Glossary · term

Agentic zero trust

Agentic zero trust applies zero-trust security principles to AI agents that can select tools and perform multi-step actions. It treats each agent as a governed non-human actor with an accountable owner, an explicit purpose, scoped authority and lifecycle-managed credentials. Access is evaluated against identity, delegation, task and context at relevant control points; authentication at session start is not a blanket grant for every later tool call or data access.

Safety2025-11-05Wave 3 · 2025–26Maturity: 3/5

Origin and context

Microsoft used the exact label publicly in November 2025. In 2026, NIST's NCCoE framed open questions around agent identification, authentication, least privilege, dynamic context, delegated authority and verifiable logs. CoSAI called for adapting zero trust through agent-function segmentation, continuous behavior monitoring and authority checks. Cisco and Cequence then published enterprise architectures, while research prototypes explored task-based access and hybrid deterministic and semantic inspection.

Sources: s1, s2, s3, s4, s5, s6

Why it matters

An agent may inherit a user's powerful credentials, combine data across systems, call changing tool sets and continue acting after the initiating prompt. Ordinary login success says little about whether its next action serves the delegated task. Agentic zero trust makes that gap explicit: inventory the actor, bind it to an owner and mandate, minimize reachable resources, evaluate requests at enforcement points, log decisions, and revoke authority. This can limit blast radius, but only when policies, identities and enforcement are themselves correct and protected.

Sources: s2, s3, s4, s5, s6

Example

A reporting agent may be allowed to read quarterly sales tables but not payroll data or payment APIs. Its short-lived credential can carry the user's delegation and the agent's narrower task scope; a gateway checks each requested tool and dataset, records the decision and blocks scope expansion. That design demonstrates bounded authorization, not that the report is accurate or the agent cannot assemble a harmful sequence from individually permitted actions.

Sources: s2, s4, s5, s6

How it differs

Security Considerations for AI Agents

General agent-security guidance covers model, prompt, memory, supply-chain, tool and operational risks. Agentic zero trust is the narrower identity, authority, access and enforcement lens within that wider security program.

OWASP Top 10 for Agentic Applications 2026

OWASP's list is a risk taxonomy. Agentic zero trust is a control architecture that may mitigate parts of several risks but is neither the list itself nor a complete response to every listed failure mode.

Agent delegation chain

A delegation chain records how authority passes among people and agents. Agentic zero trust uses that evidence when deciding access, but also requires policy, enforcement, credential lifecycle, monitoring and revocation.

Maturity and evidence

Maturity is rated 3. The exact label appears across independent security organizations, and authoritative NIST work validates the identity and authorization problem even without adopting the term. Core practices converge, and commercial and research architectures exist. There is no single normative specification, conformance test or mature comparative evidence base; terminology and implementation boundaries continue to change, so maturity 4 would imply more stabilization than the sources support.

Sources: s1, s2, s3, s4, s5, s6

Limits and open questions

Zero trust is a design approach, not automatic protection. Weak identity proofing, excessive scopes, stale inventories, compromised policy engines, shared secrets, missing enforcement points or incomplete logs can preserve the original risk. Individually authorized calls can compose into an unsafe trajectory, and semantic intent checks can be evaded or mistaken. The approach does not by itself stop prompt injection, poisoned tools, model misbehavior or insider abuse. Validate claims per architecture and do not infer compliance, certification or safety from the label.

Sources: s2, s3, s4, s5, s6

Related terms

References

Last updated: 2026-09-07