Defining AI Agent Security and Zscaler’s New Platform
AI agent security is the practice of controlling how autonomous software agents connect to systems, access data, and act on behalf of users so they cannot bypass enterprise governance, compliance, or Zero Trust controls as they operate at machine speed. Zscaler’s latest release extends its Zero Trust Exchange platform to this rapidly expanding “agentic” layer by securing how AI agents talk to tools and services, how they exercise permissions, and how they run on endpoints. Traditional identity and access tools expect known human users and predictable sessions; agentic AI breaks those assumptions with ephemeral identities, spawned sub-agents, and constant, automated requests. Zscaler responds with an AI Broker for mediated access, Endpoint AI Security for local threats, and an AI Access Graph to map identities, data, and models. Together, these pieces aim to close visibility and governance gaps before autonomous agents become an unchecked shadow layer inside enterprise IT.
Extending Zero Trust AI to Agentic Communications
Zscaler’s AI Broker puts a Zero Trust AI control point in the middle of MCP and agent-to-agent (A2A) traffic, the channels that tie agents to tools, APIs, and each other. By inserting policy-aware mediation into these broker paths, organizations can apply fine-grained access decisions to every AI request instead of granting broad, static permissions. An integrated Agent Registry records which agents exist, who owns them, and what each is allowed to use, which directly supports agentic AI governance. This registry also provides the baseline for consistent AI agent security policies across cloud and on-premises environments. Instead of relying on informal configuration files or ad hoc scripts, security teams gain a central place to approve, restrict, or decommission agents. In effect, Zscaler is turning previously opaque AI agent meshes into governed, auditable Zero Trust AI fabrics where every interaction can be monitored and constrained.
Endpoint AI Security: Closing the Local Blind Spot
While AI Broker handles upstream communications, Endpoint AI Security tackles the growing risk at the device layer, where many AI experiments start without formal oversight. Zscaler notes that AI is increasingly embedded in browsers, plugins, extensions, and local tools that legacy endpoint products often miss. Endpoint AI Security inspects those layers directly, giving security teams visibility into which AI components are installed, how they interact with data, and whether they introduce new attack paths. According to Zscaler, these capabilities mean policies can now cover “AI everywhere including endpoint and cloud,” aligning endpoint behavior with enterprise AI compliance requirements. For IT leaders trying to enforce Zero Trust AI, this closes a major gap: agents and tools that run locally but connect to sensitive SaaS or internal systems. With monitoring and blocking at the endpoint, organizations can prevent unauthorized data flows before they leave the device or reach external AI models.
AI Access Graph and AI Protect: Governance for Data and Identities
Governance over agentic AI depends on seeing who talks to what, and with which permissions. Zscaler’s AI Access Graph, built from technology acquired with Symmetry Systems, maps the relationships between users, AI agents, applications, models, and data sources. This map shows how identities and data move across the enterprise so teams can remove unnecessary access and track data lineage in real time. On top of this, Zscaler has expanded AI Protect—its broader AI security suite—across asset management, secure access, and protected infrastructure. New AI Asset Management functions discover embedded AI in SaaS traffic, locate AI agents and MCP servers in public cloud, scan codebases for agentic risks, and extend visibility to endpoints. Secure access controls add prompt extraction and full conversational views across more than 250 generative AI apps with support for Anthropic and OpenAI compliance APIs, strengthening enterprise AI compliance controls for both sanctioned and emerging tools.
Addressing the Governance Gap in Rapid AI Agent Adoption
The strategic backdrop for these launches is an adoption curve that has outpaced control frameworks. Enterprises are widely deploying AI agents that can chain tasks, act continuously, and interact with sensitive systems without constant human oversight. Traditional security stacks struggle to log, analyze, or constrain this behavior. Microsoft research cited by Zscaler shows that 84 percent of senior leaders see unsanctioned agents as a growing security risk, underscoring the governance gap. Zscaler aims to close that gap by tying together endpoint controls, AI-specific brokers, and a unified access graph into a single AI agent security platform. For IT and security leaders, the promise is consistent agentic AI governance: every agent registered, every interaction logged, every permission revocable, and every data flow traceable. If effective, this Zero Trust AI model could prevent the silent spread of over-privileged agents while allowing enterprises to keep experimenting with autonomous systems safely.






