Share

Key takeaways

Today’s threat landscape calls for AI-ready Zero Trust.

As enterprises move full speed on AI innovation, autonomous agents can no longer be treated as mere user-driven tools — they are operating inside the network. If an agent possesses the authority to query cross-repository data or scan internal endpoints for context, it becomes a vessel for automated lateral movement. Zero Trust now must shift toward continuous verification of not just the human but the autonomous shadow processes acting in their name.

Risks like frontier LLMs call for new Zero Trust approaches.

As threat actors launch attacks at multiple vectors at once and the prospect looms of frontier AI models that can diagnose weaknesses in seconds and launch an attack in less, the need for an integrated suite has become even more important. A Zero Trust strategy must move beyond a collection of stand-alone tools. AI-driven threats can exploit siloed security products, moving faster than human intervention can track.

Automated microsegmentation stops machine-speed lateral movement.

Today’s threats require a Zero Trust architecture that uses AI-powered defenses to take on AI-fueled threats. Relying on slow, human-led incident responses allows rapid AI-driven intrusions to spread into catastrophic systemic failures — but AI-powered microsegmentation automates threat containment into self-isolating cells, allowing today’s security teams to cap the blast radius and suffocate threats the moment they manifest.

Zero Trust is your answer to AI risk

The concept of Zero Trust is hardly new, but in the new AI era, it’s more important than ever. Forrester Research first promoted it years ago, warning organizations that it was time to overhaul the traditional method of granting unfettered access to any user or application once it passed the network perimeter. Instead, every device, user, and network flow should be verified before full access is granted.

Zero Trust began to gain traction as organizations sought to solve the access problems associated with hybrid work and cloud deployments. But now the perimeter is no longer just remote — it’s dynamic and operating at machine speed.

AI has made deepfakes not only possible but sophisticated, and LLM-backed phishing attempts can now be created at scale with unprecedented levels of personalization. More concerning, the prospect of frontier AI models that quickly identify vulnerabilities that had evaded human detection for decades makes a breach not only a question of “if, not when,” but of how damaging it will be.

Consider the rise of ransomware as a service, through which developers create ransomware and rent it to affiliates to launch attacks. It allows even unskilled hackers to execute advanced attacks. Recently, three of the most prominent ransomware groups — ALPHV/BlackCat, CL0P, and LockBit — all conducted quadruple extortion attacks. In these attacks, threat actors not only encrypt and exfiltrate data but also threaten DDoS attacks and contact a victim’s customers, partners, employees, and the media to force them to pay a ransom. Generative AI and LLMs (large language models) are helping to increase the frequency and scale of ransomware attacks by making it easier for individuals with less technical expertise to launch sophisticated campaigns.

Human-led defenses are too slow to keep up with this new reality. Organizations must quickly pivot to a “defense-first” AI strategy. They need to protect every single digital interaction.

Amid this evolving and often confusing cybersecurity landscape, network and security software vendors have rushed in to brand their existing products as AI-enabled or to introduce new products. It has left security teams struggling to keep pace and confused by the purchasing decisions that set the foundation for a shift to a Zero Trust strategy.

This guide is designed to provide security teams with a blueprint for making investments in Zero Trust technology amid rising AI threats by identifying where to start and outlining the key differentiating factors.

Autonomous agents and shadow AI signal a new era

Where employees may once have introduced risks to the network by logging in from an unsecured Wi-Fi spot or succumbing to a phishing attempt, the threats today are far more insidious. Unlike the SaaS sprawl of the previous decade, shadow AI involves unmanaged capabilities — employees now deploy AI browser extensions and autonomous agents that create stealthy data paths bypassing traditional data loss prevention efforts.

According to IBM’s Cost of a Data Breach Report,1 one in five organizations has already suffered a breach linked to unmonitored AI — with 2026 telemetry showing these extensions are three times more likely to request excessive permissions, transforming the browser into an exfiltration hub.

These tools create stealth data paths. However, the threat is evolving from passive data leakage to active reconnaissance. Security pros now need to consider the possibility of LLMs, equipped with autonomous reasoning, mapping internal networks by exploiting latent vulnerabilities in Model Context Protocols (MCP).

