{"id":348170,"date":"2026-03-19T23:52:11","date_gmt":"2026-03-19T23:52:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/il\/348170\/"},"modified":"2026-03-19T23:52:11","modified_gmt":"2026-03-19T23:52:11","slug":"new-tools-and-guidance-announcing-zero-trust-for-ai","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/il\/348170\/","title":{"rendered":"New tools and guidance: Announcing Zero Trust for AI"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Over the past year, I have had conversations with security leaders across a variety of disciplines, and the energy around AI is undeniable. Organizations are moving fast, and security teams are rising to meet the moment. Time and again, the question comes back to the same thing: \u201cWe\u2019re adopting AI fast, how do we make sure our security keeps pace?\u201d<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s the right question, and it\u2019s the one we\u2019ve been working to answer by updating the tools and guidance you already rely on. We\u2019re announcing Microsoft\u2019s approach to Zero Trust for AI (ZT4AI). Zero Trust for AI extends proven Zero Trust principles to the full AI lifecycle\u2014from data ingestion and model training to deployment and agent behavior. Today, we\u2019re releasing a new set of tools and guidance to help you move forward with confidence:<\/p>\n<p>A new AI pillar in the <a href=\"https:\/\/microsoft.github.io\/zerotrustassessment\/guide\" rel=\"nofollow noopener\" target=\"_blank\">Zero Trust Workshop<\/a>.<\/p>\n<p>Updated Data and Networking pillars in the Zero Trust Assessment tool.<\/p>\n<p>A new Zero Trust reference architecture for AI.<\/p>\n<p>Practical patterns and practices for securing AI at scale.<\/p>\n<p class=\"wp-block-paragraph\">Here\u2019s what\u2019s new and how to use it. <\/p>\n<p>Why Zero Trust principles must extend to AI<\/p>\n<p class=\"wp-block-paragraph\">AI systems don\u2019t fit neatly into traditional security models. They introduce new trust boundaries\u2014between users and agents, models and data, and humans and automated decision-making. As organizations adopt autonomous and semi-autonomous AI agents, a new class of risk emerges: agents that are overprivileged, manipulated, or misaligned can act like \u201cdouble agents,\u201d working against the very outcomes they were built to support.<\/p>\n<p class=\"wp-block-paragraph\">By applying three foundational principles of Zero Trust to AI:<\/p>\n<p>Verify explicitly\u2014Continuously evaluate the identity and behavior of AI agents, workloads, and users.<\/p>\n<p>Apply least privilege\u2014Restrict access to models, prompts, plugins, and data sources to only what\u2019s needed.<\/p>\n<p>Assume breach\u2014Design AI systems to be resilient to prompt injection, data poisoning, and lateral movement.<\/p>\n<p class=\"wp-block-paragraph\">These aren\u2019t new principles. What\u2019s new is how we apply them systematically to AI environments.<\/p>\n<p>A unified journey: Strategy \u2192 assessment \u2192 implementation<\/p>\n<p class=\"wp-block-paragraph\">The most common challenge we hear from security leaders and practitioners is a lack of a clear, structured path from knowing what to do to doing it. That\u2019s what Microsoft\u2019s approach to Zero Trust for AI is designed to solve\u2014to help you get to next steps and actions, quickly.<\/p>\n<p>Zero Trust Workshop\u2014now with an AI pillar<\/p>\n<p class=\"wp-block-paragraph\">Building on last year\u2019s <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/07\/09\/microsoft-expands-zero-trust-workshop-to-cover-network-secops-and-more\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">announcement<\/a>, the <a href=\"https:\/\/microsoft.github.io\/zerotrustassessment\/guide\" rel=\"nofollow noopener\" target=\"_blank\">Zero Trust Workshop<\/a> has been updated with a dedicated AI pillar, now covering 700 security controls across 116 logical groups and 33 functional swim lanes. It is scenario-based and prescriptive, designed to move teams from assessment to execution with clarity and speed.<\/p>\n<p class=\"wp-block-paragraph\">The workshop helps organizations:<\/p>\n<p>Align security, IT, and business stakeholders on shared outcomes.<\/p>\n<p>Apply <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/zero-trust\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Zero Trust principles<\/a> across all pillars, including AI.<\/p>\n<p>Explore real-world AI scenarios and the specific risks they introduce.<\/p>\n<p>Identify cross-product integrations that break down silos and drive measurable progress.<\/p>\n<p><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on-async--click=\"actions.showLightbox\" data-wp-on-async--load=\"callbacks.setButtonStyles\" data-wp-on-async-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/ZT-Workshop-scaled.webp.webp\" alt=\"Image of the Zero Trust Workshop Dashboard that demonstrates a first, then, next approach to making progress along your Zero Trust journey. \" class=\"wp-image-145874 webp-format\"  data-orig-src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/ZT-Workshop-scaled.webp.webp\"\/><\/p>\n<p class=\"wp-block-paragraph\">The new AI pillar specifically evaluates how organizations secure AI access and agent identities, protect sensitive data used by and generated through AI, monitor AI usage and behavior across the enterprise, and govern AI responsibly in alignment with risk and compliance objectives.