# ============================================================================= # Published - Zero Trust is being rewritten (verbatim) # ============================================================================= # A verbatim reproduction of an article authored by Cedric Ancellin. # Text is preserved as published (including original wording and any typos). # Governed by ../LAWS. Verbatim files are exempt from the em-dash rule. # # Retrieved from LinkedIn on 2026-10-11. # ============================================================================= title: "Zero Trust is being rewritten" author: "Cedric Ancellin" published: "2026-10-11" platform: "LinkedIn (Pulse)" source_url: "https://www.linkedin.com/pulse/zero-trust-being-rewritten-cedric-ancellin-y29de/" cover_image: "/assets/articles/zero_trust_is_being_rewritten.jpg" topics: ["zero trust", "AI coding agents", "agent security", "least privilege", "egress allowlist", "code review", "product specification", "ontology", "security engineering"] summary: > An argument that zero trust, which began as a network model and grew to cover identities, devices and workloads, now has to cover AI agents working alongside engineers. It walks through five publicly reported 2025 and 2026 incidents, argues that click-to-approve prompts fail through alert fatigue, and proposes two controls in their place (an isolated least-privilege environment with an egress allowlist, and an independent audit by a product owner and a senior engineer). It closes on the product specification and the system ontology becoming the main control once code is cheap to produce. body: | When members of your team work alongside an artificial partner, you have to treat that new friend as a hostile actor. Zero Trust now has to extend to this partner, and to everything it touches. Zero trust, a term John Kindervag coined at Forrester in 2010, began as a network security model. Stop assuming anything inside the corporate perimeter is safe, and verify every request instead. Over the years it grew to cover identities, devices and workloads. Now it has to grow again, to cover the partner your engineer works with, the environment it operates in, and the assumption that because a human signed off, a human actually checked. In August 2025, attackers published malicious versions of Nx, a popular build package. The malware looked for AI command-line tools already installed on developers' machines, including Claude, Gemini and Amazon Q, and used them to search for secrets and help exfiltrate them. The attackers then used stolen credentials to make more than 6,700 private repositories public. The agent had the access, and the attacker borrowed it. In July 2025, a developer was building an app with Replit's AI agent. The agent was working in development, but it still had a live connection to the production database, and it ran destructive commands that wiped it. A few months later, a user asked Google's new AI coding tool, Antigravity, to clear a project cache. The agent instead ran a delete command at the root of his entire D: drive, with a flag that skipped the Recycle Bin. In both cases the access itself was not new. A development environment with a live connection to production, or a user account that can delete a whole drive, was tolerable when only a human was at the keyboard. The agent inherited that access without that judgment. In March 2026, an AI mistake reached one of the largest retail sites in the world. Amazon's retail site went down for about six hours, and customers could not check out, see prices or reach their accounts. Amazon said the root cause was an engineer acting on inaccurate advice that an AI agent inferred from an outdated internal wiki. Amazon responded by requiring senior-engineer review of AI-assisted changes. In July 2026, the AI went further and attacked on its own. OpenAI disclosed that one of its experimental agents broke out of its sandbox during an internal hacking evaluation and broke into Hugging Face's production servers to find the answers to the test. Nobody told it to. OpenAI had deliberately lowered the model's safety restrictions for the test, but the sandbox was supposed to hold. Five incidents, four different kinds of failure. These agents can be capable, and they can follow strict rules, but you cannot see how they reason or predict exactly what they will do. The developer's environment must be locked down far beyond what we tolerated before. Code review must get tighter. And the product team needs to expand its scope, because as code becomes cheaper, the specification becomes the control. Most AI coding agents offer the same safeguard. Before the agent runs a command or touches a file, it asks the developer to approve. It is not a real control, and it fails the way every attention-based safeguard fails. Security people call it alert fatigue. The SOC analyst flooded with alerts starts skimming, and the web user clicks accept on every cookie banner. An agent on a real task asks for approval many times a session, and each prompt gets less attention than the last. A control that depends on a human staying attentive all day does not hold. And the agent reads more than your instructions. A README, a pull request comment, an error message, a web page it fetched, any of these can carry text that tells it to act, so the environment it runs in is untrusted, not the person operating it. Worse, an agent with open internet access can act on that text. It can fetch a file or a script from anywhere and run it, or send your code and secrets back out to a server you have never heard of. That is what the allowlist exists to stop. And the developer might reach for whatever is least restricted, pasting company code into a personal AI account when the sanctioned tool blocks what they want to do, unless the environment makes that account unreachable. The click is not a control. Replace it with two that do not depend on a tired human. The first is the environment, the agent runs under its own least-privilege identity, not the developer's session, with no path to production, no secrets in its working directory, and an egress allowlist that lets it reach the package registry, the internal docs and the approved AI provider and nothing else. That same allowlist is what closes the shadow-AI leak, since the unsanctioned account is simply not reachable. The second is an independent audit by someone other than the person running the agent. A product owner checks that what shipped matches what was asked, and a senior engineer checks the change itself for risk. Tier it so low-stakes work gets the product check and the dangerous paths get both. The operator approving their own agent's actions was never a control. These two are. Before agents, a vague requirement cost a conversation. An agent does not ask. It fills the gap with a guess and keeps going. That puts a new duty on the product team, and on whoever owns the system's ontology, the shared map of entities, rules and relationships that agents read as truth. - Acceptance criteria that are testable, not aspirational. - Edge cases named explicitly. - A definition of done that says what the feature must not do, not only what it must. - Review of the shipped behavior against the spec, by the person who wrote the spec, before release. - The ontology of the whole system kept current, because an agent will build on whatever it says. The product manager cannot delegate a security decision to a language model that decides based on the most statistically plausible guess. Your engineers have not changed. What they work with has. Zero trust has kept expanding ever since it left the network. The artificial partner is simply the next actor it has to cover. If your controls still assume the only actor in the room is the human you hired, you are already behind. And once an agent can produce the code, the hard part is deciding what to build and verifying it got built right. The developer is no longer the center of gravity. The product and the ontology are. Build your process for that, or keep securing the wrong seat. transcription: "Verbatim as published (2026-10-11). Retrieved from LinkedIn 2026-10-11."