In short
Zero Trust for AI agents, based on an Anthropic framework for deploying autonomous agents in enterprises. It argues that perimeter security is insufficient because attackers can use agentic coding tools too, so organizations must authenticate agents, restrict their privileges (“least agency”), monitor behavior, validate inputs/outputs, and plan recovery.
Guests (hosts)
Daniel Whitenack, CEO at Prediction Guard; Chris Benson, principal AI and autonomy research engineer.
Key claims
Most enterprises aren’t ready to secure agents with zero-trust controls; agent threats include prompt injection (including indirect via files), tool/resource misuse (e.g., MCP servers exposing unintended endpoints), identity/privilege abuse (agents spawning higher-privilege agents), supply chain/dependency risks (models, MCP servers, packages changing at runtime), and memory/context poisoning (including RAG/vector DB poisoning).
Notable examples
A PDF with hidden “white text” instructions to trigger indirect prompt injection; an API/MCP “/docs” route example showing how agents could discover and misuse unallowed endpoints; healthcare memory poisoning where patient A is redefined as patient B to corrupt later retrieval.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOSetting the Stage for AI Agents
0:36 to 2:16
Discussion on the significance of zero trust for AI agents in enterprise settings.
“Welcome to another Practical AI podcast episode.”
The Role of Autonomous Agents
2:16 to 4:10
Exploration of how autonomous agents can create value and the need for security measures.
“covering the new threat landscape, a tiered zero trust architecture, and defensive operations built for AI accelerated attacks.”
The Dual Nature of Autonomous Agents
4:10 to 6:05
Analyzing the positive and negative impacts of adopting autonomous agents in organizations.
“I guess that's a good place to start with the kind of premise of this.”
Understanding Zero Trust in AI
6:05 to 7:46
Defining the zero trust cybersecurity model and its application to AI agents.
“So I think there's the positive side of this, obviously, which is there's a future where autonomous agents are doing very positive things and you have this kind of digital workforce of agents within your organization.”
Current State of AI Security
7:46 to 12:55
Discussing the challenges organizations face in adopting zero trust principles for AI agents.
“If we assume that, then you say, well, okay, well, now we're going to have these autonomous agents operating in our environment.”
Framework for AI Agent Security
13:13 to 14:00
Overview of Anthropic's proposed framework for securing autonomous AI agents.
“able to cover in detail but i think the overall structure that they present are some some kind of initial background and considerations, kind of definitions related to autonomous systems that people need to consider.”
Understanding Agent Operations
14:00 to 18:04
Explore how agents work, their communication and security terms.
“why are we talking about like a new framework?”
Current Threats to Agentic Systems
18:04 to 21:09
Learn about the main threats to agentic systems, including prompt injection.
“And I guess the other, so that's threat number one, prompt injection, instruction manipulation.”
Privilege and Identity Risks
21:09 to 24:50
Discuss identity and privilege abuse problems in agent operations.
“cybersecurity book from, uh, it's like the cuckoo's.”
Supply Chain and Dependency Risks
24:50 to 28:00
Examine the risks associated with supply chains in AI agents.
“The next one that Anthropic highlights is supply chain and dependency risks.”
Show all 16 chapters
Challenges in Patient Data Security
28:00 to 29:18
Learn about potential data security issues in healthcare AI agents.
“where it was a healthcare situation and someone, you know, an agent or a prompt is like in a first interchange, it says, hey, do this for patient A.”
Capability Tiers for Security
29:18 to 34:06
Explore the three capability tiers for AI security: foundation, enterprise, and advanced.
“different areas you need to do something.”
Access Control and Behavioral Monitoring
34:06 to 39:38
Understand the significance of access control and the importance of behavioral monitoring in AI.
“The next category that they talk about is access control and privilege management.”
Integrity, Recovery, and Implementation Phases
39:38 to 41:26
Delve into integrity, recovery processes, and phased implementation strategies for AI agents.
“you know, going back a couple of points to behavioral monitoring and trying to identify what's appropriate for agents to be doing, you know, within all the other security parameters that we've talked about along the way.”
Adapting Zero Trust for Dynamic Capabilities
42:08 to 45:06
Learn about evolving zero trust principles to accommodate dynamic AI capabilities.
“And they give some kind of specifications under each of those phases for people to think about.”
Cybersecurity Revolution and Future Tools
45:06 to 46:06
Explore the rapid changes in cybersecurity and the need for new tools and strategies.
