Zero trust was built to verify people and devices. An agent that decides its own tools, chains API calls, and vanishes once its job is done doesn't fit that mold — and most companies haven't realized it yet.
An agent interprets a goal, chooses its own tools, chains API calls, spawns subtasks, adapts its behavior based on the data it encounters, and disappears once the work is done. It can hold credentials it doesn't directly control, touch resources its designer never anticipated, and operate at machine speed with no human in the loop between steps — characteristics the zero trust model, designed for people and fixed devices, simply never accounted for.
At a typical 2026 company, machine identities outnumber human users by orders of magnitude, with surveys citing ratios of 50 to 1 in traditional environments, climbing to 500 to 1 in microservices-heavy stacks. According to Gravitee's State of AI Agent Security 2026 report, only 47.1% of deployed AI agents are being actively monitored or secured — more than half operate with no real security oversight.
A Cloud Security Alliance and Aembit study found that 68% of organizations can't clearly distinguish human activity from AI agent activity in their own logs — a fundamental visibility problem that makes it nearly impossible to apply any differentiated security policy between the two types of actor.
The Cloud Security Alliance's Agentic Trust Framework (ATF) is a maturity model that treats AI like employees, categorizing them from "Intern" roles (minimal access, constant supervision) up to "Principal" agents with deep system access — a gradual trust-progression framework, instead of treating every agent the same from day one.
The recommendation solidifying is simple to state and hard to implement: keep the human in the loop for high-impact decisions, but automate the defensive response. In practice, this means treating every agent as a first-class identity with its own credential lifecycle, permissions scoped to the specific task it executes, and logs that explicitly distinguish its activity from that of any human user.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel