Zero Trust for AI Agents: Understanding the Need for Visibility
The advent of artificial intelligence (AI) agents has revolutionized the way organizations approach automation, efficiency, and productivity. However, as AI agents continue to proliferate within enterprises, security teams are facing a new challenge: ensuring the visibility and control of these agents. A recent string of incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to examine whether speed has outpaced the ability to secure what gets deployed.
Research from Veeam reveals that 70% of organizations admit that AI workflows are already in contact with sensitive corporate data without full oversight in place, and 67% report that IT cannot fully track the autonomous workflows that employees are building. This has led to the emergence of 'Shadow AI,' which exemplifies how quickly and pervasively this fundamental first step can slip through one's grasp.
The concept of Zero Trust is gaining traction in the AI community, with some experts advocating for the implementation of Zero Trust principles as a means of supporting an AI governance program. However, this approach requires a fundamental shift in the order of operations, with inventory management taking precedence over enforcement controls and detections. As the article states, "You cannot govern what you cannot see," which highlights the importance of visibility in maintaining security.
The article highlights three key challenges to visibility in AI agents: the first being the issue of Shadow IT, where new technologies are adopted without adequate governance in place. The second challenge is the lack of a single camera that can take the full picture, as AI agents operate across various networks, endpoints, and SaaS-hosted platforms. The third challenge is the need for continuous monitoring, as traditional audits and monitoring are inadequate for maintaining visibility in AI agents.
The article concludes by emphasizing the importance of building continuous monitoring around every AI agent, with each agent holding its own identity. This requires a fundamental shift in the way organizations approach AI governance, with a focus on discovery, correlation, and runtime identity controls.