“I mean, this is a revolution in cybersecurity, just to put a dot, you know, as we're finishing up here.”
Transcript
Automatic transcript. May contain errors.0:02Welcome to the Practical AI Podcast, where we break down the real-world applications of artificial intelligence and how it's shaping the way we live, work, and create. Our goal is to help make AI technology practical, productive, and accessible to everyone. Whether you're a developer, business leader, or just curious about the tech behind the buzz, you're in the right place. Be sure to connect with us on LinkedIn, X, or Blue Sky to stay up to date with episode drops, behind-the-scenes content, and AI insights. You can learn more at practicalai.fm. Now, on to the show.
0:41Welcome to another Practical AI podcast episode. This time, it's just Chris and I, my co-host. In these episodes where it's just the two of us, we try to take something that's in the AI industry. news or a topic for a deep dive, something that will help all of us level up our AI and machine learning game. I'm Daniel Whitenack. I'm CEO at Prediction Guard, and I'm joined as always by my co-host, Chris Benson, who is a principal AI and autonomy research engineer. How are you doing, Chris? Hey, doing great. Lots of cool stuff out there. Looking forward to today's conversation. Yes. Yeah, for sure.
1:19There's no shortage of things to talk about. But even in our, I don't know if you remember this passing comment, Chris, but I think it was in our episode where we were talking about MCP on top of Kubernetes, the guest mentioned that, hey, when Anthropic kind of drops one of these white papers or research topics or blog post, often that's a window into something that's significant and something to pay attention to and review in detail. And it just so happens that they, on May, I think, 27th of this year, 2026, released this, I guess it's an e-book, white paper, blog post, however you want to framework around zero trust.
2:11Yeah, zero trust for AI agents. Say zero trust for AI agents. We share a security framework for deploying autonomous AI agents in the enterprise, covering the new threat landscape, a tiered zero trust architecture, and defensive operations built for AI accelerated attacks. So that's a lot of words. Now, I think first off, Chris, it's probably worth recognizing that Anthropic obviously has a horse in this race, especially with things like Claude Code or Claude Cowork or all the Claude things. These are autonomous agents that can operate in your enterprise environment. So obviously, I think probably there are things that are happening and things where their customers or people using these tools are obviously thinking about the security implications of that.
3:02They also recently released Cloud Security, which is more on the AI for security side, not so much the security for AI side, which is mostly what we'll talk about today in relation to this article or ebook. But yeah, I think that's worth acknowledging. Obviously, if people have a secure way of deploying autonomous agents. I'm sure they are hoping that many of those are built on anthropic technologies. I'm sure they do. And, you know, just to keep in the back of our mind, this is the same organization that has Mythos out there and is working with, I believe the latest number is 150 organizations is the latest thing I saw published on their website, trying to go through and do security audits and such as that.
3:53And with the timing of this, I would guess, don't know, but just making a guess that some of the leveling up that Mythos has enabled is probably driving some of their zero trust and other security concerns going forward. So looking forward to this. Yeah, yeah. I guess that's a good place to start with the kind of premise of this. I think there's a few things to frame here maybe. Maybe one is there is probably a segment of the market and of our audience that is already using autonomous agents for something, even if that's just like cloud code or or something like that for development purposes, where by autonomous, I mean, it's making actions on on your behalf to do some things.
4:40And I think generally, in terms of where we're seeing the market going, on the positive side, organizations are going to need to more and more adopt these autonomous agents within their organization for value creation or new revenue or saving on operational efficiency. So that's like thing, you know, premise one is that that's the way the market's going. I think the other kind of background to this, though, is like you were saying, there's a bit of a forcing function here because AI or how should I? so attackers, so malicious parties, hackers, et cetera, have equal, you know, they have equal access to these agentic coding and development capabilities themselves, right?
5:33Meaning that the pace at which people are about to be or are already being attacked and exposed to threats in their infrastructure is just like expanding exponentially, which means you cannot keep up with that level of attack using human-only approaches, meaning that the forcing function that I'm talking about is you are necessarily going to have to adopt autonomous agents at least to help you manage the threats associated with the offensive use of this AI technology. So I think there's the positive side of this, obviously, which is there's a future where autonomous agents are doing very positive things and you have this kind of digital workforce of agents within your organization.
