Zero Networks Enhances AI Security with 'Least Agency' Controls
Zero Networks Enhances AI Security with ‘Least Agency’ Controls
Zero Networks has launched Least Agency Enforcement, a groundbreaking capability designed to implement the Open Worldwide Application Security Project’s (OWASP) emerging Least Agency principle for enterprise AI. 🚀 While AI security today is largely focused on restricting what an agent can do, Zero Networks has built a failsafe that can block a compromise midway by adding a network layer of protection.
Key Features
- Identity-Based Micro-Segmentation: This offering aims to prevent AI agents from exceeding their intended autonomy by restricting which systems they can communicate with, what resources they can access, and when human approval is required for sensitive actions.
- Automated Policy Generation: Organizations can limit AI agents to explicitly authorized systems and services.
- Just-in-Time Multi-Factor Authentication (MFA): Sensitive paths get an MFA prompt on the protocols themselves, ensuring that a compromised agent identity can’t quietly use RDP, SMB, or WinRM to move sideways.
Chris Boehm, Zero Networks’ field CTO, stated, “Most vendors are trying to control AI agents at the application layer. The question we care about isn’t what the agent was asked to do. It’s what the agent can reach if it’s manipulated, misconfigured, or just wrong.”
The Importance of Governance
As organizations increasingly experiment with agentic AI without corresponding security controls, Zero Networks’ research indicates that nearly 80% of enterprises have already deployed internal AI agents, yet roughly two-thirds still lack governance policies for them. The OWASP’s Agentic Applications Top 10 project recently introduced the Least Agency principle, recommending that organizations explicitly constrain an AI agent’s autonomy, tool usage, and decision-making authority to reduce risks such as prompt injection, privilege abuse, and compromised agents.
Benny Lakunishok, CEO and Co-founder of Zero Networks, emphasized, “We’re doing the same thing for AI agents that least privilege did for people, except now it must be automatic. If an agent gets fooled or misused, it should hit a wall almost immediately, not wander around the network looking for something valuable.”
For more details, Read full article