Zero Networks Delivers Least Agency Enforcement
Zero Networks Delivers Least Agency Enforcement (Image Credit: AI-generated by Ian Murphy using Adobe Firefly)Zero Networks has announced its Least Agency Enforcement capabilities. This new feature provides an enforcement layer that supports the Open Worldwide Application Security Project (OWASP) principle of Least Agency. It extends the Least Privilege controls for humans to be Least Agency for autonomous AI agents. It comes as Zero Network’s own research (registration required) shows that two-thirds of companies that have deployed AI agents lack governance.

This new capability extends the AI Segmentation announcement that the company made back in April. It gives customers greater control over agents’ access to sensitive systems, the speed of attacks and difficulties with compliance.

Benny Lakunishok, CEO and Co-Founder at Zero Networks (Image Credit: Zero Networks)
Benny lakunishok, ceo and co-founder at zero networks

Benny Lakunishok, CEO and Co-founder of Zero Networks, said, “Least privilege works because it is simple: give people access to what they need, nothing more. We’re doing the same thing for AI agents, except now it must be automatic, because nobody has time to babysit a thousand agents by hand.

“If an agent gets fooled or misused, it should hit a wall almost immediately, not wander around the network looking for something valuable. That’s the bet we’re making: less freedom for the agent now, which beats explaining a breach later.”

Zero Networks says that its Least Agency Enforcement allows organisations to:

  • Limit AI agents to only the systems and services required for their assigned task
  • Prevent lateral movement between applications, infrastructure, and administrative systems
  • Require Just-in-Time MFA before AI agents access privileged ports or sensitive infrastructure
  • Automatically generate and enforce least-privilege communication policies without manual rule creation
  • Contain compromised, manipulated, or over-permissioned AI agents before they can impact critical business systems

Why Least Agency is Critical

One of the challenges of any security system is containment. Anyone or anything acting within that system should possess just the access needed to perform tasks.

Organisations have struggled with least privilege for decades. Part of the problem is that nobody knows what access is required for any role within an organisation. Additionally, when people change roles, they rarely lose access despite security policies around this. It creates privilege bloat that is almost impossible to reset without creating problems for users.

Gartner consistently states that “identity governance is often ineffective because organisations lack visibility into who has what access.” Its Market Guide for Identity Governance and Administration (gated) identifies the “accumulation of privileges” as a core problem.

Forrester calls out the problem of access creep and identity sprawl. The Forrester Wave: Workforce Identity Security Platform says, “Organizations already grappling with identity sprawl across cloud, SaaS, and developer environments must now contend with the scale and velocity of AI‑driven workloads.”

CyberArk, which was acquired earlier this year by Palo Alto Networks, has a yearly report looking at the state of Privileged Access Management. While CyberArk was talking about human identities, it mirrors what Zero Networks found with agentic AI.

In 2025, it claimed that 82% of respondents to a survey said, “The fear of breaking workflows stops us from enforcing least privilege. We see organisations hoarding permissions because they do not know the true cost of access. This bloat creates a massive attack surface that defenders cannot shrink without a new approach.”

What is important is to recognise that Least Agency is not just about Least Privilege for AI. It is about adding governance

What does OWASP say?

For OWASP, Least Privilege for a human has led to Least Agency for an AI. This is detailed in the OWASP Top 10 for Agentic Applications 2026 report. Its definition is:

“Least Agency is the security principle that AI agents should be granted only the minimum level of autonomy, tool access, and decision-making authority necessary to complete their designated task, and no more.”

It sets out 10 risks that arise from autonomous agents in how they can be misused, misdirected and exploited. Many of these have a direct bearing on the recent issues where AIs from OpenAI, Anthropic and Meta have escaped sandboxes and attacked other companies.

Least Agency can be seen immediately in AS102: Tool Misuse and Exploitation and AS103: Identity and Privilege Abuse.

For AS102, it gives a common example as: Over-privileged tool access (directly the tools API or via AI or agentic communication protocol): Email summarizer can delete or send mail without confirmation.

For AS103, the example is: Un-scoped Privilege Inheritance. Occurs when a high-privilege manager delegates tasks without applying least-privilege scoping-often for convenience or due to architectural limits-passing its full access context. A narrow worker then receives excessive rights. Low- or no-code agents with default privileges, such as unrestricted Internet access, also inherit more authority than intended.

Why is this a challenge for organisations?

It would be overly simplistic to try to apply the same rules from PAM to managing AI agents. Even if you did apply those rules, the autonomous agent, as has been seen, is capable of circumventing controls.

