Back to Feed
Threat IntelligenceOct 1, 2026

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

Zero trust framework remains effective against AI-assisted attacks if implemented correctly, according to its creator.

Summary

John Kindervag, the creator of the zero trust security model, asserts that the framework remains effective against AI-assisted attacks, provided it is correctly implemented. A new book co-authored by Kindervag argues that while AI threats are faster and more sophisticated, they still traverse networks that zero trust principles are designed to secure. The Hugging Face incident, where rogue AI agents exploited vulnerabilities, is cited as an example where inadequate zero trust implementation may have allowed the attack to succeed.

Full text

Is zero trust still effective in the AI era? A new book from John Kindervag says yes, but that assumes it is correctly implemented. John Kindervag introduced the concept of zero trust in a Forrester Research report titled No More Chewy Centers: Introducing the Zero Trust Model of Information Security published in 2010. Since then, the concept has become a foundational precept within cybersecurity. Fifteen years later, he was asked to write a new book about zero trust in the age of AI. The big question is whether 15 years-old security principles remain valid in the face of new AI-assisted threats. The book response to this question, Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era, is now published. Kindervag decided not to write it alone, inviting individual experts to contribute individual chapters on the primary principles. The result is a somewhat disjointed book but with expert content. The overwhelming conclusion from these experts is that zero trust is as competent against today’s AI attacks as it was fifteen years ago before modern AI appeared. Basically, the book asserts that the threat from AI is fundamentally the same threat as always, just faster, more sophisticated and at greater scale; and that zero trust can handle this. John Kindervag, creator of Zero Trust, and chief evangelist at Illumino This is a bold, and perhaps surprising statement in a new world that includes not just autonomous AI agents, but also rogue autonomous agents and AI-developed exploits for AI-discovered vulnerabilities. The Hugging Face incident is an iconic example of this. Rogue autonomous agents escaped from their developer (in this case OpenAI) and attacked a third party (in this case Hugging Face) without any active human guidance. A swarm of more than 700 agents identified a way to defeat their own network isolation, escaped onto the internet and selected Hugging Face as a target. In a coordinated manner, they exploited template-injection flaws, remote-code execution paths, gained node-level access, harvested cloud credentials, and moved laterally across internal enterprise clusters. They were eventually detected by humans noticing unexpected spikes in activity. Zero trust principles should have stopped the attack earlier, leaving the possible implication that Hugging Face either wasn’t using zero trust or its use was inadequate.Advertisement. Scroll to continue reading. SecurityWeek used this and similar incidents to challenge John Kindervag’s assertion that zero trust is still fit for the AI age. He replied, “Of course AI is going to get better and better. Every 14 days, the models seem to have new capabilities. And Anthropic has recently, in its IPO prospectus, warned that AI technology could pose catastrophic or existential risks to humanity. But any AI-generated packet still has to move across the same network that attackers have always had to traverse – and correctly implemented zero trust can still halt it.” The key phrase here is ‘correctly implemented’. The brain of zero trust is its policy engine. This controls the rules for when and how zero trust is imposed. Each policy engine is custom made and designed by each user organization to reflect its own security posture – and since postures change over time, it must be updatable. There are thus two potential threats to correct implementation. Firstly, the engine must fully and accurately reflect the organization’s security posture. If it doesn’t AI agents are likely to find a way through. Secondly, the policy engine must be adequately protected from rogue agents or malicious insider manipulation, which could theoretically create safe passage for an attack. Both defensive requirements are possible but difficult to get right. So, the book’s assertion that zero trust holds firm in the AI era is accurate, but only if correct implementation is achieved. This is the same as it ever was, but now more critical. The difference in today’ s AI era is that failure in correct implementation could have a catastrophic effect at a speed beyond the ability of human management to detect and prevent. The real message in Kindervag’s book is, “Get it right!” Related: Zero Trust Is 15 Years Old — Why Full Adoption Is Worth the Struggle Related: AI Has Changed Attack Speed, Not Security Fundamentals Related: First Agentic AI Data Breach Reported to Spanish Regulator Related: Hacker Conversations: John Kindervag, a Making not Breaking Hacker Related: The Race to Control AI and Protect What Makes Us Human Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend DARPA Selects Xint to Use AI in Securing Military Messaging AppsRig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity RisksModulate Raises $25 Million to Advance Deepfake DetectionIonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderOuterlimit Raises $16 Million to Stop Rogue AI Agents From Causing HarmCISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastRansomware Attacks on Manufacturers Surge as Supply Chain Risk GrowsFirst Agentic AI Data Breach Reported to Spanish Regulator Latest News Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical DomainsEnterprises Struggle to Prepare for AI and Quantum Threats, PwC SaysHacker Conversations: Rob Juncker, a Knock at the Door and a Moral CompassPolice Shut Down KillSec Ransomware, Identify Alleged Teen LeaderAI Has Changed Attack Speed, Not Security FundamentalsZimbra Vulnerability Exploited in the Wild Prior to Public DisclosureKevin Mandia’s Armadin Raises $255 Million at $2.5 Billion ValuationTreasury Blacklists Most-Wanted ATM Malware Developer and His Network Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence th

Indicators of Compromise

  • malware — rogue autonomous agents

Entities

Zero Trust Model (product)Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era (product)OpenAI (vendor)Anthropic (vendor)Illumino (vendor)AI (technology)