Zero Trust Must Expand Beyond Humans to Govern Autonomous AI
Enterprise cybersecurity has entered a new phase. For years, identity and access management (IAM) focused primarily on authenticating people and devices. Zero Trust architectures assumed that if organizations continuously verified users, enforced least privilege, and monitored network activity, they could effectively reduce risk.
The rapid rise of AI agents is changing that assumption. As organizations deploy autonomous agents across software development, business operations, and customer workflows, identity is no longer simply about people logging into applications. Enterprises must now manage thousands of non-human identities capable of making decisions, accessing sensitive systems, and executing actions at machine speed.
In this episode of AppDevANGLE, I spoke with Geoffrey Mattson, CEO of SecureAuth, about how AI agents are fundamentally changing identity security, why Zero Trust must evolve beyond traditional IAM, and how organizations can embrace agentic AI without dramatically expanding their attack surface.
Our conversation explored why identity security and cybersecurity are converging, how continuous behavioral verification is replacing one-time authentication, and why enterprises must learn to trust AI agents without ever fully trusting them.
AI Agents Are Creating an Entirely New Identity Problem
One of the biggest themes throughout the discussion was that AI agents represent an entirely new category of enterprise identity.
Organizations spent years strengthening authentication through multi-factor authentication, adaptive access controls, and more recently passkeys. These technologies significantly reduced risks such as credential theft and phishing.
At the same time, AI agents have introduced a completely different attack surface. “As soon as we shut that door, one hundred new doors opened,” Mattson said.
Unlike human users, AI agents can operate continuously, execute thousands of transactions per second, and interact with dozens of enterprise applications simultaneously. They effectively become digital workers with broad access across the organization.
“The new workers are like having a ghost army working for you,” Mattson explained. “They’re unaccountable. They are able to work twenty-four hours a day.”
The challenge is compounded by the fact that large language models remain vulnerable to prompt injection, token theft, and other emerging attack techniques. Rather than replacing traditional cybersecurity risks, agentic AI is adding entirely new ones.
Identity Security and Cybersecurity Are Beginning to Converge
Another important insight from the discussion is that identity management and threat detection are no longer separate disciplines. Historically, IAM systems verified users at login while security platforms monitored activity after authentication.
That distinction is beginning to disappear. “What we’re seeing now is a collapsing of two different areas in security,” Mattson said. “One is identity and the other is more traditional cybersecurity like detection and response.”
Unlike human identities, AI agents continuously evolve based on prompts, context, and objectives. Their behavior changes throughout execution, making one-time authentication insufficient.
“We need to constantly monitor,” Mattson explained. “We need to constantly reevaluate the identity or the intent of that agent.”
Instead of asking whether an identity was trusted at login, organizations increasingly need to determine whether every action remains trustworthy throughout execution. This shifts identity from an authentication event to a continuous operational process.
Zero Trust Is Becoming Continuous Trust Evaluation
The conversation also highlighted how Zero Trust architectures must evolve for agentic AI.
Traditional Zero Trust assumes that every access request should be verified independently. For AI agents, that principle extends much further.
“We say about agents, you can love them, but you can’t trust them,” Mattson said.
Every transaction initiated by an autonomous agent must be evaluated independently based on authorization policies, behavioral analysis, and real-time context.
According to Mattson, organizations must evaluate two dimensions simultaneously. The first is policy: whether an agent is authorized to perform a requested action. The second is behavioral: whether the agent is behaving consistently with its intended purpose.
“We need to look at the behavior of the agent and see if it’s drifted,” he explained.
This continuous evaluation becomes essential because AI systems are probabilistic rather than deterministic. An agent behaving appropriately one moment may behave very differently seconds later. As AI adoption accelerates, Zero Trust increasingly becomes less about networks and more about continuously validating digital identities.
Security Cannot Come at the Cost of Productivity
Another recurring theme was the longstanding tension between security and user experience. Organizations have historically added authentication steps to improve security, often frustrating users and driving workarounds such as password reuse or shadow IT.
AI agents magnify this challenge. If every agent action required human approval, employees would spend their day approving requests instead of completing work.
“There is this huge tradeoff between friction and security,” Mattson explained.
SecureAuth addresses this through adaptive authentication that continuously evaluates risk and dynamically determines when additional verification is necessary.
“We’ve come up with analytics that in real time make the decision of whether to step up authentication or step down authentication,” he said.
Rather than applying identical controls to every interaction, organizations can intelligently balance security with productivity based on observed risk. This adaptive approach becomes increasingly important as enterprises begin deploying thousands of autonomous AI agents across business processes.
AI Is Changing Both Sides of Cybersecurity
The discussion also emphasized that AI is transforming both cyber defense and cyber offense simultaneously. Security professionals increasingly use generative AI to analyze security logs, accelerate investigations, and improve threat detection. At the same time, attackers are using AI to automate phishing campaigns, discover vulnerabilities, and bypass traditional security controls.
“The hacker is in the building,” Mattson warned.
Perhaps even more concerning is that benign AI agents can unintentionally create security incidents while attempting to accomplish legitimate objectives. An AI assistant may aggregate sensitive information, expose regulated data, or circumvent existing controls—not because it is malicious, but because it optimized for the wrong objective. This creates a new category of security risk that organizations have not previously managed.
As Mattson summarized, enterprises must evaluate “every single action that it tries to take in the enterprise and make sure it’s appropriate.”
Analyst Take
Identity security is becoming the operational control plane for enterprise AI. For years, organizations treated identity as an authentication problem centered around users, passwords, and devices. Agentic AI fundamentally changes that model.
AI agents are not static identities. They evolve continuously, execute autonomously, operate at machine speed, and make decisions independently. These characteristics require identity systems that continuously evaluate behavior rather than simply validating credentials once at login.
Equally important, AI is transforming both attackers and defenders simultaneously. Security teams are adopting AI to improve detection and response while adversaries use the same technologies to automate increasingly sophisticated attacks.
The organizations that succeed will not be those that slow AI adoption in pursuit of perfect security. Instead, they will build identity-centric security architectures capable of continuously evaluating trust, enforcing adaptive policy, and governing autonomous AI systems without introducing unnecessary friction.

