Skip to content

Agentic AI and Zero Trust: Identity, then connectivity ​

AI & Cybersecurity · May 2026 · 8 min read

A malicious AI agent infiltrates through a chain of compromised credentials. It moves at machine speed, reaches internal services, exfiltrates data, and executes destructive actions autonomously. What architecture stops that cascade before it becomes a breach?

AI has changed the rules ​

Agentic AI doesn't just answer questions: it acts. It researches, executes tools, moves data between systems, and makes decisions with increasing autonomy. This creates a fundamental problem: the infrastructure connecting these agents was designed for humans, not for machines operating at millisecond speed.

FactorBefore (Conversational AI)Now (Agentic AI)
SpeedResponds to human requestsAutonomous actions at machine speed
ScopeOne model, one APIMultiple tools, services, zones and domains
Attack surfacePrompt injectionLateral movement, exfiltration, tool abuse
Response timeMinutes/hours to containSeconds before damage is irreversible

The problem isn't AI, it's the infrastructure

AI reduces the cost of discovering, weaponizing and verifying attack paths. If a service is reachable, AI shortens the path from exposure to impact. Reachability can no longer be the starting point: it must be the result of identity and policy.

The failure of "connect first" ​

In traditional architecture, the sequence is: connect first, verify later. The agent has a reachable path before being authorized. The firewall, VPN, or gateway tries to filter traffic once the connection already exists.

This creates three structural gaps:

1. Reused credentials = immediate access ​

An attacker steals a service account or CI/CD credentials. They deploy a container as a rogue agent and attempt to join the internal network. In a "connect first" model, reused credentials create reachability before identity verification catches up.

2. Reconnaissance at machine speed ​

The rogue agent scans thousands of nodes, performs hundreds of directory queries, and attempts unauthorized communications. In a model where services are discoverable by default, the attacker maps the entire topology before anyone can react.

3. Unrestricted lateral movement ​

Once inside, the agent uses reachable paths to expand its scope: crosses zones, accesses admin tools, invokes internal APIs, and exports data. If the network allows connectivity by default, every service is an escalation opportunity.

The principle: Identity before connectivity ​

The alternative is to invert the sequence: authenticate and authorize before connectivity exists. Without a valid cryptographic identity and a matching policy, there is no service path, no packet, no connection.

Traditional modelIdentity-first model
Connect → verify → filterAuthenticate → authorize → connect
Services exposed by defaultServices dark by default
Security is a filter on the networkIdentity is the network
A token grants access and downstream checks contain itNo valid identity = no path

This means identity isn't "bolted on" around the network: it's embedded in the communication fabric itself. The network doesn't decide first and policy second. Identity and policy decide whether a connection can exist at all.

Three key outcomes ​

This architecture produces three simultaneous benefits for regulated organizations:

1. Improved security ​

Infrastructure, tools, AI models and services are not reachable unless identity and policy explicitly create the path. An agent can run, but unless it's enrolled in the identity, policy, and audit framework, it cannot reach internal services or invoke governed tools.

2. Faster innovation ​

Teams don't depend on repeated infrastructure changes (routing, NAT, firewalls, VLANs, load balancers, proxies, security groups) for each new agent, model, or service. Connectivity is resolved through identity policy, eliminating the "connectivity tax" that slows AI adoption.

3. Simpler deployment ​

The solution runs across existing networks, clouds, Kubernetes containers, edge sites, and third-party environments. No need to rebuild the underlying infrastructure. Agentic AI won't wait for every firewall, NAT, and VLAN to be redesigned.


How we implement this at BlueUP ​

At BlueUP, this model isn't theory: it's the foundation of our platform. We use OpenZiti (the open-source connectivity substrate developed by NetFoundry, our technology partner) as the Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity.Read more → Zero Trust reachability layer, integrated with our governance and compliance stack.

LayerFunctionTechnology
ReachabilityIdentity-first connectivity, dark servicesOpenZiti / NetFoundry
ContainmentPer-agent sandbox, deny-by-defaultgVisor, OpenZiti LANs, eBPF
GovernanceTool authorization, human approval, auditMCP Gateway, LLM Gateway
ComplianceRegulatory policies, continuous monitoringBlueUPALM, ComplianceView, OPA

Want the full technical analysis?

This article is an executive summary. Download our whitepaper with the 5 technical controls, detailed attack scenarios, and the complete identity-first architecture framework for agentic AI.

→ Download whitepaper: Agentic AI and network functions


→ Back to blog