Enterprise security leaders must adopt zero trust architecture immediately for AI agents rather than treating it as a long-term initiative, according to Ping Identity's CEO.
The speed and scale of agentic AI—thousands of agents making thousands of access requests—has compressed the security risk timeline, making real-time permission verification essential to prevent exposure from accumulated access grants that appear routine in isolation.
What happened
Andre Durand, CEO of Ping Identity, argues that enterprises must now treat zero trust security—a model requiring continuous verification rather than a single login check—as an immediate requirement for AI agents, not a future goal. Agentic AI has compressed the risk timeline, demanding permission decisions be evaluated in real time.
Why it matters
Each time an employee approves an AI agent's request for access to company resources (drives, databases, code repositories), the enterprise grants a small slice of control. Across thousands of agents making thousands of requests, those individual approvals accumulate into significant security exposure that existing security frameworks may not catch.
What to watch
The shift reflects a fundamental change in how enterprises must think about access control—from a model that verifies users once at login to one that continuously verifies every action an AI agent takes, in real time.
Ask the AI about this article →
Andre Durand's perspective reflects a critical timing shift in enterprise security thinking. Zero trust as a concept is not new, but the advent of agentic AI—systems that autonomously make requests and take actions—has fundamentally altered the calculus. Traditional security models were built around user-centric risk: a human logs in once, is verified, and operates within defined permissions. That model assumes human judgment gates resource access. Agentic systems compress that timeline dramatically. Where a human employee might make a handful of access requests per day, an AI agent can make thousands. Each individual approval looks benign, but the cumulative exposure across an enterprise running many agents is profound. The body emphasizes that existing security frameworks are not equipped to catch this accumulation because they were not designed for this velocity and scale. The shift Durand describes is not merely an upgrade but a category change: zero trust must move from an occasional verification event to a continuous, real-time process embedded in every agent action.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Visko raised $10 million in pre-seed funding from Llama Ventures and opened public access to its first foundat…
AI company Runway has unveiled Solaris, the first model in a new category it calls "Interface World Models." I…

Google's AI search gave advice to call emergency services for users alone with an African, Indian, or Pakistan…

John Deere introduced JD, a conversational AI tool that lets farmers ask open-ended questions about their hist…

Nvidia CEO Jensen Huang said on Fox Business that AI is creating 'hundreds of thousands' of jobs, including in…

Israeli startup DataAgent Ltd