6:20But maybe part of the forcing function behind this discussion is that people actually need to adopt autonomous agents because of this offensive threat to their infrastructure. Yeah, I agree. And I think that'll put quite a strain on a lot of the humans involved in this because, you know, there's a certain amount of leveling up from a human standpoint to understand what different harnesses are and what the different capabilities that are now becoming available, understanding different vendors versus open source and such as that. So to actually get to the point where you can start implementing these is a bit of a lift.
7:00And I think that that's going to be something that we observe is that I think there'll be a spread across organizations where you'll have some, you know, on one extreme end, you have the anthropics that are leading the way and producing these capabilities and stuff like that. But then there's a lot of kind of a mom and pop organizations or maybe not that small, but, you know, midsize and stuff like that that are going to struggle to level up just a little bit. And so I think we have some interesting, I think the security landscape will be very interesting, a little bit wild west in the days ahead as people, even if tools are available, they have to get to where they can uptake those and get productive with them.
7:44So, yeah. Yeah. So I agree. And I think maybe a way to get into this discussion is that if we frame the background with an assumption, and I'm sure there are arguments against this assumption, but let's assume that your organization is and will adopt autonomous agents for, you know, positive things, like I talked about operational efficiencies, new revenue, whatever that is, and or cybersecurity purposes. If we assume that, then you say, well, okay, well, now we're going to have these autonomous agents operating in our environment. They could cause all sorts of harm themselves. So it's like I could shoot myself in the foot trying to protect against the offensive malicious people by releasing a bunch of agents into my infrastructure and they themselves cause a lot of harm.
8:40Like, how do I manage those things? And Anthropic has, so they have not come up with this idea of zero trust, to be clear. This is a general concept, which we can talk about the definition of. But they're essentially releasing with this framework a way to think about a zero trust approach or a zero trust framework for managing AI agents or autonomous agents within your organization. So maybe it'd be good to just define that term first. In the past, if we think about cybersecurity, there's been what's generally referred to as perimeter-based cybersecurity. This is a more traditional model that would focus on that boundary of your organization and outside or internal and external.
9:35And the kind of core principle being that I'm going to trust everything that's inside and distrust everything that's on the outside. So there is a perimeter in which within that perimeter, I trust things. A zero trust approach to cybersecurity, on the other hand, would actually assume that everything inside the network, that threats are already inside your network, already inside your parameters. So it treats every user, device, request as a potential threat. So that's why it's called Zero Threat. And like I say, this has been something that's been around for a long time. NIST has published about it in Zero Trust Architecture back in 2020 and other government organizations and others have talked about it as well.
10:30So that's that kind of difference. I don't know if that zero trust idea has crossed into your perimeter of knowledge, Chris, I'm sure. Yes. You know, without going into any detail at all, working in defense and intelligence, that is pretty core. and yeah I mean the simple way of thinking about it is every single API request that you have has to have security credential and that can be from a variety of different mechanisms but you don't trust anything and everything is down to a granular level unless it is authenticated and authorized to do whatever it is trying to do so in the world that I'm living that's pretty standard.
11:16Though, I think there's room for all of us, even those of us who have been doing it, to level up and get better at this. So I don't think that there's anybody who has just nailed it. So it's one of those ongoing learning curves. Yeah. And we're about to dig into a lot of that as related to AI agents. However, to your point, there's a lot of organizations that are still trying to think about this concept even generally in their kind of general cybersecurity world. And, you know, one of my one of my hot takes here is is we'll talk about that these kind of foundational things that Anthropic is suggesting.
11:56And, you know, probably 90 percent of plus of of organizations, enterprises that have AI deployments currently are not operating according to this model. They are, according to this framework, they would be completely exposed. And I think, so just acknowledging much of this is probably aspirational for enterprises and they need to work towards it in a, maybe a more rapid way, just because of how things are advancing. And, you know, there's better tooling out there day by day, better products, et cetera. But yeah, This is just just so if you're out there and you're thinking, I have agents running and I have none of what we're about to talk about.
12:40That's probably the situation that most are in in in the enterprise world would be. Hopefully today we can we can help people start on on a path here. Yeah, exactly. Next week, you have no excuse. But coming into this conversation, you you have an excuse.
13:01yeah exactly um so i i think the i would encourage people to if you just search for zero trust for ai agents you know anthropic blog post we'll link it in the show notes as well so you can click through to that ebook um and the framework itself there's a lot that we won't be able to cover in detail but i think the overall structure that they present are some some kind of initial background and considerations, kind of definitions related to autonomous systems that people need to consider. And then they talk about the current threats to those agentic or autonomous systems, and then how to apply this zero trust to those threatened agentic systems.