In an AI-ready Zero Trust architecture, these autonomous agents can no longer be treated as mere user-driven tools; they are operating inside the network. If an agent possesses the authority to query cross-repository data or scan internal endpoints for context, it becomes a vessel for automated lateral movement. Zero Trust now must shift toward continuous verification of not just the human but the autonomous shadow processes acting in their name.

Two IT professionals collaborating on code and security configurations using monitors and a tablet.

Zero Trust’s architectural shift

For years, the industry rallied around a single, uncompromising mantra: “Never trust, always verify.” This was the bedrock of early Zero Trust, a necessary pivot away from the “castle-and-moat” mentality that assumed anything inside the network was safe. But today, simply verifying identity has become the bare minimum. With AI-driven scripts now capable of hijacking authenticated sessions and mimicking user behavior at machine speed, the focus must shift from identity validation to architectural resilience.

We now have to assume the verification gate will eventually be bypassed. The goal is no longer just to check credentials but to ensure the architecture itself is designed to survive an active intrusion. Organizations must move beyond basic permissions to a state of automated containment. For instance, if an account user’s credentials are exploited by an automated script, the system shouldn’t just verify them; that user shouldn’t be allowed to touch anything outside of a narrow, predefined sandbox.

Modern cybersecurity resilience relies on real-time, automated responses that suffocate a threat the moment it manifests. If the telemetry signals a breach, the architecture shouldn’t wait for a human analyst — it must autonomously isolate the segment. This fundamental shift effectively neutralizes the “breakout phase” of an attack.

Plane on halt mode
Plane on halt mode

How to create a Zero Trust architecture for AI-backed threats

Today’s threats require a comprehensive approach to staffing, policy, and communication, particularly between security and developers. But when it comes to the actual products that can help fulfill a Zero Trust strategy, they should be driven by four goals.

1. Don’t trust any entity; constantly verify.  

“Don’t trust, and constantly verify” sounds far easier in the abstract. If you simply cut off any access to all systems and data, you have locked down your network. The real challenge is to constantly verify without creating massive business disruptions, particularly when most systems were designed with implicit trust in mind. You need broad visibility and control for all types of access, and simple and practical means of enforcing and maintaining policy.

2. Once verified, ensure you’re providing minimal access.

In a Zero Trust environment, once a user has been verified, they must be given access to only what is required by their role.  

3. Continuously monitor for threats.

As most industry experts will tell you, Zero Trust is an ongoing exercise. Threat actors are becoming increasingly sophisticated as they try to breach a company’s defenses, and the organization must continuously monitor, verify, and limit access. One of the advantages of Zero Trust is that it shifts the focus from chasing ever- evolving threats to securing legitimate business intent. By defining the “known good” — exactly which users, devices, and workloads need to communicate — you create an environment where any unauthorized activity is blocked by default, regardless of the attacker’s tactics or the novelty of their tools.

With a true Zero Trust policy in place, attackers are hard-pressed to subvert all the things that your business needs to run at once. Ideally, you’ll be able to stop every attack at some point in the chain. That includes the ability to stop attacks that have not yet been conceived. You won’t care whether it’s a zero-day attack; Zero Trust can help mitigate it.

4. Autonomous exposure analysis.

It’s no longer enough to just monitor against active threats. Today’s Zero Trust initiatives must constantly be evaluating where your defenses might be exposed. That should include the potential impact of a breach — what could be exposed, how assets can be reached, and the potential blast radius. The prospect of frontier LLMs and what they’ve shown they can do in limited testing has made it clear that defending against a single penetration attempt is no longer sufficient. Security needs to be proactively identifying risks and ready to lock down any lateral movement in real time.

The dark side of Zero Trust

As an organization embarks on implementing Zero Trust, it must also consider the flip side of all this distrust and the limits on access. A fundamental aspect of Zero Trust is restricting access, historically accomplished through positive security. This is the practice of dictating what can happen; everything else is denied by default.

