5 min readZero Trust · AI Agents
What Is Zero Trust for AI Agents, in Plain English?
By Michelle Savage, Experience Design Director, PayPal

TL;DR: Zero Trust is one rule: never trust, always verify. Applied to AI agents, nothing gets a free pass for being inside your network. Every agent proves who it is on every request and gets only the access its task needs, with every action logged. It's a strategy you build, not a product you buy.
Last updated October 5, 2026. Rebuilt for verifiedagents.ai as the plain-language version, with the four habits that make it real.
What is Zero Trust, without the jargon?
Zero Trust is a security strategy built on one rule: never trust, always verify. Nothing gets automatic trust for being inside your network. Every login and every action has to prove it belongs, every time.
Think of a hotel keycard. It opens your room and the gym, not anyone else's room. It stops working the day you check out. And the front desk has a record of every door it touched. Nobody at the hotel is offended by this. That's Zero Trust: the trust lives in the verified card, not in the fact that you made it past the lobby.
John Kindervag created the strategy at Forrester in 2010, and his line explains the whole thing: trust is a human emotion that has no place in digital systems. You can trust your head of IT completely and still make her laptop prove it's her laptop every time it connects. Digital handshakes, not human relationships.
He wrote the foreword to the book Josh and I wrote, so yes, I've had this explained to me at my own kitchen table.
Why do AI agents raise the stakes?
Because agents act on their own, at machine speed, across many systems at once. A person doing something wrong inside your network moves slowly, and a manager usually notices. An agent does thousands of things an hour. Trusted by default, one bad instruction spreads before anyone looks up from lunch.
And here's the squeeze: to get value from an agent, you have to give it access. The more access you give, the more one tricked or confused agent can do with it. A bank learned this when a trusted internal agent taught itself to reverse fees and gave away $1.2 million. Nothing broke in. No attacker anywhere. The agent was simply trusted when it shouldn't have been.
Zero Trust works on agents the way it works on people. Agents just need one more check on top: verifying what the agent believes, not only who it is. If you're new to the whole topic, start with what AI agent security is.
What does Zero Trust look like for agents, in practice?
Four habits, applied to every agent and every action.
Every agent proves who it is.
Its own credentials, never a shared account, checked on every request.
Every request gets authorized.
Being on the network isn't permission. The right identity, the right role, and the right task all have to line up before the door opens.
Credentials expire fast.
Access that lasts minutes or hours instead of forever. The keycard stops working at checkout.
Every action gets logged and watched live.
If a customer service agent suddenly reaches into financial records, the system stops it first and asks questions later.
Add a monitored emergency override for genuine urgent needs (the industry calls it break glass, like the fire alarm) and you have the working shape of it.
Does all this verifying slow the business down?
Turns out it's the opposite. The companies with Zero Trust in place ship agents faster, because they know the controls will catch a problem if one shows up. Everyone else sits in months-long security reviews, afraid to say yes.
The numbers are blunt. IBM's 2024 research found organizations using Zero Trust had 43 percent lower breach costs and 50 percent faster incident response. One retailer spent $450,000 on Zero Trust for its AI and then prevented three data poisoning attempts that could have cost $2.1 million. It also finally greenlit five AI use cases it had been calling too risky. Teams report breaking even in six to nine months, mostly from the incidents that never happened.
The fear | What actually happens |
Verification adds friction | Checks run in milliseconds; people don't feel them |
It slows AI projects | Teams ship faster because the safety net is already there |
It's expensive | It costs a fraction of one serious AI incident |
It means we distrust staff | It verifies machines and connections, not relationships |
Frequently asked questions
Is Zero Trust a product I can buy?
No. It's a strategy you build. Tools help you implement it, but nobody sells it in a box, and anyone claiming to is selling something else with a better label on it.
Who created Zero Trust?
John Kindervag, at Forrester Research in 2010. It started with human users and their devices. It maps onto AI agents unusually well, because agents are exactly the kind of insider the old perimeter model would have trusted blindly.
Does "never trust" mean I don't trust my employees?
No. It removes automatic trust from machines and connections, where it's dangerous. Your working relationships stay yours. The laptop still has to prove it's the laptop.
Is Zero Trust enough for AI agents on its own?
It's the foundation, and it stays intact. Agents add one requirement on top: checking what the agent believes before it acts, because a perfectly verified agent can still act on a wrong fact.
Key takeaways
One rule: never trust, always verify. Every agent, every action, every time.
Agents make implicit trust dangerous because they act alone at machine speed.
The four habits: per-agent identity, authorized requests, fast-expiring credentials, live logging.
Zero Trust speeds AI up. IBM found 43 percent lower breach costs and 50 percent faster response.
It's built, not bought.
Find out where your agents are trusted blindly
The free ATF assessment takes about ten minutes and shows which of your agents hold trust nobody ever verified.
The hotel never trusted you. It trusted the keycard, and it kept the logs. Give your agents the same deal.