Zero Networks targets AI agent security gaps with network-level ‘Least Agency’ controls
BreachWhile AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforcement,” a new capability designed to implement the Open Worldwide Application Security Project’s (OWASP) emerging Least Agency principle for enterprise AI. Built on Zero Network’s identity-based micro-segmentation platform, the offering aims to prevent AI agents from exceeding their intended autonomy by restricting which systems they can communicate with, what resources they can access, and when human approval is required for sensitive actions. “Most vendors are trying to control AI agents at the application layer,” said Chris Boehm, Zero Networks’ field CTO. “The question we care about isn’t what the agent was asked to do. It’s what the agent can reach if it’s manipulated, misconfigured, or just wrong.” The pitch is that while application-level controls focus on prompts and model outputs, identity and network enforcement limit the business impact if those safeguards fail. Extending least privilege from people to agents The announcement comes as organizations increasingly experiment with agentic AI without corresponding security controls. According to Zero Networks’ own research, nearly 80% of enterprises have already deployed internal AI agents, yet roughly two-thirds still lack governance policies for them. OWASP’s Agentic Applications Top 10 project recently introduced the Least Agency principle, recommending that organizations explicitly constrain an AI agent’s autonomy, tool usage, and decision-making authority to reduce risks such as prompt injection, privilege abuse, and compromised agents. Using identity-based microsegmentation, automated policy generation, and just-in-time multi-factor authentication (MFA), Least Agency Enforcement allows organizations to limit AI agents to explicitly authorized systems and services, the company said in a press release shared with CSO ahead of its publication. The offering is aimed at mapping what an agent identity should be allowed to touch, then enforcing it at the host firewall so everything outside that set is denied by default. “We’re doing the same thing for AI agents that least privilege did for people, except now it must be automatic,” said Benny Lakunishok, CEO and Co-founder of Zero Networks, in the release. “If an agent gets fooled or misused, it should hit a wall almost immediately, not wander around the network looking for something valuable.” Not another IAM or PAM offering Rather than competing directly with identity providers or privilege access management platforms, Zero Networks positions Least Agency Enforcement as addressing what happens after an AI agent has already received valid credentials. According to the company, conventional IAM, PAM, and non-human identity (NHI) platforms primarily govern whether an AI is entitled to receive access. Once an authenticated session begins, however, those tools generally do not control where the agent can move across the network, Boehm argued. Instead, Zero Networks’ enforcement works on both the identity and network layers. It claims understanding and restricting communication to authorized agents, as well as having sensitive protocols routed through MFA as a backup against compromises. “Sensitive paths get an MFA prompt on the protocols itself, so a compromised agent identity can’t quietly use RDP, SMB, or WinRM to move sideways,” Boehm explained. Least Agency Enforcement builds on the company’s existing AI security portfolio, which includes AI agents Control, AI Segmentation, AI SaaS Control, and protections for enterprise LLM deployments. The capability is available immediately and will be demonstrated at Black Hat USA 2026, where Zero Networks plans to showcase its broader AI security platform.
Read full story at CSO Online →