust is applied to AI systems using human-centric controls?

A: Human-centric Zero Trust breaks when the actor can move across platforms, access sensitive data, and take actions faster than identity checks, device trust, and manual review can keep up.

Q: Why do AI agents push security teams toward data-centric enforcement?

A: AI agents move, transform, and share information across tools, so the practical control point becomes the data itself.

Q: How should security teams limit the risk from AI agents that have access to production systems?

A: Security teams should scope every agent to the smallest set of actions and resources needed for its task, then remove standing privilege wherever possible.

Practitioner guidance

  • Map sensitive data flows for AI use cases Identify where AI systems ingest, transform, and export sensitive information across cloud, SaaS, and internal workflows.
  • Define least-agency constraints for AI systems Document which actions an AI system may take, not just which datasets it may reach.
  • Classify and monitor data touched by AI tools Apply data classification and monitoring to every AI-connected tool, including embedded SaaS features and internally developed assistants.

Bottom line: AI changes Zero Trust because the actor can cross systems and act faster than identity-first controls can evaluate those actions.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 2 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21366
 

Zero Trust for AI becomes a data governance problem before it becomes an access problem. The article is right to move the trust boundary away from the identity layer and toward the data layer. AI systems can cross application boundaries, transform content, and trigger downstream actions faster than human-paced access governance can meaningfully intervene. The implication is that security programmes built only on user-style access checks will miss the real control plane.

A few things that frame the scale:

  • 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should organisations treat Zero Trust for AI as a separate control model?

A: Organisations should treat Zero Trust for AI as an adaptation of the same governance discipline, not a separate philosophy. The difference is that AI requires the trust boundary to follow the data and the permitted action set, while traditional Zero Trust is usually anchored more heavily to identity and device posture.

👉 Read our full editorial: Zero trust for AI fails when data becomes the trust boundary


This post was modified 2 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.