
You’re reading an issue of “The AI Economy,” my newsletter exploring the forces shaping the AI era—tracking how AI is rewriting business, work, technology, and culture. Subscribe to get expert insights and curated updates delivered straight to your inbox.
As new AI agents accelerate their entry into the workplace, cybersecurity platform Zscaler is extending its Zero Trust Exchange to govern how these autonomous systems connect, access data, and operate across enterprise networks. On Tuesday, the company unveiled three new capabilities—AI Broker, AI Access Graph, and Endpoint AI Security—that together constitute what Zscaler calls the industry’s first complete Zero Trust platform for agentic AI.
The announcement, made at the company’s Zenith Live conference, targets a governance gap it argues most enterprises haven’t fully reckoned with yet. Unlike human employees who authenticate through established identity systems, AI agents create ephemeral identities, spawn sub-agents, and access sensitive systems at machine speed. They can be largely invisible to the current security tools organizations already have in place.
“Security has always evolved as an incremental thing,” said Swamy Kocherlakota, Zscaler’s executive vice president of agentic AI, in an interview. He likened traditional enterprise security to building a house: first, you add a door; then a fence to keep people out of the yard; then a path connecting the two. Each addition makes sense in isolation. The cumulative result, he said, is an industry riddled with disconnected point solutions: ”Scotch tape and chewing gum to keep it together.”
The Zero Trust Exchange is Zscaler’s solution to that problem, built on a single principle: never assume trust, always verify it. It’s a cloud-native platform that sits between users and whatever they’re trying to reach, inspecting every connection in real time rather than routing traffic back to a corporate data center for review. At its current scale, the platform inspects more than 750 billion transactions daily. Until today, every one of those connections involved a human on one end.
Creating Agent Visibility for CISOs
The problem, according to Kocherlakota, is that HTTP traffic doesn’t reveal whether it’s from regular web browsing or AI traffic. Because they’re technically indistinguishable, organizations struggle to govern traffic using their existing toolset. He claimed that since Zscaler sits between the user and the internet, it can intercept HTTP packets, identify those containing AI-related traffic, and apply AI-specific governance policies. That gives organizations something they currently don’t have: visibility into what employees and agents are sending to AI tools, and the ability to enforce business rules on the output.
Two new capabilities from Zscaler are designed to close this gap: AI Broker and Endpoint AI Security. With the former, the company’s Zero Trust Exchange becomes the intermediary for Model Context Protocol (MCP) and Agent2Agent (A2A) communications. It includes an Agent Registry to help organizations track what each agent is authorized to access and enforce permissions specific to its designated function, rather than applying a blanket policy across all agents. An agent built to read financial data, for example, shouldn’t also be able to write to HR systems or approve purchase orders.
The latter targets risks and threats on any device connected to an organization’s network. This includes laptops, desktops, smartphones, and tablets. Zscaler’s Endpoint AI Security will identify and mitigate any security issues, whether they’re hidden in browsers, plugins, extensions, or locally hosted AI tools.
As Kocherlakota put it, it’s all about giving CIOs and CISOs visibility into what’s being installed on company devices, letting them manage what an employee can and cannot do.
Zscaler Gets an AI Graph
Zscaler is also introducing the AI Access Graph, a real-time intelligence map for every identity, application, and data source within an enterprise. It’s designed to solve the problem of accumulated complexity. In a typical enterprise with 1,000 employees, Kocherlakota said the number of individual roles and entitlements can reach 10,000 or more across systems like Snowflake, ServiceNow, Workday, Oracle Financials, and Microsoft 365. Adding AI agents to the mix only compounds the number of connections with agents accessing databases, communicating with MCP servers, and operating across cloud environments. Nobody has a single view of what has access to what.
The AI Access Graph draws on technology from Symmetry Systems, which Zscaler recently acquired. Symmetry’s core capability is building knowledge graphs of entitlements, mapping which users and non-human identities have access to which systems, and whether those permissions are actually being used. It’s the intelligence layer that distinguishes the AI Access Graph from a basic monitoring tool by tracking excessive access and enforcing tighter permissions in real time. Zscaler Chief Executive Jay Chaudhry said such a capability wasn’t necessary until now, thanks to the rise of AI agents that have made the complexity of enterprise access too great to govern with existing tools.
That inability to govern AI with existing tools is, for Kocherlakota, the heart of the matter. Securing AI is not a refinement of current security practice but a genuinely new discipline, and one he believes most enterprises are underestimating. “Protecting AI is the net new,” he said. “If you don’t do protection, you will learn the hard way, and the cost of learning this hard way is not something enterprises are ready for at this time. That’s why we want to get ahead in protecting AI.”
Disclosure: I attended Zscaler’s Zenith Live conference as a guest of the company, with some travel expenses paid for. However, what I write reflects my own reporting and analysis. No one reviewed or approved this piece before publication.
