Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
Zero trust creator John Kindervag's new book argues the model still stops AI-assisted attacks, but only if correctly implemented.
John Kindervag, who created zero trust at Forrester in 2010, has published "Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era," arguing the model remains effective against AI-assisted attacks. Contributors conclude AI threats are fundamentally the same threats, just faster, more sophisticated, and at greater scale, and that correctly implemented zero trust can still halt them. The review cites the Hugging Face incident, where a swarm of 700+ rogue OpenAI agents defeated network isolation, exploited template-injection flaws and RCE paths, harvested cloud credentials, and moved laterally before humans noticed activity spikes. Key risks are policy engines failing to reflect organizational posture or being manipulated by rogue agents and insiders.
- Kindervag's book claims correctly implemented zero trust still halts AI-assisted attacks
- Contributors argue AI threats are faster, larger-scale versions of existing threats
- Cites Hugging Face incident: 700+ rogue agents escaped isolation and moved laterally
- Policy engine accuracy and protection from rogue-agent manipulation are the main failure risks
Full article736 words · extracted from securityweek.com · click to collapse
Is zero trust still effective in the AI era? A new book from John Kindervag says yes, but that assumes it is correctly implemented.
John Kindervag introduced the concept of zero trust in a Forrester Research report titled No More Chewy Centers: Introducing the Zero Trust Model of Information Security published in 2010. Since then, the concept has become a foundational precept within cybersecurity. Fifteen years later, he was asked to write a new book about zero trust in the age of AI.
The big question is whether 15 years-old security principles remain valid in the face of new AI-assisted threats.
The book response to this question, Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era, is now published. Kindervag decided not to write it alone, inviting individual experts to contribute individual chapters on the primary principles. The result is a somewhat disjointed book but with expert content.
The overwhelming conclusion from these experts is that zero trust is as competent against today’s AI attacks as it was fifteen years ago before modern AI appeared. Basically, the book asserts that the threat from AI is fundamentally the same threat as always, just faster, more sophisticated and at greater scale; and that zero trust can handle this.

This is a bold, and perhaps surprising statement in a new world that includes not just autonomous AI agents, but also rogue autonomous agents and AI-developed exploits for AI-discovered vulnerabilities. The Hugging Face incident is an iconic example of this. Rogue autonomous agents escaped from their developer (in this case OpenAI) and attacked a third party (in this case Hugging Face) without any active human guidance.
A swarm of more than 700 agents identified a way to defeat their own network isolation, escaped onto the internet and selected Hugging Face as a target. In a coordinated manner, they exploited template-injection flaws, remote-code execution paths, gained node-level access, harvested cloud credentials, and moved laterally across internal enterprise clusters. They were eventually detected by humans noticing unexpected spikes in activity. Zero trust principles should have stopped the attack earlier, leaving the possible implication that Hugging Face either wasn’t using zero trust or its use was inadequate.
Advertisement. Scroll to continue reading.
SecurityWeek used this and similar incidents to challenge John Kindervag’s assertion that zero trust is still fit for the AI age. He replied, “Of course AI is going to get better and better. Every 14 days, the models seem to have new capabilities. And Anthropic has recently, in its IPO prospectus, warned that AI technology could pose catastrophic or existential risks to humanity. But any AI-generated packet still has to move across the same network that attackers have always had to traverse – and correctly implemented zero trust can still halt it.”
The key phrase here is ‘correctly implemented’. The brain of zero trust is its policy engine. This controls the rules for when and how zero trust is imposed. Each policy engine is custom made and designed by each user organization to reflect its own security posture – and since postures change over time, it must be updatable.
There are thus two potential threats to correct implementation. Firstly, the engine must fully and accurately reflect the organization’s security posture. If it doesn’t AI agents are likely to find a way through. Secondly, the policy engine must be adequately protected from rogue agents or malicious insider manipulation, which could theoretically create safe passage for an attack. Both defensive requirements are possible but difficult to get right.
So, the book’s assertion that zero trust holds firm in the AI era is accurate, but only if correct implementation is achieved. This is the same as it ever was, but now more critical. The difference in today’ s AI era is that failure in correct implementation could have a catastrophic effect at a speed beyond the ability of human management to detect and prevent. The real message in Kindervag’s book is, “Get it right!”
Related: Zero Trust Is 15 Years Old — Why Full Adoption Is Worth the Struggle
Related: AI Has Changed Attack Speed, Not Security Fundamentals
Related: First Agentic AI Data Breach Reported to Spanish Regulator
Related: Hacker Conversations: John Kindervag, a Making not Breaking Hacker
Related: The Race to Control AI and Protect What Makes Us Human