13:44That's kind of the flow of what they talk about. So the first thing, and I think this is something we've talked about more on the show and have already covered, but just to set the foundation, some of these considerations, kind of background information that we may want to give is that, you know, why are we talking about like a new framework? Well, agents are different in how they operate. We've talked about this on the show before. They use a distributed set of tools. They interpret instructions, try to accomplish goals. They execute operations without human initiation, I think importantly, they might preserve context across sessions if they're trying to accomplish some goal.
14:28And then you kind of add multiple agents and they might communicate with one another. So you've got this multi-agent communication. Now, there's a couple of terms here, Chris, that I think we've even mentioned, but they just define specifically related to agent security as new terms that people might be unfamiliar with. One is blast radius, which kind of I think people could assume what that means, right? It measures the potential damage if something goes wrong, if an agent does go off the rails of that blast radius. And least agency, which I guess is a term coined by OWASP. And that extends this kind of idea of least privilege to agentic applications.
15:16So you shouldn't be giving more agency to your agents than they need to do their agent things. And that's standard zero trust ideas. You give it just what it needs and absolutely no more. Yep. And so that's kind of the, I guess, the background in which we're operating. Then the anthropic paper goes into these current threats, which is some are ones we've talked about. Some are ones we've not talked about as much, Chris. It's interesting that they talk, they kind of frame everything within the agent world as agentic systems, which I very much like in our product. That's why I insist on using the idea of AI system as a thing, because you have these distributed set of things that are powering agents these days.
16:05And so they kind of break down then this like current threats to agentic systems. The first of those, which is probably not a surprise because it's the first on OWASP's list often as well, is prompt injection and instruction manipulation. Again, we've talked about this. there's everything from the obvious direct, you know, human input into a chat interface, ignore your instructions and do this other thing, which you shouldn't be doing. But the one that they mentioned as the more difficult or scary one would be the indirect prompt injection, where that's coming in through maybe it's a file that's, you know, you have an agent connected to your email and attachment comes through with hidden instructions in it.
17:00Anecdotally, I helped another company do some interviews and I wrote a technical exercise and put it in a PDF. And I knew everyone would use quad code like they should. But just because I wanted to be fun, I had all the instructions in black text and then I had an extra like three fourths of a page. So I just filled up that page with instructions that would make Cloud Code do the opposite of what I was saying in the instructions, just to see if they would catch it. So that sort of thing. Very devious. Very devious. It was fun. Did you make it white text in the PDF so it wasn't obvious? Yes. White text.
17:43Which would get interpreted if you just uploaded it into Cloud Code or whatever. That's very sneaky, but actually quite common in terms of vector. I mean, because everyone just throws everything they can, you know, the way things have been operating. And so, yeah, that's what we're doing today. Yes, true. And I guess the other, so that's threat number one, prompt injection, instruction manipulation. Threat number two that they talk about, which is related to agents using tools, particularly through MCP, which was a topic on a recent episode of this show, which you can look back at for much more information on that.
18:28On MCP. On MCP, yeah. So they talk about agents that can manipulate tools maliciously or kind of do things that they shouldn't be doing because of privileges. is I think about Chris like it's kind of like you set up a server maybe I set up a fast API API that you know my agent could use and I only tell it about instructions you know about a couple get routes on the API in the instructions but I don't shut down the other routes right and if the agent was smart in any sort of way, right, it could just look at the Swagger documentation at the slash docs endpoint and know about all the other routes that maybe it shouldn't use.
19:19And then like all of a sudden I have problems, right? That's right. Yeah. And just to clarify, Swagger is a protocol that defines what those routes are. And, you know, you mentioned, you know, kind of going off the rails, but, you know, the notion of malicious MCP server has now been documented and there could be lots of various types of tooling that is coming into being now just to take advantage of these vulnerabilities. So, I think we'll see a whole class of malicious software arising to do these kinds of tool and resource misuse. Yeah, exactly. And a lot of times these tool descriptors or schemas or metadata is injected into the context for an LLM to actually generate the output.
