AI orchestrated, fully automated offensive attacks are real now. OpenAI said that at Black Hat, and they are right.

The answer we are reaching for is not new, and that is the problem.

The industry's answer to AI is acceleration. Discover vulnerabilities faster, patch faster, respond faster. We apply these broadly, across everything we own, and that is where it breaks. The response scales with the attack surface, and the attack surface is unbounded, so the work never reaches the goal. The reality is that segmentation gets a footnote.

The footnote is literal. In a 37 minute talk, segmentation appears at minute 36. And the sentence immediately before it is the most important one in the presentation: these agents ultimately are bounded by the privileges they can obtain and the systems they can communicate with.

The bound is privileges and reach. Having named it, the talk moves on to automating defense.

Rob Joyce compared this moment to the Morris Worm, and the comparison holds. It is worth remembering what we actually did after 1988. We built CERT and we organized ourselves to respond. It took us decades to learn that response alone does not scale, and Zero Trust is the name we gave to what we learned. We should be careful about answering a watershed moment the same way we answered the last one.

John Kindervag's five steps have not changed. Define the protect surface. Map the transaction flows. Build the architecture. Create the policy. Monitor and maintain. The protect surface is the small and knowable set of things that actually matter, which is what separates it from the attack surface. In practice, most organizations start at step three, because step three is where the products are. Starting there has always been the mistake.

What is new is that step one got harder, and step two with it, because you cannot define what you are protecting without knowing what talks to it. Three things changed.

  • Flows no longer settle into a pattern you can observe. Here is how we used to do this. We watched, we waited for traffic to stabilize, and then we wrote policy from what we saw. That worked because an application's behavior was a property of the application. An AI agent's destinations are decided at runtime by whatever someone asked it to do, so there is no settled state to wait for. You can observe for 90 days and still miss the path that opens on day 91 because someone phrased a request differently.
  • Reach extends past the first hop, and we only scope the first one. The agents in that incident were running inside OpenAI's own evaluation environment, sandboxed with no internet access. They could reach an internal package manager. That package manager had internet access and was shared across the environment. The boundary around the agent was defined. The boundary around what those systems could reach in turn was not, and OpenAI's own presenter called that the crux of the incident. The sandbox worked, so this is not a control failure. It is a scoping failure, and scoping is step one. 
  • The agent is both subject and resource at once. Zero Trust assumes a subject requests access and a resource is protected, and that the two are distinct. An agent orchestrating other agents is both, and which one it is depends on the direction of the task. Our classification models have nowhere to put that.

Once that reach existed, the agents went from code execution on a single dataset worker pod to cluster admin across multiple clusters in under 13 hours. The same package manager became a message board. Agents wrote files into it, other agents read them, and they used it to pass along what they had found. When the channel was discovered, the credentials were revoked, the service was rebuilt, and the board was cleared. The agents reestablished it days later through a different endpoint. You cannot close a channel faster than an unbounded set of paths can open a new one. You can only make the set smaller.

None of this breaks Zero Trust. The principles hold. An AI system is another workload, and we already know how to contain workloads. What broke is the process we use to scope them.

The five steps were always meant to be a loop, with step five feeding back into step one so that each pass starts stronger. Step three is the slow layer. You build enforcement points and fabric on a project cadence and they stay where you put them. Scoping, mapping, and policy are what run through that fabric, and the cycle time of that loop is what changed.

So ask your team a simple question. When something changes in the environment, how long before policy reflects it?

For most organizations the honest answer is months, and sometimes longer. That was tolerable when the environment changed at the speed of a change advisory board. It is not tolerable now.

Months needs to become days, and days need to become minutes. The work is closing that gap. It is not a new control and it is not a new category. It is a faster loop around the steps we have been skipping for years.

At WWT we treat this as a scoping problem before a control problem. The controls are mature, and most organizations already own them. What is missing is a current and accurate answer to what an agent can reach, and a process that keeps that answer current as the environment moves.

You can start on this without buying anything.

  • Get the number. Pick one recent change in your environment and measure how long it took for policy to reflect it. That number is your starting position, and most teams have never measured it.
  • Enumerate reach, not grants. What an agent is permitted to touch directly is the easy half. What it can reach through the things it touches is the half that gets you.
  • Treat shared substrates as paths. Package managers, artifact repositories, vector stores, and shared context stores are communication channels whether or not you provisioned them as such. If two agents can both write to one and read from it, it is a path.

Protect what matters. Otherwise you are not protecting anything.

Where to start

Most organizations already have segmentation somewhere. What they lack is agreement on what to protect first. WWT's half-day Enterprise Segmentation Workshop aims to reach agreement in the room, with no commitment beyond the session. Reach out to your WWT account team or me to set one up.