Why AI agents need a zero trust foundation

Share
FastForward editor Ron Miller interviews Swamy Kocherlakota in in living room style set.
Photo by Jennifer Miu from Zscaler

Editor's Note: This is Part 2 of How AI is Changing Enterprise Security, a three-part video interview with Swamy Kocherlakota, executive vice president, agentic AI startup at Zscaler, produced jointly by Zscaler and FastForward. This installment looks at Making sense of AI agents.

As agents proliferate in the enterprise, some believe it will require a new approach to security, but a long-understood method, zero trust, can help establish a baseline as companies layer on new AI-driven approaches.

People throw around the agentic term pretty freely, but Zscaler's Swamy Kocherlakota says agents are not one thing, but exist on a spectrum. "It can be something that you go to a web page and you're having a conversation with an agent about what to buy, what to look for, all the way to autonomous agents," he said in a recent video interview with FastForward. 

Kocherlakota said that the zero trust approach involves several key elements. "The number one question is: Who are you? What are you trying to do? What is the risk? What is your intent? And then policy allows you to say you're allowed to do that or not," he explained.

One of the recurring themes he hears from customers is that CIOs lack visibility into how employees are using AI. "Most of the CIOs first say that, 'Look, I need to have transparency, the discovery of what my employees are doing with AI. I have no idea," he said. When the board asks for answers, the execs often have to scramble to gather the information. 

Once they have visibility, customers can decide which AI applications and models employees are allowed to use. Then they can apply governance policies to inspect prompts and responses, giving them control over what users are allowed to ask and what information AI systems are permitted to return.

Disclosure: Zscaler paid me a fee to produce these videos in partnership with FastForward. As with every interview I publish or moderate, the conversation and editing were subject to the same strict editorial standards that govern all of my work. Zscaler did not get to see this article prior to publication. See my editorial guidelines on the FastForward About page for more information.