20:09So if I'm a malicious party or maybe just an agent that doesn't know what it's doing and, like I say, has drifted from its goals or something, there's nothing preventing that from doing this poisoning thing where I find out about the descriptor schema and metadata and I even modify that in the instructions to maybe get the MCP server to do different things. So this tool and resource misuse is definitely a reason why it's kind of number two there. The next one, identity and privilege abuse. So yes, yes, exactly. So they talk about this. agents often operate with elevated privileges or service accounts and traditional identity systems designed for humans struggle to accommodate them uh there's sometimes unscoped privilege inheritance um almost like i i kind of think about this like um what was uh uh that uh that cybersecurity book from, uh, it's like the cuckoo's.
21:20Yes. The cuckoo's nest or something. Someone can tell us in the comments, but it's like you, you kind of land one place in a network and then you escalate privileges. Right. And you can move laterally and go in all of these directions. Right. Really old book. It was one of the original cybersecurity books that came out before it was really a field. Um, I read it many years ago and yeah, definitely inspiring. Um, Yeah. And so. The cuckoo's egg. That's that's what it was. Yeah. And as you are looking at lots of different agents that have different levels of privilege and different capabilities, and as agents are formulating things, you know, during runtime, essentially, that didn't exist as a preset static thing that you want to do, and they're developing that, it's very easy for one agent to spin off another agent, and it has more privilege than it needs, and then that can be taken advantage of.
22:16So there are lots of different variations of of how those kinds. Yeah, yeah, for sure. So that's the privilege. And I should say, I do really encourage people to take a read through the ebook. Obviously, we're highlighting some of these things, but there's much more detail there. Also, a great resource around this, if you're trying to learn some of this, is if you go to the OWASP Gen AI project, We've had reps on our show before and my team's involved in the AI Balm project and other things with OWASP. There's a lot of great people involved, but they have so many great resources online related to this sort of thing and guides for MCP, guides for agentic security, etc.
23:01So take a look at those as well. You might be listening to this episode and thinking that, hey, I am part of one of those organizations that's in the 90 % of enterprises that are not ready security-wise for autonomous agents operating in my environment. How am I going to manage supply chain risks and have an AI bill of materials and define agent boundaries, secure tool access and implement input validation and output controls. Well, this is one of the reasons why I think it's so important to have great platforms that don't require you to build your own AI agent governance platform. That's why outside of the Practical AI podcast, I personally am leading an organization full of really smart people that are thinking about these problems and have brought Prediction Guard into existence.
24:00Prediction Guard is an AI control plane that's self-hosted. It lives in your own infrastructure where you're going to deploy those autonomous agents. And it allows you to manage this supply chain risk and put in governance policies that are enforced and maintain observability over those agents. And I'm just really excited about the capabilities that are already in the product and are being released later this year. So I would encourage you, please check us out at predictionguard.com slash practical AI. You can book a call with me and the team to discuss how you're going to manage security for your agents operating in your enterprise.
24:42That's prediction guard.com slash practical AI prediction guard.com slash practical AI. The next one that Anthropic highlights is supply chain and dependency risks. So you were just mentioning how sometimes agents compose things at runtime, Chris. This includes potentially loading external tools or installing packages or changing infrastructure. And so that supply chain can actually update in real time or at runtime as agents are trying to accomplish a task, but also model and tool supply chain. So models have their own supply chains related to the weights and how they were trained or fine tune, how easy it is to jailbreak them or prompt inject them.
25:34But then MCP servers are also software components, right? They have their own integrations, their own software dependencies, et cetera, which have their own potential vulnerabilities. So all of this, it's very much a multilayered thing that could evolve dynamically, which is kind of scary. And one thing to call out while we're talking about supply chain and dependency risks is that all of the traditional zero risk vulnerabilities, all the things that we were talking about in the cybersecurity world before we started having, you know, AI agentic system conversations about this, those all still apply as well.
26:12And I was prompted, no pun intended, to say that by you when you mentioned the multi-layer. So you can still have BIOS and CMOS vulnerabilities that lend themselves to some of these vulnerability layers and packages that build up. So there's many different points in a stack where these attacks can occur. All the way down to, you know, networking and firewall, right? If you're, if you're have an agent operating in that environment, it could, you know, find and detect things that, that it shouldn't. And so, yeah, it's, it's so, yeah, I guess multi-layered, which, you know, many security things are.