However, by decreasing an attacker’s ability to carry out their malicious campaign, an organization can increase the likelihood of accidentally preventing someone from being able to do their job. Alternatively, false positives that lead to blocking legitimate packages or users, or false negatives that let through malicious traffic, can cumulatively add up to delays and frustrations. A Zero Trust strategy that keeps people from effectively doing their jobs is no kind of strategy at all.

Similarly, today’s complex IT environment now confronts an even more complex threat landscape. That introduces the prospect of security teams managing thousands of manual rules. This is no longer tenable. Organizations need to embrace a defensive AI approach to Zero Trust security. While AI has simplified attacks, it can also simplify policy creation, allowing teams to rapidly deploy and adjust policies while maintaining crucial human oversight.

A strong Zero Trust strategy will therefore strike a balance between security and access, or automation and human oversight.

Elements of Zero Trust

In the years since the term Zero Trust was first coined, cobbling together a comprehensive security approach that protects both north-south and east-west traffic has proven difficult for many organizations. Turning to one vendor for a firewall and Zero Trust Network Access (ZTNA) and another for microsegmentation has made implementation difficult, particularly as security teams struggled to roll out manual policy updates. Zero Trust initiatives have also faced internal cultural challenges with siloed groups, like networking and systems engineers blaming one another for vulnerabilities or breaches instead of working together to find a solution.

Now, with threat actors launching attacks at multiple vectors at once and the prospect of frontier AI models that can diagnose weaknesses in seconds and launch an attack in less, the need for an integrated suite has become even more important. Organizations don’t have time for the slow rollout of a module or manual updates.

To achieve the level of architectural resilience required today, a Zero Trust strategy must move beyond a collection of stand-alone tools. AI-driven threats can exploit siloed security products, moving faster than human intervention can track. Resilience can be found in the tight integration of these three core technological pillars:

1. Unified access fabric (ZTNA and identity verification)

In an era of deepfakes and autonomous AI agents, identity is the new perimeter. ZTNA must be unified under a single policy engine that goes beyond initial login. Verification now requires phishing-resistant MFA and continuous session evaluation. By integrating these, the system doesn’t just check a password; it analyzes device posture and behavioral signals in real time. If an AI script hijacks a session, the integrated fabric detects the subtle shift in telemetry and revokes access instantly across all applications.  

2. Automated microsegmentation

If an attacker gains a foothold, microsegmentation is what can prevent a localized breach from becoming a systemic catastrophe. Manual segmentation is now obsolete — it cannot keep pace with AI-driven lateral movement. Modern resilience relies on automated, exposure-aware segmentation that dynamically isolates workloads. By grouping assets into self-contained cells, the architecture ensures that even if a service account is compromised, its reach is physically limited. This caps the blast radius, forcing the attacker into a dead end.

3. Intelligence-led DNS firewalls

The final line of defense against an AI-driven breach is disrupting its command and control (C2) infrastructure. DNS firewalls act as a critical interception point, blocking the queries that AI scripts use for orchestration and data exfiltration. Because these attacks often use domain-generation algorithms and evasive tunneling, the DNS firewall must be integrated with the broader threat intelligence loop. By automatically severing the link between the internal breach and the external attacker, the system renders the AI script unable to receive instructions or leak sensitive data.

These technologies are no longer optional layers; they are the integrated components. Only through this tight coupling can a system detect, contain, and neutralize an AI-accelerated threat before a human analyst even receives the first alert.

The principles of Zero Trust

The network is always assumed to be hostile

External and internal threats exist on the network at all times, including autonomous agents

Network locality is not sufficient for deciding trust in a network

Every device, user, and network flow is authenticated and authorized

Policies must be automated, dynamic, and calculated from as many sources of data as possible

Containment is now the best response to the likelihood of an AI-powered breach

Zero Trust Network Access (ZTNA)

Sometimes confused with the overall approach to Zero Trust, ZTNA is a fundamental part of the technology stack. Secure access is typically the first step in any Zero Trust framework. Unfortunately, like so many elements of the process, it quickly becomes more complex than it sounds.

Secure access is not a binary decision. Providing the right level of access to the right application for the right users at the right time has become far more complex as users and applications have become more widely distributed. In fact, the very definition of a user can now include customers, suppliers, and partners, as well as employees. Meanwhile, applications can include legacy apps, SaaS, or mobile apps and require access to and from the data center, internet, or cloud environments.

