In the cyber realm, humans have long been the weakest link. Human vulnerability, psychological vulnerability, and the ability to circumvent technology meant that cybercriminals were only too happy to target humans. But according to Zscaler CEO Jay Chaudhry, those times are changing. AI agents are everywhere today and are rapidly becoming a major weak link.
From a security perspective, the rapid deployment of AI agents within corporate environments cannot be directly compared to previous waves of innovation. If you compare it, for example, to the explosion of websites or cloud applications, there was always a common denominator: humans as users of the technology. When designing a company’s security framework, you can explicitly focus on building a human-centered architecture. But with AI agents, the tools have, as it were, become the workforce themselves. In practice, the agents behave like virtual employees who make decisions and carry out actions independently in the background.
This autonomy is precisely what creates the modern security risk. The agents operate continuously at machine speed. They read emails, search databases, and execute complex workflows in seconds, without pause or weekends. Moreover, human oversight is almost always minimal. Because many corporate networks grant these virtual employees broad access rights or full access tokens, a dangerous mix arises. With this freedom of movement, a compromised agent can move from reconnaissance to large-scale data theft within minutes. These agents are therefore extremely attractive to cybercriminals. And they can certainly make mistakes. The lightning-fast, tireless agent is thus, as Chaudhry rightly points out, the weak link in the cybersecurity landscape.
The breaking point of the traditional firewall
Zscaler’s CEO has been arguing for years that traditional security models are too weak to protect businesses, but in the world of agentic AI, he believes this is even more true. Traditional firewalls and VPN connections are, at their core, simply not built to detect autonomous agent traffic, let alone control it adequately. A firewall acts as an open bridge between two networks. As soon as that bridge is open to enable legitimate work, malicious traffic can flow across it just as easily.
The greatest danger in this traditional setup is “lateral movement.” As soon as a network component is accessible, it is vulnerable. For AI agents in particular, which move invisibly and at lightning speed through corporate networks, this traditional freedom to move through a network poses an enormous risk. The current proliferation of Model Context Protocol (MCP) servers and agents that join the network unnoticed only exacerbates this problem. A hijacked agent on a traditional network effectively has the same freedom of movement as a compromised human user, but carries out destructive actions many times faster.
Zero trust and continuous verification
To secure this new reality, Zscaler is currently undergoing a large-scale overhaul of its Zero Trust Exchange. According to the company, the answer to the unrestricted freedom of AI agents lies in a strict “least privilege access” approach. Organizations must strictly limit agents’ access to only the specific, necessary applications, rather than granting them the current open-ended access rights. Every office, every factory, and now every agent must function as an invisible island that cannot be easily discovered.
In addition, continuous verification has become crucial in this architecture. Security teams require inline enforcement and monitoring for every individual prompt, plug-in, and connector. Zscaler is therefore adding specialized AI Brokers for agent-to-agent communication, combined with an advanced engine that inspects prompts and responses in real time. Only when the actual intent behind a request is deemed safe is a secure point-to-point connection established. A newly introduced Agent Registry with granular access controls then provides immediate visibility into which agent is authorized to access which specific resource.
An indispensable part of this new architecture is the AI Access Graph, a technology stemming from the recent acquisition of the startup Symmetry Systems. Because the number of agents per individual employee will rise rapidly, perhaps to a ratio of over 100, manual access policy management has become unfeasible. This new technology uses AI to map the entire flow of data, enabling the system to automatically understand which entity accesses which data source.
Zscaler views its updated suite as the first truly comprehensive zero-trust environment that effectively covers agentic AI. This is based on the understanding that the tireless virtual employee will form the undisputed new front line of cybersecurity in the coming years.