Zero Networks ties AI agent identity to the network layer, with just-in-time MFA for the sensitive protocols
Zero Networks launched Least Agency Enforcement at Black Hat USA 2026, implementing OWASP's emerging Least Agency principle with identity-based microsegmentation and default-deny network access for AI agents, plus MFA prompts on RDP, SMB, and WinRM even when an agent presents valid credentials.
Zero Networks announced Least Agency Enforcement on August 4, 2026 at Black Hat USA, a network-layer implementation of OWASP's Least Agency principle for enterprise AI. The capability maps which systems a given agent identity should be able to reach, then enforces that map at the host firewall with default-deny for everything else, identity-based microsegmentation rather than a policy an agent could talk itself around. For higher-risk protocols specifically, RDP, SMB, and WinRM, it adds just-in-time MFA prompts, so an agent with valid but compromised or over-scoped credentials still can't move laterally without a human in the loop. Zero Networks cites its own 2026 Lateral Movement Exposure Report finding that nearly 80 percent of enterprises have already deployed internal AI agents while roughly two-thirds have no governance policy covering them. "If an agent gets fooled or misused, it should hit a wall almost immediately," said CEO Benny Lakunishok.
Why it matters
The framing worth noting is what it enforces against: not whether the agent's task was legitimate, but what it can technically reach if it's manipulated, misconfigured, or simply wrong. That's the same shift toward securing AI agent identities as a distinct, scoped problem that showed up repeatedly across Black Hat vendor announcements this week, treating an agent's credentials the way you'd treat any other identity that can be tricked into acting against its owner's interest.
The 80/two-thirds gap Zero Networks cites is the number to sit with regardless of vendor: if your organization has agents running with standing access and no zero standing privilege model behind them, this is the gap that gets exploited first, not a hypothetical one.
Source: CSO Online
Related on Start with Identity
- BlogTeleport launches Beams, giving each AI agent its own microVM and identity
Each agent runs in an isolated Firecracker VM with identity built in, reaching infrastructure and inference services without secrets, under Teleport's existing
- BlogC1 ships enterprise-managed authorization, putting SSO in front of MCP agents
The identity platform formerly called ConductorOne now issues short-lived scoped tokens for MCP servers under the open enterprise-managed authorization extensio
- BlogSaviynt launches Zuma, an AI identity platform, as ARR passes 300 million dollars
Zuma splits into Insights, Governance, and Access: discover AI and non-human identities, apply lifecycle and certification controls, then decide at runtime whet
- GlossaryJust-in-Time (JIT) Access
Granting elevated permissions only when needed, for a limited duration, and revoking them automatically. JIT eliminates standing privilege, the largest contribu
- ArticleTop 5 Just-in-Time Access Tools in 2026
A detailed comparison of five leading just-in-time (JIT) access tools, CyberArk, BeyondTrust, Britive, Apono, and Opal, that eliminate standing privileges and e
- ArticleTop 8 Zero Trust Network Access (ZTNA) Tools in 2026
Compare the top 8 ZTNA tools that replace traditional VPNs with identity-aware, least-privilege network access for modern distributed workforces.