An effective ZTNA solution will verify the identity of the user and the health of their device, and that they can access the applications they need — no matter where they are — which reduces the possible attack area and improves flexibility and monitoring. For decades, organizations relied on virtual private networks (VPNs) supported by identity providers to provide access. Those VPNs, designed for a different era, are no longer sufficient.

In the AI era, as deepfakes and sophisticated phishing efforts make credential theft and impersonation more dangerous than ever, having strong defenses at the point of initial access is critical.

Key considerations for purchasing Zero Trust Network Access solutions

As companies initiate their network access defense strategies, there are a number of areas to consider. Today’s more advanced solutions should combine identity and access management, application security, multi-factor authentication (MFA), and single sign-on, all with management visibility and control under a single interface. This includes the ability to verify the health of a device accessing the network. For example, is antivirus software running on the device?


Organizations pursuing Zero Trust initiatives should look for solutions that can address their current needs but also scale with the business. This allows them to quickly onboard employees from a merger or acquired company, conduct manufacturing or production in different markets or geographies, easily add and remove contractors to adapt to changing business needs, and move applications to the cloud cost-effectively without sacrificing security.

ZTNA solutions also need to work in tandem with microsegmentation solutions to deliver unified controls. If, for example, a user account has been hijacked after it’s been given access to the ZTNA, microsegmentation can still prevent it from spreading to other workloads. Organizations should seek solutions that can integrate directly with existing identity infrastructures as well, even if they include multiple directories and identity service providers. This allows the ZTNA service to be deployed quickly with no need to change the existing identity infrastructure or architecture.

Look to the edge

There is also a significant differentiator among the products in the marketplace that the Zero Trust purchasing teams may not take into consideration but definitely should. Solutions that are combined with edge cloud platforms can offer additional benefits by acting as an identity-aware proxy that abstracts connectivity to the edge platform, ensuring that all authentication happens at the edge and away from the data center. Although some companies turn to access proxy architectures run within the DMZ, this fails to take advantage of the cloud’s ability to better absorb attacks, provide bandwidth for caching, and autoscale as needed.

An identity-aware proxy built in the cloud can scale on demand, run CPU-heavy resources, and absorb attacks. Moreover, it sits on a private IP address that is not directly reachable from the internet. The activities that are most performance- and security-sensitive take place at the edge, closest to the end user. Additionally, the sensitive ingress path into the application happens over a reverse application tunnel, effectively removing the IP visibility of the perimeter and reducing the risk of volumetric attacks.

As AI accelerates attacks across multiple vectors at once — combining network and application DDoS attacks, API attacks, and more into coordinated campaigns — mounting defenses further away from the network becomes even more important.

MFA considerations in building a Zero Trust blueprint

Since the COVID-19 pandemic, the rise of remote work and the need for greater access have meant most organizations have already embraced MFA and have some sort of solution in place. It’s important to recognize, however, that the combination of enterprise-wide access and MFA is greater than the sum of its parts. MFA is central to the concept of trust because it requires you to have more than just a password. You need a second verification to ensure that you’re not falling prey to one of the most commonly abused areas of trust. It’s also important to remember that not all MFA solutions are created equal.

Traditional “push” MFA is no longer enough in the age of AI-powered deepfakes, where AI-automated prompt bombing and voice cloning have nearly automated credential theft. Today, FIDO2/WebAuthn-compliant MFA solutions are the only way to achieve phish-proof protection.

When evaluating MFA solutions as part of a Zero Trust strategy, organizations should look for solutions that are:

Integrated with identity and access management (IAM)

Compliant with FIDO2 to ensure user credentials are isolated and encrypted on users’ personal devices

Able to verify users via their smartphone without relying on a physical key

Microsegmentation: The containment engine

There is no perfect state of Zero Trust. To assume otherwise is to ignore the reality of modern attacks. Inevitably, persistent attackers or autonomous shadow agents will find a gap. Therefore, a resilient architecture requires more than just perimeter defense — it requires an internal containment engine.