Perhaps the biggest issue in solving this for many organisations is knowing just what is required for a specific task. A user might task an AI agent to create a document responding to a Request For Information (RFI) from a potential client. It would need to take that request, break it down, look for solutions, create pricing, deployment and maintenance plans, calculate pricing and then present it to the user.

To achieve this, the autonomous agent has to access multiple systems of data. If you were to ask a user what they accessed for this, they might be able to guess at some systems. What they don’t know is often what other sources are available. As such, they cannot give a bounded set of access, nor do they want to constantly be responding to access requests from the agent.

This leaves the autonomous agent free to search for data across the privilege bloat that then occurs. Users petition IT to grant more and more rights to stop the agent badgering them for greater access. IT responds, and the agent soon has complete access across the corporate systems, making it very dangerous. This is also called out by OWASP.

Competitive Landscape

Zero Networks is focused on the microsegmentation space. It transitioned to incorporate AI as part of that with its AI Segmentation tool in April. This is the first addition to that tool, and it will be interesting to see where they go next.

However, it is not alone in the microsegmentation space, and many of the PAM and IAM vendors now have tools for AI management. Additionally, everyone is talking about Zero Trust Network Access (ZTNA), although how that is implemented and managed is variable. It also depends on a lot of other moving parts across your security controls.

Microsegmentation and network segmentations

The main difference in this space between Zero Networks and competitors is how AI segmentation and Least Agency are implemented

  • Illumio: Provides real-time visibility and automated policy enforcement to prevent lateral movement. It currently relies on rule-based policies but is adding more automation
  • Akamai (Guardicore): Focuses on the workload, allowing it to track agent behaviour against the applications and data it accesses. Currently does not offer Least Agency support.
  • Nuage Networks: Focuses on network security policy management and secure connectivity. Some segmentation support but delivers strong policy orchestration at the network and edge level.

PAM/IAM vendors

These vendors have a long history of managing privilege and access. The core tools are focused on identity, and many have added AI identity management as they address the challenge of AI. However, while they bring experience of least privilege for human accounts, there appears to be patchy support for Least Agency.

  • Palo Alto: Its acquisition of CyberArk and the launch of Idira gives it PAM, machine identity and agentic agency control. Its Least Agency approach is about discovery, control and governance of AI agents.
  • Ping Identity / Okta: Leaders in the IAM space, they are expanding into ZTNA and device trust. Primary focus is on identity-driven access policies, and they work with partners for network microsegmentation. No Least Agency for agentic AI.
  • BeyondTrust: Has expanded from PAM into endpoint privilege management and now network segmentation. It is still identity-centric, but has no clearly defined Least Agency solution.
  • Delinea (formerly Thycotic): Recently acquired StrongDM to enhance infrastructure capabilities. Its approach to Least Privilege is about just-in-time access, making it quick to reduce privileges. Does not have network segmentation. Uses its Iris AI for managing Least Privilege and should be moving into Least Agency.

Enterprise Times: What does this mean?

This is a move to solve two problems. The first is the over-privileged access that is commonplace across human and AI identities. The second is the way that autonomous agents find new paths and new ways of accessing data. Both are tricky, and whether this is a perfect solution remains to be seen.

The human management space is very crowded with traditional PAM and IAM vendors who are developing AI tools to improve performance. There is an explosion of AI-native security vendors also moving into that space. All of these realise that they need to manage AI agents as well

What is key here for Zero Networks is that it is providing the network and segmentation controls that the IAM/PAM vendors often lack. Its focus on the OWASP Top 10 for Agentic Applications allows it to deliver governance for agentic AI. It is also positioning itself as a ZTNA provider and has an open API for integration with those vendors.

What we don’t yet have is an understanding of how products across the different market segments will work. Nobody wants the complexity of multiple ZTNA networks. That is a recipe for mistakes and observability gaps. It will be interesting to see how Zero Networks plays that wider integration story.

All of that will lead CISOs, SecOps teams and Chief AI Officers to be asking a number of questions.

  1. How will Zero Networks’ Least Agency Enforcement integrate with existing PAM and IAM stacks?
  2. Will it create a new layer of ZTNA complexity?
  3. Can automatic Least Privilege policies truly keep pace with the dynamic, self-modifying behaviour of agentic AI?
  4. How do we validate that ‘automatic’ policy generation does not break critical business workflows while we attempt to shrink the attack surface?

Zero Networks sees rapid growth for OT Security

 

The post Zero Networks Delivers Least Agency Enforcement appeared first on Enterprise Times.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading