AI in Zero Trust: Automate Evidence, Not Accountability
Originally published in 2024; substantially revised in 2026 to deepen the analysis and incorporate additional sources.
Zero trust creates an appealing environment for artificial intelligence. Every access request can generate context: identity, device posture, workload state, data sensitivity, behavior, location, threat intelligence, and prior activity. AI and machine learning can help correlate those signals faster than human analysts can review them individually.
But there is a design trap. If the organization uses AI to make opaque access decisions inside an architecture intended to improve security visibility and control, it can reproduce the very problem zero trust was meant to solve.
AI should automate the collection, interpretation, and routing of security evidence—not dissolve accountability into an inscrutable risk score.