Artificial intelligence has rapidly evolved past the point of simply answering a few basic prompts on a screen. We are living in an era where autonomous AI agents are taking over complex corporate workflows, talking to other systems, and processing sensitive data at machine speed. While this brings an incredible boost to daily operational efficiency, it also introduces a massive headache for corporate IT and security teams.
The problem is that traditional enterprise cybersecurity tools were built entirely around known human identities and predictable access behaviours. Automated AI agents throw that textbook out the window. They operate autonomously on a user’s behalf, create temporary or ephemeral identities, and spawn their own sub-agents far faster than human teams can keep track of. This leaves a gaping blind spot in data governance, making data flows incredibly difficult to trace at scale.

To tackle this exact paradigm shift, Zscaler has announced a major expansion of its security ecosystem, delivering the industry’s first complete Zero Trust platform for Agentic AI. This new evolution moves away from standard human-centric parameters and focuses directly on protecting how autonomous agents connect, handle data, and run on local devices. It is a necessary shift in approach, especially considering how deeply exposed endpoints are becoming to malicious tools and plugins that legacy endpoint solutions fail to see.
Taming the AI Ecosystem with Brokers and Endpoint Protections
At the centre of this platform update are two crucial additions designed to control autonomous agent behaviours. The first is the Zscaler AI Broker, which essentially acts as a strict gatekeeper for your digital workforce. It secures agentic communications across Model Control Platforms and Agent-to-Agent connections. By utilizing an integrated Agent Registry, it allows security administrators to understand and pinpoint exactly what data each agent is authorized to interact with, enforcing fine-grained policies so that automated tools do not wander into sensitive corporate repositories.
Complementing this backend control is Zscaler Endpoint AI Security, which shifts the focus to employee hardware. The reality of daily enterprise use is that rogue plugins, sketchy browser extensions, and localised AI tools often introduce severe threats that legacy endpoint software misses entirely. Zscaler is extending its capabilities right into the browser, extension, and plugin layers, allowing organisations to enforce uniform security policies whether an asset is sitting in the cloud or running locally on a laptop.
Tracking Data Lineage via AI Access Graph
To help security teams make sense of these automated workflows, Zscaler is also introducing the AI Access Graph. Powered by technology from Zscaler’s recent acquisition of Symmetry Systems, this visualisation engine maps out exactly how identities, applications, and data sources connect across the enterprise. When dealing with autonomous tools that function independently, tracing data lineage in real-time becomes critical. The AI Access Graph lets organisations track data movements explicitly, allowing them to validate policies, adjust access rights dynamically, and cut off unnecessary risks before they can escalate.

Beyond these new architectural frameworks, Zscaler is also pushing major updates to its existing AI Protect suite to strengthen runtime visibility. Its AI Asset Management tool can now discover embedded AI hidden within standard SaaS and internet traffic while scanning codebases to uncover risks in agentic environments. For companies utilising external generative tools, the Secure Access to AI features have been expanded to protect against prompt extraction across more than 250 popular apps. Finally, the infrastructure layer gains a standalone prompt hardening service and advanced AI red teaming tailored specifically for Model Control Platforms to identify structural weaknesses before bad actors do.
Ultimately, enterprise technology is moving too quickly for organisations to freeze adoption due to security anxiety. By embedding these granular Zero Trust boundaries directly into machine-speed workflows, Zscaler is attempting to make autonomous operations viable for risk-averse corporate environments, giving companies the confidence to let AI agents do their jobs safely.