<\/p>\n<p>Zero Trust Assessment\u2014expanded to Data and Networking<\/p>\n<p class=\"wp-block-paragraph\">As AI agents become more capable, the stakes around data and network security have never been higher. Agents that are insufficiently governed can expose sensitive data, act on malicious prompts, or leak information in ways that are difficult to detect and costly to remediate. Data classification, labeling, governance, and loss prevention are essential controls. So are network-layer defenses that inspect agent behavior, block prompt injections, and prevent unauthorized data exposure.<\/p>\n<p class=\"wp-block-paragraph\">Yet, manually evaluating security configurations across identity, endpoints, data, and network controls is time consuming and error prone. That is why we built the Zero Trust Assessment to automate it. The <a href=\"https:\/\/aka.ms\/zerotrust\/assessment\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Zero Trust Assessment<\/a> evaluates hundreds of controls aligned to Zero Trust principles, informed by learnings from Microsoft\u2019s <a href=\"https:\/\/www.microsoft.com\/en-us\/trust-center\/security\/secure-future-initiative\" rel=\"nofollow noopener\" target=\"_blank\">Secure Future Initiative (SFI)<\/a>. Today, we are adding Data and Network as new pillars alongside the existing Identity and Devices coverage.<\/p>\n<p><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on-async--click=\"actions.showLightbox\" data-wp-on-async--load=\"callbacks.setButtonStyles\" data-wp-on-async-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/Picture4.webp.webp\" alt=\"Image of the Zero Trust Assessment dashboard that demonstrates the output of the Zero Trust Assessment being run in a customer environment. \" class=\"wp-image-145858 webp-format\"  data-orig-src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/Picture4.webp.webp\"\/><\/p>\n<p class=\"wp-block-paragraph\">Zero Trust Assessment tests are derived from trusted industry sources including:<\/p>\n<p>Industry standards such as the National Institute of Standards and Technology (NIST), the Cybersecurity and Infrastructure Security Agency (CISA), and the Center for Internet Security (CIS).<\/p>\n<p>Microsoft\u2019s own learnings from SFI.<\/p>\n<p>Real-world customer insights from thousands of security implementations.<\/p>\n<p class=\"wp-block-paragraph\">And we are not stopping here. A Zero Trust Assessment for AI pillar is currently in development and will be available in summer 2026, extending automated evaluation to AI-specific scenarios and controls.<\/p>\n<p class=\"wp-block-paragraph\">Overall, the redesigned experience delivers:<\/p>\n<p>Clearer insights\u2014Simplified views that help teams quickly identify strengths, gaps, and next steps.<\/p>\n<p>Deep(er) alignment with the Workshop\u2014Assessment insights directly inform workshop discussions, exercises, and deployment paths.<\/p>\n<p>Actionable, prioritized recommendations\u2014Concrete implementation steps mapped to maturity levels, so you can sequence improvements over time.<\/p>\n<p>Zero Trust for AI reference architecture<\/p>\n<p class=\"wp-block-paragraph\">Our new Zero Trust for AI reference architecture (extends our existing Zero Trust reference architecture) shows how policy-driven access controls, continuous verification, monitoring, and governance work together to secure AI systems, while increasing resilience when incidents occur.<\/p>\n<p><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on-async--click=\"actions.showLightbox\" data-wp-on-async--load=\"callbacks.setButtonStyles\" data-wp-on-async-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/Picture5.webp.webp\" alt=\"Image of the Zero Trust Framework that demonstrates the new AI capability that Microsoft is announcing. \" class=\"wp-image-145859 webp-format\"  data-orig-src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/03\/Picture5.webp.webp\"\/><\/p>\n<p class=\"wp-block-paragraph\">The architecture gives security, IT, and engineering teams a shared mental model by clarifying where controls apply, how trust boundaries shift with AI, and why defense-in-depth remains essential for agentic workloads.<\/p>\n<p>Practical patterns and practices for AI security<\/p>\n<p class=\"wp-block-paragraph\">Knowing what to do is one thing. Knowing how to operationalize it at scale is another. Our <a href=\"https:\/\/www.microsoft.com\/en-us\/trust-center\/security\/secure-future-initiative\/patterns-and-practices\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">patterns and practices<\/a> provide repeatable, proven approaches to the most complex AI security challenges, much like software design patterns offer reusable solutions to common engineering problems.