Published May 31, 2026 | Version v1

Zero Trust for Fallible Agents: Why AI Belongs Inside the ZTA Control Model

  • 1. Ologos, LLC

Description

This paper argues that AI systems are a class of fallible enterprise actor and that Zero Trust Architecture (ZTA) is the appropriate control model for governing them. Drawing on NIST SP 800-207, the DoD Zero Trust Reference Architecture, and the CSA Agentic Trust Framework, the paper defines a seven-step Zero Trust control loop for AI – covering agent identity, just-in-time authorization, least privilege, continuous verification, observability, externalized policy enforcement, and revocation. A dedicated section addresses the adversarial case: insider threat amplified by AI capability, prompt injection, and model supply chain risk. The paper concludes with a risk-scaled governance model distinguishing low, moderate, and high-risk AI use cases, and a treatment of task-relative reliability as the appropriate evaluation standard for AI in enterprise environments. Intended audience: enterprise IT architects, security architects, and AI governance practitioners in regulated and defense-adjacent environments.

Files

PDF-zero-trust-fallible-agents.pdf

Files (518.8 kB)

Name Size Download all
md5:627be36cdf6cedc789aa6370a7f833f3
518.8 kB Preview Download