verifiedagents.ai
All posts

4 min readZero Trust · AI Agents

What does segmentation mean for AI agents?

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Segmentation for AI agents hero image

TL;DR: Segmentation is the Agentic Trust Framework check that asks where an AI agent can go. It limits which systems and other agents each one can reach, so one bad decision stays small. You won't find every flaw in an agent before it ships. You can decide how far a flaw can travel.

Key takeaways:

  • Segmentation is one of the five ATF elements. It answers the question "Where can you go?"

  • Containment beats enumeration. Newer models find flaws faster than any team can list them, so limit the blast radius instead of chasing a perfect list.

  • The risk that gets missed is agent to agent. Each agent can pass its own checks while two of them together make a million-dollar mistake.

  • The fix is structural: narrow network paths, verified connections between agents, and one orchestrator in the middle.

What does segmentation mean for an AI agent?

Segmentation means an agent can only reach the systems and other agents its job needs, and nothing past that. It's the fourth of the five checks in the Agentic Trust Framework, and it answers one question: where can you go?

Identity tells you who the agent is. Segmentation decides how far it can travel once it's working. An agent with a verified identity and no boundaries is a trusted employee holding a master key to the whole building.

Why isn't finding every vulnerability enough?

Because you'll never finish the list. Every model generation finds flaws faster than the one before it, and the list of what could go wrong grows faster than any team can work through it.

So stop trying to rank every flaw first. Assume one agent will do something it shouldn't, and make sure the damage stays inside a small box. We call this containment over enumeration: limit the blast radius before you chase the next finding.

This is Zero Trust applied to agents. No agent gets access just because it's already inside your network.

Where does segmentation fail in practice?

It usually fails between agents, not inside one.

One story from our book, Agentic AI + Zero Trust: A Guide for Business Leaders, shows how. Taylor ran 47 agents. At 11 PM on a Tuesday her phone buzzed: "Our inventory agent just ordered $1 million worth of snow shovels. In July. For our Phoenix warehouses."

The inventory agent hadn't gone rogue. Another agent had misclassified industrial cooling equipment as snow removal, because both were tagged "temperature management." The inventory agent trusted what it was told and acted on it.

Each agent passed its own checks. Together they made a $1 million mistake. Nothing in either agent's individual checks could catch it, because the problem lived in the conversation between them.

How do you segment AI agents?

Give every agent a narrow lane, and control the roads between lanes.

In practice that means four things:

  • Network paths: each agent reaches only the systems and data its task needs. Everything else is denied by default.

  • Verified connections between agents: agents prove who they are to each other before they exchange anything. Taylor's team added mutual TLS (mTLS), where both sides of a connection show a certificate, not just one.

  • One orchestrator in the middle: instead of agents talking to each other freely, they go through a hub that can see and stop a bad handoff. The book calls this hub and spoke.

  • Limits on what an agent can commit: a spending cap or an approval step on large actions keeps one bad input from turning into a warehouse full of shovels.

None of this needs a new platform. It's the same discipline you already apply to people and servers, pointed at agents.

How do you know if your agents are segmented?

Pick one agent. Write down every system and every other agent it can reach, and the largest action it can take without a person approving it.

If you can't write that list from memory, that's your starting point.

The free assessment on this site scores segmentation alongside the other four ATF elements. It takes about ten minutes and ends in a PDF that says what to fix first. Take the free assessment.

For the full requirements, see the Agentic Trust Framework specification.

Frequently asked questions

Is segmentation for AI agents different from network segmentation?

It builds on it. Network segmentation limits which machines can talk to each other. Agent segmentation adds limits on which agents can talk to each other, what they can hand off, and how much they can commit in one action.

Do I need segmentation if my agents already have strong identities?

Yes. Identity proves who an agent is. It doesn't limit what the agent does once it's in. An agent with the right credentials can still reach too much.

What's the fastest first step?

List every system and every other agent one production agent can reach today. Remove anything its job doesn't need. Most teams find at least one path nobody meant to leave open.

Which ATF level does good segmentation map to?

At Level 3 (Defined), segmentation limits the blast radius and agents can act on their own for defined tasks while notifying a person. Agents that run fully on their own and escalate belong at Level 4 (Optimizing).

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.