AI is no longer just answering questions or making recommendations. It is beginning to take action at the direction of users through autonomous agents, whether they're SOC analysts, researchers, developers, or threat actors. More than 80% of Fortune 500 companies are already using agents built with Microsoft Copilot or Agent Builder.1 Active agents across Microsoft 365 have grown 15x year over year, with that number rising to 18x in large enterprises.2 Agents are quickly becoming a part of how we work and moving into real business processes faster than security controls can adapt. The pace of adoption is creating a gap between what organizations can deploy and what they can confidently govern.
As organizations adopt AI agents, autonomous workflows, and AI-powered development tools, security teams are being asked to protect AI systems that can make decisions, access resources, and complete tasks with limited or no human oversight. Securing these systems requires continuously verifying access, enforcing least privilege, and evaluating risk through a Zero Trust approach.
This overall shift is forcing security professionals to rethink some long held assumptions. What does least privilege mean when software can decide what to do next? How do you govern the information an AI system remembers and relies on? How do you know an agent is acting within the authority it was given? How do you apply Zero Trust to systems that can take action without waiting for human approval at every step? Applying Zero Trust to AI means extending these principles to systems that can make decisions, access resources, and take action on behalf of users through continuous verification, appropriate permissions, and ongoing evaluation of risk.
These questions led us to write the book, Zero Trust for AI: Rebuilding Security Controls for Autonomous and Agentic Systems. It explores how Zero Trust principles apply to the realities of cybersecurity in the AI era, covering topics including AI agents, secure software development, AI memory, identity, and access control. It provides practical guidance for securing AI systems as they move from experimentation into production.
Follow Microsoft Security