Enterprise zero-trust programs were designed around a specific actor: a human, with a badge, a managed laptop, and a phone that can receive an MFA push. Every control in the stack — conditional access, device posture, step-up authentication — assumes that actor. AI agents break the assumption on every axis. They have no device, no badge, and they will never approve a push notification.
That would be a manageable gap if agents were rare. They aren't going to be. The same enterprises that spent five years getting humans behind identity-centric access are now deploying non-human actors that hold credentials, call internal APIs, and take actions at machine speed — often governed by nothing more than a service account created in a hurry with a wildcard scope.
What breaks, specifically
Identity: agents need workload identity with short-lived, narrowly scoped credentials — not shared API keys in a secrets manager that rotate annually and authorize everything. Access: conditional-access policies keyed on device compliance and location mean nothing for a pod; the equivalent signals are workload attestation, namespace, and runtime posture. Egress: a compromised human clicks one bad link at a time; a compromised agent exfiltrates at line rate, which makes inspected, allowlisted egress a first-order control instead of a checkbox. Audit: "who did this" must resolve to which agent, on whose behalf, under which policy — an identity chain most logging setups simply don't record.
The authority question
The hardest part isn't technical. When an agent wants to take an action with real consequences — reallocate spend, modify a firewall rule, push a fix — who approved that class of action, within what bounds, and how is it revoked at 2 AM? Bounded authority, escalation paths, and a kill switch aren't features you bolt on after the pilot. They're the operating model that determines whether security ever lets the pilot leave the lab.
Human-era zero trust
- Identity = person + device + MFA
- Service accounts as the unmanaged exception
- Egress policy tuned for browsing humans
- Audit answers "which user"
- Access reviews quarterly, by spreadsheet
Agent-era zero trust
- Workload identity with short-lived, scoped credentials
- Attestation & runtime posture as access signals
- Inspected, allowlisted egress as a primary control
- Audit resolves agent → principal → policy
- Bounded authority with a tested kill switch
Where to start
Inventory the non-human identities you already have — most enterprises find an order of magnitude more service credentials than employees, before a single agent ships. Then pick the first agent workload and build the full chain for it properly: scoped workload identity, segmented network path, inspected egress, attributable audit, revocation drill. One workload, done right, becomes the template every subsequent agent inherits. That template is the difference between agents that security accelerates and agents that security — correctly — blocks.