<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/zero-trust-has-a-big-ai-agent-problem-ahead-foz6sfjs2" -->

---
title: Zero trust has a big AI agent problem ahead | daily.dev
description: Security experts argue that zero trust architecture is fundamentally at odds with agentic AI in enterprise environments. Autonomous agents chain together...
canonical: https://daily.dev/posts/zero-trust-has-a-big-ai-agent-problem-ahead-foz6sfjs2
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Zero trust has a big AI agent problem ahead | daily.dev
og:description: Security experts argue that zero trust architecture is fundamentally at odds with agentic AI in enterprise environments. Autonomous agents chain together...
og:url: https://daily.dev/posts/zero-trust-has-a-big-ai-agent-problem-ahead-foz6sfjs2
og:image: https://api.daily.dev/og/posts/foZ6sFjs2.png
og:image:alt: Zero trust has a big AI agent problem ahead
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Zero trust has a big AI agent problem ahead

**[CSO Online](https://daily.dev/sources/csoonline)** · 7 min read · 0 upvotes · 0 comments

## Summary

Security experts argue that zero trust architecture is fundamentally at odds with agentic AI in enterprise environments. Autonomous agents chain together individually-authorized actions into unauthorized outcomes, spawn subagents without recognized identities, and can be hijacked to leak instructions across agent-to-agent communications that no vendor can currently inspect. Most agents in enterprises are unregistered shadow IT, making identity-based governance an inventory of a compliant minority rather than real control. Proposed mitigations include GPG-style delegated short-lived credentials, spend/rate limits, sandboxing, approval gates for irreversible actions, and immutable activity trails, though experts remain skeptical that full agent-to-agent visibility is achievable.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4215449/zero-trust-has-a-big-ai-agent-problem-ahead.html>

## Questions this post answers

### why doesn't zero trust security work well with autonomous AI agents

Zero trust evaluates each request independently, but agents chain many individually-authorized actions into outcomes nobody approved, like reading a document, querying a source, summarizing it, and emailing it externally, each step legal alone but together an exfiltration path. Agents can also spawn subagents that inherit privileges without a recognized identity, and updates to a model, tools, or memory can change what an approved identity actually does without triggering re-approval.

_Anyone rethinking identity governance for AI agents can follow how these risks evolve on daily.dev._

### what percentage of AI agents in enterprise environments are unregistered shadow IT

Roughly 80% of agents running in enterprise environments are not registered with IT or security teams, according to Krti Tallam of Kamiwaza.ai. This means governance models built around an approved-agent inventory only account for a compliant minority, leaving most agent activity effectively invisible to security teams and undermining identity-based access controls.

_Security teams tracking agent sprawl can stay current on emerging AI identity risks via daily.dev._

### how can enterprises safely delegate credentials to AI agents and subagents

One proposed model, from Mike Wilkes of Aikido Security, borrows from GPG/OpenPGP: a user keeps a strongly protected primary identity and delegates limited, short-lived signing subkeys or signed credentials to an agent, with even narrower delegated credentials for subagents. Pair this with rate limits, spend and data budgets, sandboxing, approval gates for irreversible actions, and immutable activity trails, reserving full autonomy for reversible decisions only.

_Teams designing agent credential delegation can track practical approaches like this on daily.dev._

## Similar posts on daily.dev

- [Zero Trust for Agentic AI: Safeguarding your Digital Workforce](https://daily.dev/posts/zero-trust-for-agentic-ai-safeguarding-your-digital-workforce-qon3brk1z) · Cisco · 1 upvotes · 0 comments
- [Zero Trust in the Age of AI: Why the Classic Model Isn’t Enough Anymore](https://daily.dev/posts/zero-trust-in-the-age-of-ai-why-the-classic-model-isn-t-enough-anymore-j66ljlvyr) · Security Boulevard · 1 upvotes · 0 comments
- [The agentic blind spots in your zero trust program](https://daily.dev/posts/the-agentic-blind-spots-in-your-zero-trust-program-aic8yqwgr) · CSO Online · 0 upvotes · 0 comments
- [The Agent Trust gap: What Our Research Reveals About Agentic AI Security](https://daily.dev/posts/the-agent-trust-gap-what-our-research-reveals-about-agentic-ai-security-drhloeayz) · Cisco · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cloud](https://daily.dev/tags/cloud), [#ai-agents](https://daily.dev/tags/ai-agents), [#agentic-ai](https://daily.dev/tags/agentic-ai)

[View this post on daily.dev](https://daily.dev/posts/zero-trust-has-a-big-ai-agent-problem-ahead-foz6sfjs2)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Zero trust has a big AI agent problem ahead","url":"https://daily.dev/posts/zero-trust-has-a-big-ai-agent-problem-ahead-foz6sfjs2","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/zero-trust-has-a-big-ai-agent-problem-ahead-foz6sfjs2"},"datePublished":"2026-09-03T08:27:57.855Z","dateModified":"2026-09-03T08:34:07.566Z","description":"Security experts argue that zero trust architecture is fundamentally at odds with agentic AI in enterprise environments. Autonomous agents chain together...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b07b992d6b98b89e3bde258bf15ee4de?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b07b992d6b98b89e3bde258bf15ee4de?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/zero-trust-has-a-big-ai-agent-problem-ahead-foz6sfjs2","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cloud,ai-agents,agentic-ai","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Zero trust has a big AI agent problem ahead"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/zero-trust-has-a-big-ai-agent-problem-ahead-foz6sfjs2#faq","mainEntity":[{"@type":"Question","name":"why doesn't zero trust security work well with autonomous AI agents","acceptedAnswer":{"@type":"Answer","text":"Zero trust evaluates each request independently, but agents chain many individually-authorized actions into outcomes nobody approved, like reading a document, querying a source, summarizing it, and emailing it externally, each step legal alone but together an exfiltration path. Agents can also spawn subagents that inherit privileges without a recognized identity, and updates to a model, tools, or memory can change what an approved identity actually does without triggering re-approval. Anyone rethinking identity governance for AI agents can follow how these risks evolve on daily.dev."}},{"@type":"Question","name":"what percentage of AI agents in enterprise environments are unregistered shadow IT","acceptedAnswer":{"@type":"Answer","text":"Roughly 80% of agents running in enterprise environments are not registered with IT or security teams, according to Krti Tallam of Kamiwaza.ai. This means governance models built around an approved-agent inventory only account for a compliant minority, leaving most agent activity effectively invisible to security teams and undermining identity-based access controls. Security teams tracking agent sprawl can stay current on emerging AI identity risks via daily.dev."}},{"@type":"Question","name":"how can enterprises safely delegate credentials to AI agents and subagents","acceptedAnswer":{"@type":"Answer","text":"One proposed model, from Mike Wilkes of Aikido Security, borrows from GPG/OpenPGP: a user keeps a strongly protected primary identity and delegates limited, short-lived signing subkeys or signed credentials to an agent, with even narrower delegated credentials for subagents. Pair this with rate limits, spend and data budgets, sandboxing, approval gates for irreversible actions, and immutable activity trails, reserving full autonomy for reversible decisions only. Teams designing agent credential delegation can track practical approaches like this on daily.dev."}}]}
```

