Skip to content
Article reader Listen + reading controls
LISTEN + READ YOUR WAY

Article reader

Preparing the reader…

0:00 0:00
Reading settings
Text size
100%

AI in Zero Trust: Automate Evidence, Not Accountability

Originally published in 2024; substantially revised in 2026 to deepen the analysis and incorporate additional sources.

Zero trust creates an appealing environment for artificial intelligence. Every access request can generate context: identity, device posture, workload state, data sensitivity, behavior, location, threat intelligence, and prior activity. AI and machine learning can help correlate those signals faster than human analysts can review them individually.

But there is a design trap. If the organization uses AI to make opaque access decisions inside an architecture intended to improve security visibility and control, it can reproduce the very problem zero trust was meant to solve.

AI should automate the collection, interpretation, and routing of security evidence—not dissolve accountability into an inscrutable risk score.

Zero trust is a decision system

NIST defines zero trust as an architecture that removes implicit trust based on network location and continually evaluates access to resources (NIST, 2020). The core product is not a collection of security tools. It is a policy decision: should this subject be permitted to perform this action on this resource under these conditions?

A mature zero-trust system separates several functions:

  • Policy information: signals about identity, device, workload, data, behavior, and threat.
  • Policy decision: the logic that evaluates those signals against explicit rules and risk tolerances.
  • Policy enforcement: the technical control that permits, constrains, or denies the action.
  • Observation and learning: telemetry that reveals whether the decision produced the intended result.

AI can strengthen each layer, but the role it plays should be explicit.

Use AI where complexity exceeds fixed rules

Rules remain the right tool for many security requirements. A user without required clearance should not gain access because a model assigned a favorable score. A prohibited data flow should not become permissible because behavior appears normal.

AI is most useful where patterns are complex, contextual, or too numerous for static logic:

  • Detecting anomalous identity or device behavior
  • Correlating weak signals across tools and time
  • Prioritizing alerts and investigations
  • Inferring hidden service or dependency relationships
  • Identifying probable credential misuse
  • Summarizing evidence for an analyst
  • Recommending a proportionate response

The model should add context to policy, not replace policy. Hard constraints, human authority, and mission-specific rules still define the permissible action space.

Risk scores need semantic content

A numerical risk score can create false precision. A value of 82 tells an operator very little unless the system explains the evidence, comparison baseline, uncertainty, and policy consequence.

A useful AI-assisted decision should expose:

  • Which signals contributed materially
  • Whether those signals are current and trustworthy
  • What normal behavior or peer group was used for comparison
  • Which alternative explanations remain plausible
  • What the model has not observed
  • Which policy threshold the result affects
  • What action an analyst can take next

This improves both security and governance. Analysts can challenge the recommendation, policy owners can evaluate whether the model is influencing the right decisions, and incident responders can reconstruct why an action occurred.

Identity and data quality become model dependencies

AI cannot compensate for weak identity or telemetry foundations. If service accounts are shared, device ownership is ambiguous, data labels are inconsistent, or logs omit important context, the model learns from institutional disorder.

Before deploying AI into zero-trust decisions, organizations should assess:

  • Coverage and reliability of identity signals
  • Consistency of asset and service inventories
  • Quality and timing of device-posture information
  • Data classification and resource ownership
  • Traceability across authentication, authorization, and enforcement events
  • Representation of legitimate but rare behavior

Otherwise, automation may increase alert volume, reinforce biased baselines, or block the users whose work is least well represented in historical data.

Treat the AI component as part of the attack surface

An AI-assisted security control is itself a target. Attackers may attempt to poison behavioral baselines, evade detection, manipulate prompts or tool outputs, extract sensitive information, or create adversarial events that exhaust analyst attention.

Joint guidance from NSA, CISA, and international partners applies secure-by-design principles across AI design, development, deployment, and operation (NSA, 2023). For zero-trust use cases, teams should add controls such as:

  • Independent validation of high-impact signals
  • Rate limits and bounded automated response
  • Monitoring for input and behavior drift
  • Adversarial testing against evasion and poisoning
  • Separation between recommendation and enforcement authority
  • Fail-safe modes when the model or telemetry is unavailable
  • Rollback and forensic preservation for model changes

The more authority the AI receives, the stronger the evidence and containment requirements should become.

Automation should shorten the control loop

The strongest use of AI is not simply detecting more anomalies. It is reducing the time between evidence, decision, response, and learning.

A well-designed control loop can:

  1. Collect and correlate relevant signals.
  2. Identify a condition that may violate policy or increase risk.
  3. Explain the evidence and uncertainty.
  4. Recommend or execute a bounded response.
  5. Observe the result and capture analyst feedback.
  6. Update detections, policy, or system design when the incident reveals a gap.

That final step matters. If analysts repeatedly reverse a model’s recommendation but the feedback never changes the system, the organization has automated triage without creating institutional learning.

Measure decision quality, not alert volume

AI-security products are often evaluated through detection rates or reduced mean time to respond. Those metrics are useful but incomplete. Zero-trust leaders should also examine:

  • Precision of automated and analyst-facing recommendations
  • Time required to understand and resolve a decision
  • Frequency and cause of overrides
  • Impact on legitimate mission work
  • Coverage gaps across identities, devices, applications, and data
  • Incidents prevented or contained
  • Policy and architecture improvements produced by feedback

The objective is not maximum denial or maximum automation. It is better security decisions with less unnecessary friction.

The DoD Zero Trust Strategy’s seven-pillar model—users, devices, applications and workloads, data, networks, visibility and analytics, and automation and orchestration—reinforces that this is an enterprise transformation rather than a point solution (DoD CIO, 2022).

The strategic takeaway

AI can make zero trust more adaptive by connecting signals, identifying patterns, and helping teams respond at machine-relevant speed. It should not make security decisions less legible or move risk ownership beyond human reach.

The durable principle is simple: automate evidence, automate repeatable controls, and automate bounded response—but keep policy, operating limits, and accountability explicit.

If your organization is trying to connect AI, platform engineering, and accountable security operations, you can send a direct inquiry from my portfolio.

References

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.