IT Brief India - Technology news for CIOs & IT decision-makers
India
AI is testing the limits of Zero Trust

AI is testing the limits of Zero Trust

Fri, 21st Aug 2026 (Today)
David Land
DAVID LAND VP for APAC Gigamon

For more than a decade, Zero Trust has been the defining principle of modern cybersecurity. Trust nothing, verify everything, and grant the minimum level of access necessary. In a world of users, endpoints and applications, the model made perfect sense.

Then, along came AI.

What began as isolated pilots and productivity tools has rapidly evolved into something much, much bigger and more consuming. AI is now embedded inside business processes, applications and infrastructure, fundamentally changing how organisations work, but also how data moves across their environments. That movement of data presents a real problem.

The reality is that AI thrives on access. Large language models, copilots and agentic systems derive their value from consuming vast amounts of information and interacting with numerous applications and services. Yet Zero Trust, by design, was built to restrict and compartmentalise access.

The collision between these two forces is creating one of the most important cybersecurity challenges enterprises currently face.

AI needs access, but security demands restraint.

For years, security teams have worked to reduce attack surfaces, segment networks and minimise privileges. However, AI introduces the opposite dynamic.

To deliver meaningful outcomes, AI systems need broad visibility into data repositories, APIs, applications and workflows. Increasingly, machine-to-machine interactions are occurring constantly in the background, creating a level of complexity that traditional security models were never really designed to address.

This isn't a failure of the Zero Trust paradigm. Rather, AI is exposing assumptions that have existed beneath the surface all along.

The challenge is no longer simply controlling who gets access to what data - it is understanding what systems are actually doing with that access once it has been granted.

Confidence doesn't equal control

Many organisations believe they are successfully securing AI. The Gigamon 2026 Hybrid Cloud Security Survey found that nearly 40 percent describe themselves as 'operating at an integrated level of AI security maturity', with practices embedded right across the organisation. However, breach rates have climbed to 65 percent, up sharply over the past three years, and 83 percent of organisations report AI involvement in recent security incidents.

The contradiction is striking.

Investment is increasing and governance frameworks are evolving. But in today's rapidly changing market, security leaders are not necessarily being asked to deploy more tools. Increasingly, the focus is on consolidating technology stacks, finding efficiencies and freeing up budget for AI initiatives. Yet organisations are experiencing more breaches, not fewer.

Nearly half of the organisations in the survey report increases in AI-related insider threats, while more than three-quarters believe unsanctioned AI use is one of the biggest barriers to secure AI adoption. Shadow AI has become the latest version of Shadow IT, except this time the stakes are even higher.

The issue isn't about effort – people are trying to do the necessary work and take all precautions. It has become all about visibility.

The blind spot nobody talks about

Most security architectures were designed around north-south traffic - users connecting to applications and resources. AI is changing that.

Models, APIs and autonomous systems are creating enormous volumes of east-west traffic inside environments. These interactions are dynamic, distributed and – most importantly - often invisible to existing tools.

Security teams can see that something happened, but not always how or why.

The Gigamon research found nearly three-quarters of organisations report limited visibility into AI-driven data flows. More than 40 percent report that investigations are taking longer because increased complexity is slowing down their incident response. Forty-five percent cite growing visibility gaps caused by cloud complexity.

That makes simply adding more tools an increasingly difficult proposition. The priority is to get more value and visibility from existing investments without creating further fragmentation.

Logs, metrics and alerts each provide valuable perspectives, but none tell the complete story. Security teams are left correlating signals from disconnected systems, approximating behaviour rather than directly observing it.

Visibility Becomes the New Control Plane

The next chapter of cybersecurity won't abandon Zero Trust, but it will require expanding the conversation beyond access policies. Verification can no longer stop at identity - organisations must also now verify user behaviour.

That means understanding how data moves throughout the organisation, how AI systems interact with that data and how threats evolve in real time. It means seeing not just the endpoint or application, but the traffic itself.

This is why network-derived telemetry is becoming increasingly important. The research found that 92 percent of organisations believe complete visibility across data in motion is critical to improving security outcomes, while more than 90 percent also view deep observability as foundational to securing their future AI deployments. It is clear that visibility is becoming the new control plane, because in an AI-driven world, trust isn't created by policy alone, it is created by evidence.

From 'trust nothing' to 'understand everything'

Zero Trust remains one of the most effective security principles ever developed, but AI is fundamentally changing the environment it was designed to protect.

The future will belong to organisations that can move beyond static controls and gain continuous insight into how data, applications and AI systems interact across increasingly complex environments. 

After all, you cannot secure what you cannot see. In the age of AI, visibility may prove to be the ultimate form of trust.