Zero Networks has introduced a new feature, Least Agency Enforcement, aimed at enhancing the security of enterprise AI deployments by adhering to the Open Worldwide Application Security Project (OWASP) principle of Least Agency.
This enhancement helps organizations safely manage AI agents by limiting their autonomy and tool access, ensuring these agents operate within clearly defined parameters.
Lateral Movement Exposure in AI Deployments
The company's 2026 Lateral Movement Exposure Report highlights that nearly 80% of enterprises have already integrated AI agents internally, yet about two-thirds have not established governance policies. This lack of oversight results in significant exposure to potential security threats as AI agents are granted access to enterprise systems and can make decisions with minimal human intervention.
The OWASP Agentic Applications Top 10 Project suggests reducing AI agents' autonomy and access to tools to mitigate risks such as prompt injection and privilege abuse.
Implementing Least Agency Enforcement
Zero Networks uses identity-based microsegmentation, automation, & just-in-time MFA to manage AI agent interactionsZero Networks employs identity-based microsegmentation, policy automation, and just-in-time multi-factor authentication to manage AI agents' interactions. This ensures agents can only access authorized systems and resources, requiring human approval for sensitive actions. Unlike other frameworks that merely document policies, Zero Networks enforces these strategies across diverse environments, including cloud, on-premises, and hybrid setups.
Benny Lakunishok, CEO and Co-founder of Zero Networks, stated, “Least privilege works because it is simple: give people access to what they need, nothing more. We're doing the same thing for AI agents, except now it must be automatic, because nobody has time to babysit a thousand agents by hand. If an agent gets fooled or misused, it should hit a wall almost immediately, not wander around the network looking for something valuable. That's the bet we're making: less freedom for the agent now, which beats explaining a breach later.”
Benefits of Least Agency Enforcement
With this new capability, organizations can limit AI agents to their specific tasks, prevent unauthorized lateral movement, and enforce Just-in-Time MFA for accessing sensitive infrastructure.
The system automatically creates and applies least-privilege communication policies, curbing manually intensive rule creation. Compromised or misconfigured AI agents are contained swiftly, safeguarding critical business systems from potential impact.
Integration with the AI Security Platform
Least Agency Enforcement integrates with Zero Networks’ broader AI Security platform, offering features such as AI Agent Control, AI Segmentation, SaaS Control, and protection for LLM deployments.
This comprehensive security framework allows businesses to innovate in AI without compromising on security or resilience.
Availability and Demonstration
This new capability is currently available. Zero Networks plans to present Least Agency Enforcement alongside its AI security platform at Black Hat USA 2026, where they will maintain a presence at Booth #1852.