Zero Trust AI Exposure: authenticated, authorized, and still unsafe.
Zero Trust asks whether an identity should be granted access. It says much less about what that identity does with the access once it has it. For a person, the gap is tolerable. For an agent that plans, calls tools, delegates and sends data outward without a human in the loop, the gap is the exposure.
This is not a marketing position. It is the stated gap in the current literature.
The gap, in the words of the research
Existing Zero Trust Maturity Models, such as the CISA ZTMM, mainly focus on how resources are accessed and provide limited guidance on how to evaluate actions taken after access has been granted.
Mok, Jo & Lee, An Action-Centric Zero Trust Maturity Model for Agentic AI Environments, Sensors 26(16):5205, published 17 August 2026. doi:10.3390/s26165205
The paper proposes AI-ZTMM, which extends CISA’s five-pillar structure to action-level trust evaluation, defining forty-one security Functions across ten threat categories, and introducing an Action Space and a set of Action Risk Factors.
What the authors do not claim, and neither do we. The paper states plainly that its results do not establish control effectiveness — nothing demonstrates that an organisation assessed at a higher maturity level in fact experiences fewer or less severe incidents, which would require longitudinal observation. The same limit applies to the Govern360 AI Exposure Score. It measures governance state. It is not validated against incident outcomes, because no incident corpus exists.
Govern360 is the decision point, not the enforcement point
NIST SP 800-207 separates three logical components: the policy decision point, the policy information points that feed it, and the policy enforcement point that acts. Govern360 is the first two. Your existing controls are the third.
What Govern360 reads
Agents, models, connectors, non-human identities, tool grants, data classifications, enforcement state. Read-only, through management APIs.
What Govern360 decides
Governance intent compiled into native artefacts, per plane. Nothing executes without a person approving it.
What you already own
Microsoft Purview, Intune, SASE, AI gateways. Govern360 never sits in the traffic path and holds no standing write credentials.
This is why “we never proxy traffic” is an architectural statement rather than a limitation. The separation of decision from enforcement is the reference architecture, not a workaround for one.
Zero Trust AI Exposure Maturity™
CISA’s Zero Trust Maturity Model v2.0 defines five pillars — Identity, Devices, Networks, Applications & Workloads, Data — with three cross-cutting capabilities and four stages: Traditional, Initial, Advanced, Optimal. Maturity is assessed per pillar, so an organisation can be Initial in one and Advanced in another.
A stage per pillar avoids a problem percentages create. “87% identity verified” invites the question of what the denominator was. “Identity: Initial” does not, and it maps to a framework a federal buyer already uses.
| Pillar | Stage | Evidence observed | Next action |
|---|---|---|---|
| Identity | Traditional | Platform-assigned agent identities detected. No scoped action policies. No completed identity reviews. | Establish a dedicated identity, a scoped grant and a review policy. |
| Devices | Initial Verified | Intune compliance controls observed and independently read back through Microsoft Graph. | Expand coverage to the remaining device population. |
| Networks | Traditional | Five enforcement integrations supported and policy compilation available. No active AI egress contract observed. | Activate an egress contract, then verify by read-back. |
| Applications & Workloads | Initial | Agents mapped with MCP manifests, connectors, permissions and exposure legs. Discovery strong, control absent. | Bind ownership and purpose, then scope permissions. |
| Data | Traditional | Data-security signals present. Classification coverage insufficient to bound what agents can reach. | Increase classification coverage before claiming a higher stage. |
| AI Actions | Traditional | Agents visible. None purpose-bound, no scoped action policies, external egress paths present. Approval routing operational. | Bind purpose, scope permitted actions, require approval for high-impact external actions. |
Worked example from a Govern360 demonstration tenant, not a customer estate. Every stage cites what it was read from. Your estate will differ.
Evidence
What Govern360 actually observed. Every stage traces to signals from connected systems.
Gap
What prevents the next stage. The missing control or the missing verification, named.
Next action
What changes the result. Bind purpose. Scope an identity. Apply an egress policy. Verify enforcement.
Measure, remediate, verify, advance. A stage is only awarded when there is evidence to support it — never because a questionnaire was answered.
What each stage means
Visibility or controls incomplete. Trust still depends on implicit access or manual process.
Core signals visible and some controls exist, but coverage or verification is incomplete.
Controls scoped, consistently enforced and independently verifiable across most exposure paths.
Continuous contextual verification and action-level enforcement, evidenced across the estate.
Worked example from a Govern360 demonstration tenant, not a customer estate. Every stage above cites what it was read from. Your estate will differ.
Early enterprise AI estates commonly begin with strong discovery and limited action-level enforcement. A low first assessment is the expected shape, not an indictment — it is a position on a curve, and the curve is the point. We do not publish a cross-customer benchmark figure, because we do not yet have the sample size or a published methodology to stand behind one.
Enforcement needs an inventory first
Zero Trust for AI agents is a real field. Cisco, Zscaler, Palo Alto and Keyfactor all ship toward it. What they have in common is where they sit: each is a policy enforcement point, and each needs to know what exists before it can enforce anything.
SASE platforms become enforcement layers that depend on inventory they don’t own.
Futurum Group, on the agentic AI security control plane, June 2026.
Zero Trust AI Exposure is the layer above that. Govern360 discovers the estate read-only, decides what should be true, compiles it into artefacts your planes already understand, and reads back whether the plane applied them. Whatever you enforce with keeps doing the enforcing. We are the system of record and the decision layer, not a competing chokepoint.
Zero Trust is not a product anyone completes. It is a maturity curve assessed per pillar. The honest thing a vendor can tell you is where you sit on it, what each stage was read from, and what moves it.
What we do not claim
- Govern360 does not enforce Zero Trust. It decides and compiles; your planes enforce.
- A maturity stage is not a guarantee of fewer incidents. The research says so explicitly, and so do we.
- Where a plane exposes no read path, enforcement is reported as compiled or marked applied — never as verified.
- Runtime behaviours that need instrumentation we do not have — memory poisoning, trajectory assurance, MCP runtime integrity — are outside what this assessment can see, and are named as such.