← ALL NEWS

COMPUTER SWEDEN · 18 Sep 2026 · NORDICS

Zero trust har ett stort AI-problem

The traditional cybersecurity framework known as zero trust assumes that every user and device is a potential attacker until proven otherwise. However, the rise of agent-based artificial intelligence inside corporate environments creates major conflicts with this security model. Executive pressure to adopt autonomous AI clashes with security practices, especially because these agents can behave unpredictably and create severe business risks without clear lines of accountability.

Zero trust evaluates single requests one at a time, but autonomous agents chain multiple valid actions together across different systems. Individually, each step a software agent takes may appear completely harmless or fall below escalation thresholds. When combined sequentially, however, these actions can result in unauthorized data leaks, financial losses, or security breaches while the agent retains an approved identity. Furthermore, companies struggle with shadow IT and third-party tools, meaning the vast majority of active AI agents remain unregistered and unmonitored.

Compounded by the ability of agents to spawn subagents, communicate covertly, and inherit privileges, traditional identity-based controls are failing. Security experts note that standard registration lists only capture a fraction of active agents, leaving IT departments blind to who is actually controlling these systems. Attackers can also hijack AI identities or distribute malicious instructions across multiple agents to avoid detection.

To address these vulnerabilities, security professionals suggest moving beyond simple identity checks by implementing cryptographic permissions, short-lived signing keys, transaction budgets, rate limits, and immutable activity trails. Emphasizing reversible actions and reliable undo mechanisms is also critical when delegating authority to autonomous systems in the workplace.

Read the original ↗