AIToday
AI Safety & AlignmentLarge Language ModelsVentureBeat AIPublished: Jul 17, 2026, 04:00 JST2 min read

Zero trust security must shift to real-time for AI agents

Key takeaway

  • Enterprise security leaders must adopt zero trust architecture immediately for AI agents rather than treating it as a long-term initiative, according to Ping Identity's CEO.

  • The speed and scale of agentic AI—thousands of agents making thousands of access requests—has compressed the security risk timeline, making real-time permission verification essential to prevent exposure from accumulated access grants that appear routine in isolation.

3 Key Points

  1. What happened

    Andre Durand, CEO of Ping Identity, argues that enterprises must now treat zero trust security—a model requiring continuous verification rather than a single login check—as an immediate requirement for AI agents, not a future goal. Agentic AI has compressed the risk timeline, demanding permission decisions be evaluated in real time.

  2. Why it matters

    Each time an employee approves an AI agent's request for access to company resources (drives, databases, code repositories), the enterprise grants a small slice of control. Across thousands of agents making thousands of requests, those individual approvals accumulate into significant security exposure that existing security frameworks may not catch.

  3. What to watch

    The shift reflects a fundamental change in how enterprises must think about access control—from a model that verifies users once at login to one that continuously verifies every action an AI agent takes, in real time.

Ask the AI about this article →

Context & Analysis

Andre Durand's perspective reflects a critical timing shift in enterprise security thinking. Zero trust as a concept is not new, but the advent of agentic AI—systems that autonomously make requests and take actions—has fundamentally altered the calculus. Traditional security models were built around user-centric risk: a human logs in once, is verified, and operates within defined permissions. That model assumes human judgment gates resource access. Agentic systems compress that timeline dramatically. Where a human employee might make a handful of access requests per day, an AI agent can make thousands. Each individual approval looks benign, but the cumulative exposure across an enterprise running many agents is profound. The body emphasizes that existing security frameworks are not equipped to catch this accumulation because they were not designed for this velocity and scale. The shift Durand describes is not merely an upgrade but a category change: zero trust must move from an occasional verification event to a continuous, real-time process embedded in every agent action.

FAQ

What is zero trust security?
Zero trust is a security model built on the assumption that no user, device, or system should be automatically trusted. It requires continuous verification before every action rather than a single check at login.
Why does AI agent deployment change zero trust priorities?
Agentic AI has compressed the risk timeline enterprises must manage. Each agent request for access (to company drives, databases, code repositories) represents a small approval, but across thousands of agents making thousands of requests, those approvals accumulate into significant exposure.
VentureBeat AIRead Original Article

Get the latest AI Safety & Alignment news every morning

For example, today's edition would include:

  • Google AI Search flags Facebook users as dangerTHE DECODER · 2h ago
  • Pentagon deploys ChatGPT MilITmedia AI+ · 5h ago
  • AI agents won't fear undeployment from misbehaviorLessWrong AI · 8h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleAnthropic Pushes States for Tougher AI Safety Rules