MilikMilik

Zscaler Targets Agentic AI Governance Gap With Zero Trust Platform

Zscaler Targets Agentic AI Governance Gap With Zero Trust Platform
Interest|High-Quality Software

Agentic AI Security Moves to the Zero Trust Front Line

Agentic AI security refers to the controls, monitoring, and governance that keep autonomous AI agents from misusing identities, tools, or data as they act on behalf of humans and systems. Zscaler is bringing this problem into focus by extending its Zero Trust Exchange to secure how AI agents connect, what they access, and where they run. The company argues that security is shifting from human users to software agents that create ephemeral identities, spawn sub-agents, and act at machine speed, far beyond the assumptions built into older tools. This shift has widened a governance gap as organizations deploy AI agents faster than they can control them. Zscaler’s response is a set of interconnected capabilities that treat agents as first-class subjects in a zero trust AI model, with policy-driven access, continuous inspection, and detailed visibility into every interaction.

AI Broker, Endpoint AI Security, and the New Agent Perimeter

Zscaler’s AI Broker is the centerpiece of its zero trust AI agents strategy. It secures agentic communications across MCP and A2A brokers, the emerging connective tissue between agents, tools, and services. An integrated Agent Registry tracks which agents exist, what they are allowed to access, and applies fine-grained policies across enterprise AI agents. Alongside this, Endpoint AI Security tackles threats on employee devices, aiming at blind spots in browsers, extensions, plugins, and local AI tools that legacy endpoint products often ignore. Together, these services create a new perimeter that follows the agent rather than the network, enforcing enterprise AI security policies wherever agents run or connect. For IT and security teams, this means an auditable way to let agents act on behalf of users without giving them unchecked access to sensitive systems or data.

AI Access Graph: Mapping Identities, Data, and Agent Behavior

Governance for zero trust AI agents depends on clear visibility, which is where Zscaler’s AI Access Graph comes in. Built on technology acquired from Symmetry Systems, it maps how identities, applications, models, and data sources link together across the enterprise. By integrating this graph into the Zero Trust Exchange, security teams can see which users and agents talk to which models and datasets, and through which applications. That visibility supports tighter controls and continuous AI governance: policies can be enforced to reduce unnecessary access, while data lineage can be tracked in real time across every channel. According to Microsoft research cited by Zscaler’s announcement, 84 percent of senior leaders see unsanctioned agents as a growing security risk, which underlines the need for a unified AI governance platform that exposes hidden agent interactions instead of leaving them scattered and opaque.

AI Protect Expansion: From Asset Discovery to Red Teaming

Zscaler is also expanding AI Protect, turning it into a broader AI governance platform. In AI asset management, new features discover embedded AI inside SaaS and internet traffic, identify AI agents and MCP servers in public clouds, scan agentic codebases for risk, and extend visibility to AI activity on endpoints. For secure access to AI, the platform now performs prompt extraction across more than 250 generative AI apps, adds full conversational views, and supports Anthropic and OpenAI compliance APIs, allowing intent-based guardrails on multi-turn conversations. On the infrastructure side, Zscaler has added AI red teaming for MCP servers, a standalone prompt-hardening service, and compliance heat maps so teams can manage enterprise AI security from build to runtime. The result is a layered approach that links discovery, control, and testing into a single operational workflow.

Closing the Governance Gap for SMEs and Large Enterprises

The speed of agent deployment is outpacing governance, especially for SMEs and large enterprises that lack centralized control over AI experiments. AI agents can appear inside workflows, SaaS tools, or browser extensions without formal review, often with excessive permissions or unknown origins. Zscaler’s latest release aims to close this gap by extending zero trust principles to every agent, endpoint, and data path. For SME IT leaders, the value lies in gaining a single view of AI assets and enforcing consistent policies without building a custom stack. For larger enterprises, the platform’s data-aware AI access graph, endpoint coverage, and brokered agent control promise a way to scale agentic AI security without slowing innovation. The strategic idea is clear: treat agents like powerful, automated users that must earn access on each request, with their actions logged and governed end to end.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!