Zero Networks has launched a new feature, Least Agency Enforcement, designed to apply the Open Worldwide Application Security Project's (OWASP) Least Agency principle for safer AI agent deployment in enterprises.
This initiative aims to mitigate the risks associated with AI agents accessing enterprise systems, which can lead to security vulnerabilities due to improper governance and autonomy.
Lateral Movement Exposure Report
According to the 2026 Lateral Movement Exposure Report by Zero Networks, approximately 80% of businesses have integrated internal AI agents, yet about 67% of these enterprises do not have sufficient governance policies in place. This oversight creates significant security gaps by allowing AI agents to access privileged tools and make decisions with limited oversight. To combat these challenges, it is essential to define and enforce appropriate levels of autonomy for AI agents.
The OWASP Agentic Applications Top 10 Project's Least Agency principle advises restricting an agent's decision-making power and system access. This limitation helps mitigate risks such as privilege abuse and compromised AI agents.
Implementation of Least Agency Enforcement
Zero Networks enforces Least Agency through identity-based microsegmentationZero Networks leverages identity-based microsegmentation, policy automation, and just-in-time multi-factor authentication (MFA) to implement its Least Agency Enforcement. This capability ensures AI agents only engage with authorised systems, access approved resources, and require human validation for critical actions. Unlike typical policy documentation frameworks, Zero Networks enforces these principles in diverse environments, including cloud, on-premises, Kubernetes, IoT/OT, and hybrid setups.
CEO and Co-founder of Zero Networks, Benny Lakunishok, stated, "Least privilege works because it is simple: give people access to what they need, nothing more. We're doing the same thing for AI agents, except now it must be automatic, because nobody has time to babysit a thousand agents by hand. If an agent gets fooled or misused, it should hit a wall almost immediately, not wander around the network looking for something valuable. That's the bet we're making: less freedom for the agent now, which beats explaining a breach later."
Key benefits of Least Agency Enforcement
Zero Networks' Least Agency Enforcement provides several advantages for organisations, including:
- Restricting AI agents to only necessary systems and services for their tasks.
- Preventing lateral movement across applications and sensitive infrastructure.
- Using Just-in-Time MFA to secure access to privileged ports.
- Automatically creating and enforcing least-privilege communication policies without manual intervention.
- Containing compromised AI agents to prevent potential damage to critical business systems.
This capability enhances Zero Networks' AI Security platform, which includes AI Agent Control, AI Segmentation, AI SaaS Control, and enterprise LLM deployment protection. Collectively, these features provide a robust security layer that enables AI innovation while maintaining high security and resilience standards.
Availability and event showcase
Least Agency Enforcement is now available to organisations. Zero Networks will showcase this feature and its comprehensive AI security platform at Black Hat USA 2026, Booth #1852.
