Bottom line: With “Least Agency Enforcement,” Zero Networks introduces a network-based control that restricts AI agents to authorized systems via micro-segmentation and just-in-time MFA, following OWASP principles, in order to contain damage in the event of a compromise.
Security vendor Zero Networks has unveiled “Least Agency Enforcement,” a new capability that restricts AI agents not at the application level but at the network and identity level. The goal is to limit the damage should an agent be manipulated, misconfigured, or compromised.
Zero Networks announced the launch of “Least Agency Enforcement” on Monday, a capability built on the company’s own identity-based micro-segmentation platform. The solution implements the “Least Agency” principle formulated by OWASP as part of its Agentic Applications Top 10 project, under which organizations should explicitly limit the autonomy, tool access, and decision-making authority of AI agents in order to reduce risks such as prompt injection, privilege abuse, and compromised agents. The feature restricts which systems an agent is allowed to communicate with, which resources it can access, and when human approval is required for sensitive actions.
According to Chris Boehm, Field CTO at Zero Networks, most vendors currently take an application-level approach that focuses on prompts and model outputs. Zero Networks, by contrast, addresses the question of what an agent can achieve if it is manipulated, misconfigured, or simply malfunctioning — regardless of what it was originally deployed for. According to the company’s own research, roughly 80 percent of organizations already have internal AI agents in use, while about two-thirds still lack corresponding governance policies.
Technically, Least Agency Enforcement combines identity-based micro-segmentation, automated policy generation, and just-in-time multi-factor authentication (MFA). The system maps what an agent identity is allowed to access and enforces this at the host firewall level — anything outside this defined set is blocked by default. CEO and co-founder Benny Lakunishok describes the approach as transferring the least-privilege principle from human users to AI agents, with the difference that enforcement must be automated. A deceived or misused agent should thus hit a boundary almost immediately, rather than being able to move through the network unchecked.
Zero Networks explicitly positions the feature not as a competitor to IAM, PAM, or non-human identity platforms, but as a complement for the phase after authentication. According to the company, classic IAM and PAM tools primarily govern whether an AI is allowed to gain access in the first place — but once an authenticated session is running, these tools generally no longer control where the agent can move within the network. According to Boehm, sensitive protocol paths receive an MFA prompt directly at the protocol level, so that a compromised agent identity cannot move laterally across the network via RDP, SMB, or WinRM undetected.
The new capability expands Zero Networks’ existing AI security portfolio, which already includes AI Agents Control, AI Segmentation, AI SaaS Control, and protections for enterprise LLM deployments. Least Agency Enforcement is available immediately and is set to be demonstrated at Black Hat USA 2026.
Source: www.csoonline.com · Published August 3, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.