Traditionally, organizations relied on firewalls and VLANs to segment networks and protect critical applications, but these hardware-centric choke points are expensive, rigid, and often unaware of the nuances of modern, distributed traffic. Today, the strategy has shifted toward software-based microsegmentation, moving away from threat hunting toward proactive exposure mapping.

This shift provides two advantages. First, it ensures that most attacks are pre-contained. By implementing precise segmentation rules based on a deep understanding of application dependencies, you effectively shrink the blast radius before an incident even begins. Second, in an active threat scenario, solutions with AI-powered segmentation rules enable a rapid incident response. Security teams can dynamically isolate compromised segments without a total network blackout. This shift moves organizations away from a reactive mitigation model to a proactive model in their defense and quarantining strategies. Causing the attacker to hit friction along the attack chain is key for organizations to stay resilient, even while experiencing a breach event.

Differentiators: AI-powered operationalization

While microsegmentation is a core pillar of Zero Trust, not all solutions are equally appropriate. Legacy tools built as network-first appliances or those confined to on-premises silos are significant red flags. An AI-ready solution must offer comprehensive visibility across hybrid environments, from legacy Windows 2008 servers to modern Kubernetes clusters and agentless IoT/OT devices.

After all, if a solution covers only 80% of your footprint, it leaves 20% of your business as an open playground for lateral movement.

Historically, microsegmentation projects failed due to the labor-intensive nature of manual policy creation — a process that could take months of guesswork and that risks breaking critical business flows. Modern solutions like Akamai Guardicore Segmentation change this math using our Generative Policy Engine (GPE). By leveraging LLMs to analyze real-time traffic flows, organizations can generate, simulate, and approve valid security policies in minutes rather than months.

From visibility to enforcement

Sophisticated microsegmentation requires more than just Layer 4 port blocking — it requires Layer 7 granularity. For example, attackers frequently exploit the services of svchost to move laterally. While you cannot block svchost entirely, a sophisticated engine can enforce policy at the microservices layer, isolating specific tasks while allowing essential system functions to continue.

Akamai provides a map — a near-real-time visualization of every communication flow in your environment. With targeted recommendations, enterprises understand what needs to be addressed first based on impact while continuously verifying security controls based on context from the rest of the security stack. As environments evolve, controls can keep pace and protections stay current and effective. This is what is now required in today’s AI-driven threat landscape.

DNS firewall

In a Zero Trust environment, it’s not just people who can’t be trusted, but the internet itself. Employees need access to the internet, and as SaaS and mobile applications, cloud services, hybrid work, and IoT devices spread, so too does an organization’s attack surface. Protecting the organization and users against threats such as malware, ransomware, phishing, and data exfiltration becomes exponentially more difficult when those methods are backed by AI.

Organizations have limited resources to manage security control point complications and complexities. Additionally, the prospect of frontier LLMs that can find long-hidden vulnerabilities in just hours means that the companies most at risk are those that struggle to patch systems, plug security gaps, and manage the complexity of their applications and network infrastructure.

What’s more, the proliferation of internal AI initiatives has led to shadow AI. This is similar to shadow APIs that emerge without security oversight; new AI projects are emerging that may bypass established security protocols, leaving organizations vulnerable. That includes new APIs that link to outside LLMs or an AI copilot that creates its own unvetted API. Suddenly, there’s a whole new avenue for data leakage, and organizations need a DNS firewall that detects data being tunneled out via unauthorized LLM API endpoints.

Core Zero Trust requirements of DNS firewall investment

While seemingly straightforward, there are requirements that technology buyers must consider when investing in a DNS firewall. Many organizations have deployed on-premises DNS firewalls but now need to extend that protection to users no matter their location. Similar to identity management, providers that have robust edge platforms typically have stronger DNS security, thanks to the threat intelligence garnered from the extended platform. Decision-makers should carefully consider these core requirements.