<\/p>\n<p>PatternWhat it helps you doThreat modeling for AI<a href=\"https:\/\/aka.ms\/SFI_ThreatModeling\" rel=\"nofollow noopener\" target=\"_blank\">Why traditional threat modeling breaks down for AI\u2014and how to redesign it for real-world risk at AI scale<\/a>.AI observability<a href=\"https:\/\/aka.ms\/SFI_AIObservability\" rel=\"nofollow noopener\" target=\"_blank\">End-to-end logging, traceability, and monitoring to enable oversight, incident response, and trust at scale<\/a>.Securing agentic systems<a href=\"https:\/\/aka.ms\/SFI_SecuringAgenticSystems\" rel=\"nofollow noopener\" target=\"_blank\">Actionable guidance on agent lifecycle management, identity and access controls, policy enforcement, and operational guardrails<\/a>.Principles of robust safety engineering<a href=\"https:\/\/aka.ms\/SFI_RobustSafetyEngineering\" rel=\"nofollow noopener\" target=\"_blank\">Core safety engineering principles and how to apply them when designing and operating real-world AI systems<\/a>.Defense-in-depth for Indirect prompt injection (XPIA)How Indirect Prompt Injection works, why traditional mitigations fail, and how a defense\u2011in\u2011depth approach\u2014spanning input handling, tool isolation, identity, memory controls, and runtime monitoring\u2014can meaningfully reduce risk.<\/p>\n<p>See it live at RSAC 2026<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019re attending <a href=\"https:\/\/microsoftsecurityevents.eventbuilder.com\/Employees?ref=Employees\" rel=\"nofollow noopener\" target=\"_blank\">RSAC\u2122 2026 Conference<\/a>, join us for three sessions focused on Zero Trust for AI\u2014from expanding attack surfaces to hands-on, actionable guidance.<\/p>\n<p>WhenSessionTitleMonday, March 23, 2026, 1:00 PM PT-2:00 PM PT<a href=\"https:\/\/forms.office.com\/Pages\/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR-Nb77L0c5tDgIRsCqN_eA1UNVJXTVhJM0xRMjQyRjhSVUlVMkhTVUZOMi4u\" rel=\"nofollow noopener\" target=\"_blank\">RSA Partner Roundtable<\/a>, by Lorena Mora (Senior Product Manager CxE), Charis Babokov (Senior Product Marketing Manager, Microsoft Intune), and Jodi Dyer (Senior Product Marketing Manager, Microsoft Intune)Zero Trust Workshop: Devices PillarWednesday, March 25, 2026, 11:00 AM PT-11:20 AM PTZero Trust Theatre Session, by Tarek Dawoud (Principal Group Product Manager, Microsoft Security) and Hammad Rajjoub (Director, Microsoft Secure Future Initiative and Zero Trust)Zero Trust for AI: Securing the Expanding Attack SurfaceWednesday, March 25, 2026, 12:00 PM PT-1:00 PM PTAncillary Executive Session, by Travis Gross (Principal Group Product Manager, Microsoft Security), Eric Sachs (Corporate Vice President, Microsoft Security), and Marco Pietro (Executive Vice President, Global Head of Cybersecurity, Capgemini), moderated by Mia Reyes (Director of Security, Microsoft). Building Trust for a Secure Future: From Zero Trust to AI ConfidenceThursday, March 26, 2026, 11:00 AM PT-12:00 PM PTRSAC Post-Day Workshop, by Travis Gross, Tarek Dawoud, Hammad RajjoubZero Trust, SFI, and ZT4AI: Practical, actionable guidance for CISOs<\/p>\n<p>Get started with Zero Trust for AI<\/p>\n<p class=\"wp-block-paragraph\">Zero Trust for AI brings proven security principles to the realities of modern AI. Whether you\u2019re governing agents, protecting models and data, or scaling AI without introducing new risk, the tools, architecture, and guidance are ready for you today.<\/p>\n<p class=\"wp-block-paragraph\">Get started:<\/p>\n<p class=\"wp-block-paragraph\">To continue the conversation, join the <a href=\"https:\/\/techcommunity.microsoft.com\/category\/microsoft-security\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Security Community<\/a>, where security practitioners and Microsoft experts share insights, guidance, and real world experiences across Zero Trust and AI security. <\/p>\n<p class=\"wp-block-paragraph\">Learn more about Microsoft Security solutions on our\u00a0<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">website<\/a> and\u00a0bookmark the\u00a0<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft Security blog<\/a>\u00a0for expert insights on security matters. Follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Security<\/a>) and X (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" rel=\"nofollow noopener\" target=\"_blank\">@MSFTSecurity<\/a>)\u00a0for the latest cybersecurity news and updates.<\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Over the past year, I have had conversations with security leaders across a variety of disciplines, and the&hellip;\n","protected":false},"author":2,"featured_media":348171,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[345,343,344,85,46,125],"class_list":["post-348170","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-il","tag-israel","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/348170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/comments?post=348170"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/348170\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media\/348171"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media?parent=348170"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/categories?post=348170"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/tags?post=348170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}