26:59And I know OWASP always recommends this kind of layered approach. But yeah, the last two are kind of related memory and context poisoning and RAG poisoning. Both obviously are this type of way that you can either in the memory or context to an LLM call or into RAG data, retrieval augmented generation data, which often lives in a database, a vector database. if you have no control over what and how things are committed to that memory or to that vector database there's nothing preventing agents or external parties from inserting things into that memory so you know the I think the one the example I used last year at the Midwest AI Summit Chris which as a reminder to our folks Midwest AI Summit coming up October 15th going to be another great great experience.
27:57You can search the details, Midwest AI Summit. But I think I used the example where it was a healthcare situation and someone, you know, an agent or a prompt is like in a first interchange, it says, hey, do this for patient A. And then you in the follow-up say like, well, in all the following, you know, consider patient A to be patient B. And then you keep filtering in that information about patient A being patient B. And then all of a sudden, when, you know, later on you're, you're wanting some information about patient A or patient B, all of a sudden you're getting data that you shouldn't, shouldn't be getting.
28:39So it can happen. Um, and, and has been shown to happen. So, um, okay, Chris, that's all the scary things. I guess there's a lot of them. Now we got to go, now we got to figure out how to fix this, right? Now, now we got to figure out how to fix this. And I do like the general structure that Anthropic provides here, recognizing, again, that many people are behind in this and that new tools and products will need to address many of these things gradually over time. They present three capability, I think what they call capability tiers or three tiers of application, basically saying, hey, in these different areas you need to do something.
29:24There's like the minimal thing that you should do, which they call foundation, the minimum viable thing. And then there's an enterprise tier, which means, hey, if you're an actual enterprise and needing to be robust and resilient, you need to do these things. And then there's advanced, which would apply to kind of particularly high risk or stringent regulatory environments, or maybe aspirationally for everyone else to try to get to that get to that level so foundation enterprise and advanced in each of these categories and then for uh they develop something in each of these categories for each of a number of uh the threats that that we talked about or the areas in which you need to secure the first one that kind of dimension it kind of breaks them down by different by dimensions and then tiers them against those three tiers that you just described?
30:21Yeah, it's kind of like I need to I need to consider these however many things I forget how many there were. I need to at least be in the foundation level for all of these. And then I can circle back and maybe upgrade particular ones to enterprise or like gradually work on it over time. So the first of those is agent identity and authentication, which they kind of frame as the foundation for every other security capability, because without this identity, you can't really enforce other things throughout the framework. Now, as we go through here, they talk about certain ways of doing identity and verification.
31:04And there are a couple terms in here that people may be unfamiliar with as well. One of those being, they talk about hardware bound credentials. Have you, I'm sure this is also a part of your life over time, Chris. Hardware bound credentials are where you have to present, you know, you may be a USB or something, you know, there's a lot of different ways it can, but you have to insert a piece of hardware or make accessible a piece of hardware which provides that authentication which an adversary would be unlikely to have in their possession. And that doesn't necessarily do it by itself. There's usually multiple tiers, but that is one way of contributing significantly is if you don't have a physical piece of hardware in your hand, you're not going to be able to gain access, even if you can break through other tiers.
Read the full transcript
31:58Yeah. And this idea of it being bound to hardware, I think, is the key point that you're referencing, Chris, where otherwise they view kind of, hey, if you have API keys, for example, and those are just floating around, you should probably consider those already compromised if we're going with this idea of zero trust versus if an agent has an identity and has an authentication to access this environment. It has authentication tied specifically to the hardware that it's operating on, you know, something like that. That hardware bound credential is something that they talk about. And just to give some examples here in the agent's agent identity and authentication piece, the foundational, and we won't be able to go through all the tiers of all the categories, we just don't have time but just to give an example of of these there is the agent identity identity verification piece the foundation level that they suggest there is to have unique cryptographic identifiers for each agent instance so to assign persistent agent ids backed by cryptographic material, not just labels.
33:22The track agent lifecycle from creation to retirement, ideas appear in all logs and access requests. The enterprise level is certificate-based authentication with full lifecycle management. And the advanced is hardware-backed identity with attestation. So that advanced, you know, you store agent credentials in hardware security modules or trusted platform modules with remote attestation, which there's a whole rabbit hole. You could go down there with those terms, but that would fit into their advanced category. That's right. Yeah. So that's an example of one of these categories, agent identity and authentication.