  • DNS inspection. Providers should be able to provide real-time inspections of all domains with sophisticated threat intelligence and automatically block malicious domains. Solutions also need to be effective across all ports and protocols to protect against malware that does not use standard web ports and protocols. The quality of DNS inspection can vary greatly across providers, and buyers should look for those with experience in the marketplace and established customer success.
  • Protection for all devices. Providers should have agents for devices that will be used on- and off-network, such as laptops, smartphones, and tablets.
  • Flexible DNS onboarding. Providers should have multiple methods to forward DNS requests to the DNS firewall to deliver maximum flexibility to cover all use cases.
  • DNS exfiltration identification and blocking. DNS exfiltration, especially low-throughput variations, can enable attackers to exfiltrate data over the DNS channel. Look for providers that have both inline and offline DNS exfiltration detections based on proprietary detection algorithms. Buyers should pay close attention to solutions that use AI for detecting leakage.

Threat monitoring

While AI — and frontier LLMs in particular — are transforming the way attackers seek out vulnerabilities, the same can be said for threat hunting. Much of the previously tedious work can now be automated. They should also consider the following four pillars for effective threat monitoring.

Key considerations

1. AI-enabled analysis and mapping

Features like Akamai’s exposure analysis and response have automated what was once a tedious process of manually mapping dependencies, flagging exposed paths an attacker might take, and suggesting microsegmentation policies. As security teams evaluate the solutions in the marketplace, AI-enabled mapping capabilities like this should be high on the list of important criteria.

2. Effective algorithms

Sophisticated algorithms with a track record of success — based on user and network activity anomalies, executable analysis, log analysis, and more — should be part of any threat-monitoring service.

3. Strong signal detection

Although software and AI are vital tools in threat monitoring, Zero Trust decision-makers should still evaluate the internal expertise of the vendors with whom they’re working. Threat-monitoring services need to be able to separate the good signals from the bad to help avoid alert fatigue and provide immediate notifications of any incident. Organizations should also expect regular reports with analyses of any high-profile campaigns.

4. Experienced staff

Teams should include people with a broad range of backgrounds, including offense, incident response, and data science, and should be available 24/7. This is an area where content delivery providers can add a substantial benefit. The insights from monitoring hundreds of terabytes per second contribute a unique perspective to any signal detection.

Where to begin?

A Zero Trust initiative is never complete, so for those considering the software, hardware, and hiring requirements, the primary question is often, “Which technology do we begin with?”

As with so many things, the answer is going to depend on a company’s individual needs, risk assessments, and relative strengths and weaknesses. For many industry observers, the answer is to begin by implementing ZTNA. Indeed, protecting the organization against malicious north-south traffic can be a prudent starting point. Yet there are also those who believe that an east-west approach with microsegmentation, specifically software-defined microsegmentation, is the better route.

The case for starting with microsegmentation

If you believe, as most experts do, that there is no perfect defense and a malicious attack will eventually make its way through, then you want to be able to protect your most valuable assets. This is what microsegmentation offers. One reason organizations may be reluctant to start with microsegmentation is the perception of complexity.

First, microsegmentation is not an all-or-nothing approach. Like Zero Trust itself, it can be undertaken in stages. Organizations can begin by identifying their most valuable assets. Focus on what’s critical. Ensure that if someone gets into your system, they can’t bring your business down. The importance of an asset can be based on the data inside that asset, or on the existing level of protection.

In many cases, you will want a microsegmentation solution that will cover your legacy systems, as these systems are often running business-critical applications and are especially vulnerable. There are some microsegmentation solutions that don’t support securing those legacy systems.

Second, software-defined microsegmentation removes much of the perceived complexity. You will not need to deal with hardware or to call on your network architects and security architects repeatedly. Nor will you need to spend months creating, modifying, and implementing policy. AI has lowered the barriers to adoption with features like Akamai’s Generative Policy Engine, which autonomously synthesizes enforcement-ready segmentation rules by modeling application behavior and mapping that intent to deep workload telemetry, including processes, users, and fully qualified domain names.

Furthermore, if you believe a breach is just a matter of time, and AI-powered attacks are making them more powerful and costly than ever, then it makes sense to start with the most effective method for stopping a breach — locking down any movement once it’s inside.

Once a microsegmentation initiative has begun, the early benefits are clear and can help push the rest of the project forward. For example, you will now have an objective source of truth for what’s happening in your environment. You can get that right away without even enforcing policy, and once you do, you’ll have a great understanding of how flows are happening. Additionally, once an organization begins application ringfencing, you can easily lock down critical services so they’re only communicating over specific ports and processes.

