Google's Beyond Zero: A New Security Model for the AI Era
Google has unveiled Beyond Zero, a new security model designed for the AI era. The approach extends zero-trust principles to autonomous AI agents and combines static authorization controls with dynamic AI-driven decisions.
Beyond Zero uses contextual and risk-based resource-level controls to continuously authorize individual actions by both humans and AI agents. It's based on five key principles: authorization at the level of individual actions and resources, a combination of static policies and dynamic controls, automatically enriched context about users and risks, automated investigation triggered by risk signals, and challenges or containment measures.
Joseph Valente and Michal Zalewski write that the assumptions underlying BeyondCorp are no longer sufficient. They note that accessors are not always human, actions don't occur at human speed, and applications are not the correct boundary for trust.