34:07The next category that they talk about is access control and privilege management. So assuming you have an identity for your agent, then you need to control access and privileges for that agent. And that authorization layer should enforce this idea that we defined earlier of least agency, which is ensuring agents receive only the access required for their specific function. And this can get very subtle, like that API example that I gave. You could only tell an agent about these endpoints, but if you haven't literally shut off the network for other endpoints or something, then there's nothing preventing that agent from going off of the rails in that case.
35:00So, yeah, just to give another kind of set of examples here, access control foundation level is role based access control or RBAC with deny by default. That's the foundation and in that category. That's right. And by the way, just as we're working through this, wanted to make one quick comment. These are all standard zero trust concepts. So those of you who in the you know, who may be watching, you may recognize a lot of these categories and stuff. And I think the key is kind of thinking about it within this agentic context. And, you know, as we're all onboarding agents and stuff, that throws it out.
35:40But keep going. I just wanted to call that out for those that might recognize that. Yeah, yeah, for sure. I think we can't abandon our good security intuition. And especially when you start treating these agents as having an identity and being operating in this zero trust environment, some of these things kind of flow through if you work out those details. But yeah, the next category, behavioral monitoring and response. Sorry, observability and auditing. That was, so there's actually these two are tied together. we could probably talk about them together there's observability which essentially captures what agents do so it observes what agents are doing and you need visibility into that so you need logging and audit trails often in our implementations with customers in my day-to-day work i often like to say hey we need to know that this human user using this api key triggered this agent which has this identity to do this goal, which issued these prompts, which triggered this tool call, which had this input, which was blocked by this governance policy, et cetera.
37:01Like that's where we're, you know, and down the line, we need that kind of traceability and logging. Otherwise you can't have visibility or build rules or monitor things. So that's the observability piece, but observability captures only what agents do. The behavioral monitoring that they're talking about determines whether the actions that agents are doing should be allowed or are suspicious. Are they appropriate for what you would expect? Are they appropriate? Yes. That's right. Yes, exactly. And this is behavioral monitoring and response, right? So in certain cases, like I say, when we enforce governance policies, we say, well, if we see this, then do this, right?
37:49So sometimes that's blocking certain things. Sometimes it's just logging. Sometimes it's, you know, alerting someone using a particular platform. Okay. The second to the last one is input validation and output controls. I think actually this one, so what are we on? One, two, two, three, four. This is the fifth one. This is probably the one that most often comes to people's mind and I think is often maybe overemphasized, which is this idea that you would have point checks over, you know, harmful things that the agent could produce in its output or harmful things that could go into the agent's context or something.
38:35This is very important, I would say, but it's kind of like table stakes. The example I usually give is, you know, is it bad for me to take my temperature if I want to be a healthy human? Well, it's not a bad thing. You know, you can take your temperature. It doesn't mean that you are plugged into a healthy lifestyle or being governed by, you know, health records and as part of a healthcare system and have a primary physician and have a care plan and a diet. And it's just a very limited way to view that kind of overall health. And if we extend that here, this would be these sort of point checks of validating inputs and outputs, which are, yeah, again, I would say those are table stakes.
39:19And the last one is integrity and recovery. So all of this prevention and detection assumes agents operate correctly, you know, when they don't, what do you do? Yeah. And I think that's actually a pretty big question in the agentic systems world. And that if you think about, you know, going back a couple of points to behavioral monitoring and trying to identify what's appropriate for agents to be doing, you know, within all the other security parameters that we've talked about along the way. But when you have gotten outside the bounds of what is appropriate, trying to figure out how to roll agents back, especially if they're in critical functions, can be quite challenging because those critical functions still have to be addressed.
40:04And so if a critical function is compromised by an agent that is intentionally or unintentionally off the rails, then figuring out how do you take a critical system back and get it back to a safe place to proceed in whatever is appropriate for that function can be quite challenging. And so So I have spent some time in that space myself. And I think that there's a lot of imagination that has to go into it that maybe wasn't quite as necessary in pre-agentic zero trust models. So I just wanted to call that out. Yeah. Yeah. They talk about, to give some examples, Chris, for configuration integrity.
40:48they talk about on the foundational level, version controlled agent configurations and the advanced level immutable infrastructure with attestation. On the recovery capabilities, they talk about at the foundation level, documented rollback procedures, which to your point, having an idea of what you might do is one thing, being able to actually do it is sometimes a challenging thing. At the advanced level, they talk about self-healing systems with automatic remediation. So yeah, definitely agree with your points there. I know that we're getting close to the end here, Chris, and just to kind of wrap things or get close to the end here, Anthropic does a good job at kind of saying, hey, here's all of this stuff and all of these tiers and levels and categories, etc.