Alternatively, a quick win might be targeting threat-specific policies. Sophisticated microsegmentation platforms will have positive security concepts built in. That means you can rapidly create a policy to stop unnecessary connections between remote desktop services and the internet. Organizations can quickly close off the kind of vulnerability that led to the Colonial Pipeline attack, for example.

Whatever the starting point, the key to any ongoing Zero Trust journey is balance — world-class identity management coupled with poor segmentation or poor web access protections does not produce good security.

Digital fingerprint composed of binary code and data nodes representing biometric cybersecurity.

Platform vs. specialized tools

As with many technology decisions, buying Zero Trust software often comes down to the choice between individual specialists and a platform that combines multiple components. The impact of Zero Trust across security teams, integrators, architects, and analysts — and their need to maintain policy across multiple consoles, agents, and integrations — offers a compelling case to go the platform route. This is particularly true in a tight labor market with a shortage of skilled cybersecurity professionals. Managing solutions from multiple vendors can increase personnel costs significantly, as solutions that do not effectively communicate with one another create false positives, which burden end users and can require additional support and training.

As AI-enabled threats mount, attackers are no longer just looking for a weak spot, but all your weak spots at once. This makes having centralized policy creation and coordinated automation vital. Additionally, an organization with a sophisticated Zero Trust defense will have tight integration across all parts of its security stack — from security information and event management to endpoint detection and response to threat intel. The platform approach significantly simplifies this for a modern organization versus taking the best-of-breed road.

Finally, the proverbial “one hand to shake” when it comes to support and contract negotiations provides a compelling case for implementing Zero Trust with a platform provider.

Ideally, you should look for a single provider with a flexible approach — one that offers a comprehensive platform for Zero Trust alongside individual point products. This flexibility makes it easier to achieve Zero Trust while enjoying the benefits of a single provider.

Revisiting the elements of Zero Trust in the AI age

Don’t trust any entity; constantly verify

Understand who’s attempting access and the health of their device.

Once verified, provide minimal access

Users and workflow access should be limited by role.

Continuously monitor

Unauthorized activity is blocked by default.

Automate exposure analysis

Manual processes are not enough. AI-enabled defense must target policy and enforcement based on impact.

Winning the AI cybersecurity struggle

Today, AI-powered cyberattacks have made the traditional cybersecurity approach of “detect and respond” obsolete. When autonomous agents and AI-enabled malware can map a network and execute lateral movement in mere minutes, human-paced investigation is no longer a viable defense. In this landscape, speed is the only definitive advantage.

Winning the AI cybersecurity struggle requires a fundamental shift in strategy: moving from chasing attackers to preemptive containment. A Zero Trust blueprint that encompasses a comprehensive platform across ZTNA, microsegmentation, DNS firewalls, and phish-proof MFA is vital to business resilience. By replacing manual guesswork with AI-driven defenses, organizations can shrink their blast radius and enforce security at the microservices layer before a threat even materializes. As we navigate this era of AI risks, the winner will not be the one manually responding to the most alerts but the one whose architecture is built to contain the invisible by default.

Akamai helps you jump-start this journey by securing every interaction. The Generative Policy Engine in Akamai Guardicore Segmentation transforms months of manual rule-setting into minutes of AI-driven policy creation, instantly mapping your exposure. By combining these core elements of Zero Trust, Akamai helps you to govern autonomous agents and contain lateral movement at machine speed. Transform complex security into operational simplicity, ensuring your architecture is resilient against the threats of tomorrow — allowing you to innovate today.

Gartner Peer Insights Customer' Choice 2026

Need more validation?

See why the 2026 Gartner® Peer Insights™ report recognizes Akamai as a Customers’ Choice for Microsegmentation.

Stop attacks from spreading with microsegmentation

Akamai Guardicore Segmentation gives you better visibility to control and stop the spread.

Get real-time visibility and powerful control against lateral movement. See how Akamai Guardicore Segmentation helps you protect your network and stay ahead of attacks.

Share