Guest Author: Sanjit Ganguli, CTO-in-Residence, Zscaler
If there is one clear theme we’ve seen in the first half of 2026, it was this: Zero Trust is evolving from a framework for securing people and applications into a platform for securing AI-driven enterprises.
That shift is real: AI is no longer just another application layer to monitor. It is becoming an active participant in how work gets done. That means security leaders now have to think beyond user access and device posture to a world of AI agents, autonomous workflows, partner ecosystems and browser-based work.
Overall, we’ve seen three broad themes bubble up.
Now, we are still seeing a balance between vision and reality. At Zscaler’s annual user conference, leaders from organizations such as AWS, Merck, Carrier, Cognizant, KPMG, Siemens Healthineers and Alstom, among others, highlighted their real-world truths about what they are actually facing: accelerating AI adoption, pressure to modernize access models and the need to simplify security while reducing risk.
AI security is not just about protecting models or filtering prompts. It is about securing the full lifecycle of AI-driven activity inside the enterprise.
That is an important distinction. As organizations adopt more agentic AI, the security challenge changes. It is no longer only about whether a user should access an app. It becomes about whether an AI agent should access data, invoke tools, call another agent or act on behalf of a user. Those are fundamentally different trust decisions and in many cases they are happening at machine speed.
This is an extension of Zero Trust principles rather than a disconnected new category. Concepts such as an AI Broker and AI Access Graph point toward a model where enterprises can map, observe and govern the growing web of interactions between agents, data sources, applications and users.
That matters because agent sprawl may become one of the defining governance challenges of the next few years. If organizations do not have visibility into what agents are connected to, what authority they have and what actions they can take, then automation quickly turns into unmanaged risk.
One principle I’d highlight:
An AI agent should never have more authority than the person it represents—and often should have less. In security, delegation is where things often get messy. Give an agent too much privilege and you create a fast, scalable way to make bad decisions.
As a former Gartner analyst, I still tend to look at these moments through two lenses: is this just language catching up to a market trend or is there a genuine effort to define the architecture enterprises will actually need? I believe it is the latter, as the industry needs a practical control plane for the AI era, not just a new set of labels.
Zero Trust B2B connectivity, including the B2B Exchange concept, may sound less flashy than AI security, but for many enterprises it is one of the most operationally important shifts underway.
Third-party access has always been messy. Suppliers, contractors, service providers and partners all need access to applications and data, but most organizations still manage that through a patchwork of VPNs, network segmentation, manual exceptions and temporary workarounds. It is difficult to scale, difficult to audit and often far too permissive.
B2B access should no longer be treated as a network extension problem. It should be treated as an identity- and policy-based access problem. That is a much cleaner and more modern way to think about it.
The promise of Zero Trust B2B connectivity is straightforward: allow secure, precise, bi-directional access between business entities without exposing internal networks or relying on legacy VPN constructs. That reduces attack surface, simplifies operations and better reflects how modern ecosystems actually function.
I think this is especially relevant as enterprises become more dependent on partners in their day-to-day operations. The ecosystem edge is often where risk accumulates, because it sits outside traditional internal controls while still requiring meaningful access. If the only way to support those relationships is to punch controlled holes in the network, then the architecture is already showing its age.
Zero Trust is not only about securing employees working remotely. It is also about securely enabling the broader business network around the enterprise. In many ways, that broader network is where digital transformation either accelerates—or gets stuck.
In many ways, the Zero Trust Extension and Enterprise Browser may be one of the most practical announcements because it addresses the reality of how people actually work.
The browser has become the primary workspace for modern users. SaaS applications, internal web apps, collaboration tools, admin consoles and increasingly AI assistants all live there. Yet security controls have often lagged behind that reality. Organizations still tend to think in terms of trusted versus untrusted devices or managed versus unmanaged endpoints, when in fact the most important activity is often happening inside a web session.
That is why the browser is becoming such an important enforcement point.
Our Zero Trust Browser and related browser extension capabilities point toward a more granular model of control—one focused on what happens in-session rather than making broad assumptions about the device. That is especially useful for bring-your-own-device (BYOD), contractors, third parties and hybrid work scenarios where organizations want secure access without the cost and complexity of full device management or virtual desktops.
Localized data controls and browser detection and response are also important. Those capabilities indicate we are moving the Zero Trust enforcement point closer to the actual user experience. That is smart, because browser sessions are where users access sensitive data, interact with AI tools, upload content and collaborate externally.
In other words, if you want to understand modern work and modern risk, start with the browser.
What struck me most in the first half of 2026 was how much the tone changed in just a year. Last year focused more on us all coming to terms with the scale of AI-driven change. Today, we’re beginning to operationalize AI.
That is a meaningful difference.
Zero Trust used to be the “future architecture.” Now it is increasingly the baseline. AI used to be an overlay on enterprise applications. Now it is becoming an actor in enterprise workflows. And the browser, once seen mainly as an access tool, is becoming a core control surface.
There is something both exciting and slightly amusing about how fast this is moving. We are no longer just debating whether users should be on the network. We are starting to debate whether their AI agents should be allowed to talk to other AI agents, what they should be allowed to see and how much authority they should inherit. That is not a minor evolution.
I believe the next phase of security will be defined by how well enterprises apply Zero Trust principles to a world of autonomous software, connected business ecosystems and browser-native work. A year from now, I suspect many of today’s debates will already feel quaint.
And that is part of what makes this space so much fun. In security, the future has a habit of arriving before we finish naming it.