Discover how to apply Zero Trust principles to secure AI adoption, manage agentic risk, and mitigate the threats of frontier AI models.
As businesses lean on AI for productivity gains and better customer experiences, security teams are struggling to secure this adoption. This challenge is further compounded by frontier AI models like Mythos. Not only are these models accelerating vulnerability discovery—leaving IT teams scrambling to secure aging hardware—they are also empowering enterprising IT engineers to spin up AI-powered agents to speed up operations.
“Yesterday’s insecure Python scripts have evolved into today’s insecure, autonomous IT agents.”
If we peel back the layers, while AI is a significant trend, security teams have weathered the internet era, the BYOD and mobility landscape, the age of cloud and cloud native adoption. And if there is one thing we have learnt, it is that security principles like least privilege access control are foundational to securing any new aspect of the technology landscape. These concepts are well rooted in architectural initiatives like NIST’s Zero Trust and are functional gaps that most organisations still need to close to secure the current AI era. (To see how these concepts translate into actionable architecture, explore my upcoming 4-hour Technical Seminars on Architecting Zero Trust and AI Security Playbook at Cisco Live Melbourne).
To demystify this further, let’s understand why security practitioners exist. At the end of the day, security practitioners’ primary mission is to ensure least privileged access to business critical resources to prevent data mis-use or leakage. However insecure code, whether it is in our applications or the underlying infrastructure that runs them, manifests as CVEs that can be exploited, ultimately leading to inadvertent critical exposures.
If all software was bug free, hackers would have very few vulnerabilities to exploit, and security tooling would be way less complex, but as we are learning, from frontier AI models like Mythos, CVEs are on an upward trajectory for now and the time to patch is an unattainable 8 to 9 hours. So while we can aim to patch faster, our true goal should be limiting access to business-critical resources and the underlying code and infrastructure that runs them, thereby preventing unpatched or worse undiscovered CVEs from being exploited.
This is where getting Zero Trust right at every layer becomes critical. This isn’t just a Cisco perspective—recent guidance from the CSA, SANS, and OWASP in their joint briefing ‘The AI Vulnerability Storm’ validates this exact approach. Their recommendations for securing the AI era rely heavily on establishing strict asset inventory and preventing lateral movement—which are, at their core, fundamental Zero Trust principles. Zero Trust principles are most commonly applied to the user layer (through the popular ZTNA), however as a concept Zero Trust is very extensible and can be easily applied to limit access to vulnerabilities at the application layer, the agentic and AI layer itself, and even down to every process, memory or file access at the kernel layer!
The Three Core Principles of Zero Trust for AIFounded in three core principles, a robust Zero Trust architecture requires us to execute the following phases comprehensively.
The above may all sound like pipedream, as most organisations struggle with Zero Trust programs and undelivered microsegmentation projects. However, Zero Trust and segmentation projects are being accelerated by AI powered tooling. Cisco is leading the AI powered Zero Trust platform race, with a common AI powered policy decision point (PDP in ZT verbiage) in Security Cloud Control, driving intent based policy into a mesh of policy enforcement points (PEPs) at every layer – from smart switches to firewalls (both Cisco and 3rd party), Security Services Edge, Workloads, Cloud provider native firewalls, cloud native Kubernetes service mesh, and into kernel level ebpf implementations on workloads and network infrastructure. AI assistance drives administrator declared intent into topology aware rules pushed to above PEPs via common interfaces. Ultimately AI driven platform approach is what makes Zero Trust achievable for the frontier AI era.

As for our most topical AI model – Mythos. While everyone is focussed on AI fueled vulnerability discovery, we now know from above that while patching is essential, its critical to get back on the Zero Trust bandwagon to limit our exposure. There is no silver bullet but to get our basics of least privilege access right.
On the positive side, AI is actually involved in the entire software lifecycle, not just the well-publicised vulnerability discoveries, but actually helping us fix vulnerabilities and even improve overall code quality.
As one of the launch partners for Anthropic’s Project Glasswing, Cisco’s early access to Mythos led to a few innovations. Firstly, our current disclosure model has been revamped to alleviate patching cycles and released as a more predictable risk-based disclosure model. Secondly, frontier AI models like Mythos are only as good as the agentic harness that drives them which led us to create and open-source Foundry security spec. Cisco has also been using AI, prior to Mythos to accelerate code development, but more importantly generate secure code and improve overall code quality, which led to Cisco donating Project CodeGuard to COSAI. In fact Cisco has also launched Antares SLMs which can further aid security practitioners and developers in vulnerability discovery when paired with Foundry security spec and fixing them securely using CodeGuard. There are also AI powered capabilities like Cisco IQ to discover vulnerable infrastructure, that works with Cisco Cloud Control, which is a new unified operations platform to aid in AgenticOps and patching at scale. And as we discussed there are features like LiveProtect to alleviate the gap between vulnerability discovery and patching.
Even with all these innovations, the patching gap is here for the foreseeable future. This is exactly why achieving a Zero Trust Architecture for the frontier AI era has transitioned from a best practice into an absolute operational imperative. Explore the Cisco Live Melbourne session catalog to add my 4-hour Technical Seminars—focusing on Architecting Zero Trust and the AI Security Playbook—to your schedule and start building your resilient architecture today.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Get Serious About Agentic AI and Its Security Risks | 0 | 10 | 17-06-2026 |
| 2 | AI Agent Governance: Securing Autonomous Agents in Production | 0 | 10.41 | 24-07-2026 |
| 3 | AI governance: Building trust in the age of AI video creation | 0 | 5.52 | 16-12-2025 |
| 4 | The agentic SOC for today’s air-gapped environments: rethinking cyber defense in the age of AI | 0 | 9.77 | 30-07-2026 |
| 5 | Why frontier AI must be stress-tested before CISOs trust it | 0 | 5 | 26-06-2026 |
| 6 | How to Build a Responsible AI Foundation for Your Agency | 0 | 10 | 01-06-2026 |
| 7 | AI Security Monitoring: Risks, Detection, and Automated Response | 0 | 4.73 | 07-07-2026 |
| 8 | The Agentic Insider: Why AI Tech Stacks Are the Ultimate Insider Threat | 0 | 5.76 | 15-07-2026 |
| 9 | Agentic AI in HR: How to create responsibly | 0 | 5 | 07-01-2026 |
| 10 | The Journey towards Logically Air-Gapped Deployment | 0 | 18.86 | 24-07-2026 |