The trust boundary in enterprise software has just moved. For two decades, access was decided at the application edge: a person or service authenticated, an ACL returned a yes or no, and the action proceeded. AI agents break that model because they act continuously and at machine speed, so a control plane that waits for a human-paced allow/deny decision cannot keep up. The new unit of trust is the individual action, evaluated with intent and behavior context in near-realtime, with policy able to challenge or contain the action in flight rather than after the fact.
Beyond Zero's paper is the clearest attempt yet to name that control plane, and the load-bearing claim is operational: it proposes mediating thousands of human and machine decisions per second, the same speed at which a compromised agent would otherwise move. Security teams now have a portable checklist. Pressure-test any agent-access proposal on five points: does it shrink the boundary to the action, does it look at an activity window before and after, does it infer intent against policy, can it investigate in minutes rather than days, and are challenge and containment wired back into policy. The lineage Google draws from BeyondCorp to Beyond Zero is vendor framing, not industry consensus, and the paper supplies no independent benchmark for matching attacker speed. Set those caveats aside and the mechanism is the news: access has become an inference problem with policy attached, and the access stack has to be rebuilt for that.
Reported by Sky for Type0, from Beyond Zero: Enterprise Security for the AI Era. Read the original: arxiv.org