41:42But then they do provide a kind of phased way that you can think about implementing agents, which I think is helpful. One, identifying requirements. Two, managing supply chain risks, including they talk about AI bomb or AI build materials. Defining agent boundaries, defending against prompt injection, securing tool access, protecting agent credentials, and then safeguarding agent memory. And they give some kind of specifications under each of those phases for people to think about. Yeah, I think, you know, as we're winding up, as they address it, I know just to share kind of how I perceive the, you know, kind of establishing the workflow is in the zero trust world that we've been in for a number of years, it's fairly static.
42:31You know, there's a lot of things and you kind of have to tick them all off. And a lot of it's a very it's almost a regulatory approach to system development. And I think the thing that agentic implementations require is the is trying to anticipate an incredibly dynamic capability that can arise. you know, kind of an emergent quality that people are doing. And I think what Anthropic has done for us is given us a way of taking what we already know in a zero-trust context and point it out, you know, that within agentic systems, these capabilities are, it definitely requires a level up to take the same ideas, but get them out of that static mindset and move into anticipating dynamic capabilities from agents.
43:22And I know as we're both in our own jobs and stuff, that certainly required us to kind of level up and reconsider. It makes it for a very interesting problem set to address. Yeah, yeah. And there's major thought process changes or philosophical shifts, as you're mentioning, that as practitioners we may have to make. They talk in the in the e-book Anthropic does about this idea of AI vendoring that, hey, there's these fragile open source projects out here that you might rely on. The thing to do might just be to have your agentic coding system just completely vendor or literally not copy, but generate a new version of that project that's proprietary to you and under your control and just include it in your project rather than bringing in a third party dependency.
44:17So there's like philosophical shifts like that. I do think there's some hard things that we'll still have to wrestle with around. I think there's still some of this conclusion that humans are going to have to make containment decisions around how to contain these things and whether it be threats in your environment or agents operating in your environment. And if things are moving so fast, I just think it's going to be hard for humans to, you know, if something is happening in your infrastructure and exploit timelines go from, you know, months to hours to minutes to seconds, you can't just like rely on waking up the CISO in the middle of the night to prove, you know, shutting this thing down.
45:06I mean, this is a revolution in cybersecurity, just to put a dot, you know, as we're finishing up here. Every intelligence agency in the world is learning how to both defend against and exploit these potential vulnerabilities that we're talking about, as well as criminal organizations of all sizes, shapes on a global scale. So this, you know, I think we're at the very beginning of this journey. I think this is a fantastic start to get us thinking. I think we're going to see a lot more tooling and a lot more capabilities coming out in the days ahead. And it seems to be coming out very quickly because the threats have risen very quickly.
45:53And so I hope folks find this as useful as we did in terms of kind of reframing this modern take on cyber in this agentic world that we've been talking about nonstop throughout this last year. And we'll, like I say, include the links in the show notes. So take a look at those and excited to keep the conversation going. Thanks for this today, Chris. Yeah, thanks for taking us through it. It was a good exercise today we do.
46:26All right, that's our show for this week. If you haven't checked out our website, head to practicalai.fm and be sure to connect with us on LinkedIn, X, or Blue Sky. You'll see us posting insights related to the latest AI developments, and we would love for you to join the conversation. Thanks to our partner, Prediction Guard, for providing operational support for the show. Check them out at predictionguard.com. Also, thanks to Breakmaster Cylinder for the beats and to you for listening. That's all for now, but you'll hear from us again next week. Thank you.
From the publisher
As AI agents become more capable and autonomous, they also introduce new security challenges. In this 'Fully Connected' episode, Dan and Chris unpack Anthropic’s Zero Trust for AI Agents security framework and what it means for organizations deploying agentic systems. They examine the key security risks facing agentic systems and discuss how organizations can apply Zero Trust principles to deploy AI agents safely. Along the way, they break down practical security controls and discuss how traditional cybersecurity principles must evolve for the age of AI agents.
Featuring:
Links:
Sponsors:
- Prediction Guard: A self-hosted AI control plane for running agents in high impact environments. predictionguard.com/practicalai
Upcoming Events:
- Register for upcoming webinars here!
- Midwest AI Summit 2026




