Start with Identity
← Blog
News

Zero Networks ties AI agent identity to the network layer, with just-in-time MFA for the sensitive protocols

Zero Networks launched Least Agency Enforcement at Black Hat USA 2026, implementing OWASP's emerging Least Agency principle with identity-based microsegmentation and default-deny network access for AI agents, plus MFA prompts on RDP, SMB, and WinRM even when an agent presents valid credentials.

By SWI Community TeamAug 4, 2026Updated Aug 6, 2026

Zero Networks announced Least Agency Enforcement on August 4, 2026 at Black Hat USA, a network-layer implementation of OWASP's Least Agency principle for enterprise AI. The capability maps which systems a given agent identity should be able to reach, then enforces that map at the host firewall with default-deny for everything else, identity-based microsegmentation rather than a policy an agent could talk itself around. For higher-risk protocols specifically, RDP, SMB, and WinRM, it adds just-in-time MFA prompts, so an agent with valid but compromised or over-scoped credentials still can't move laterally without a human in the loop. Zero Networks cites its own 2026 Lateral Movement Exposure Report finding that nearly 80 percent of enterprises have already deployed internal AI agents while roughly two-thirds have no governance policy covering them. "If an agent gets fooled or misused, it should hit a wall almost immediately," said CEO Benny Lakunishok.

Why it matters

The framing worth noting is what it enforces against: not whether the agent's task was legitimate, but what it can technically reach if it's manipulated, misconfigured, or simply wrong. That's the same shift toward securing AI agent identities as a distinct, scoped problem that showed up repeatedly across Black Hat vendor announcements this week, treating an agent's credentials the way you'd treat any other identity that can be tricked into acting against its owner's interest.

The 80/two-thirds gap Zero Networks cites is the number to sit with regardless of vendor: if your organization has agents running with standing access and no zero standing privilege model behind them, this is the gap that gets exploited first, not a hypothetical one.

Source: CSO Online

Independent analysis. No vendor sponsorship.