Frontier AI Security Pushes Zero Trust Into a New Era
Frontier AI Changes the Security Timeline
Frontier AI security is moving from theory to daily planning for enterprise teams. At Black Hat 2026, Deepen Desai of Zscaler explains why advanced models are changing the speed of attacks, vulnerability discovery and response. The discussion focuses on a simple reality. Defenders now need to prepare for attackers that can reason, chain steps and move at machine speed.
Desai says organizations should rethink software development, detection and response around this shift. AI can help teams find vulnerabilities earlier in the SDLC. It can also help create remediation guidance faster. That matters because attackers can use the same class of models to find zero days and connect weaknesses into real attack paths.
Zero Trust Becomes More Important
Frontier AI security also makes zero trust architecture more urgent. Desai warns that enterprises should assume an identity, device or agent may eventually be compromised. The goal is to limit the blast radius before that compromise spreads. For Zscaler, that means hiding exposed infrastructure, reducing external attack surfaces and applying segmentation across users, devices and agents.
The conversation also covers the rise of AI agents as a new attack surface. These systems may work alongside employees and access business services. That creates new governance and monitoring needs. Traditional security basics still matter, but they must be applied to faster and more autonomous environments.
AI Defense Needs Business Context
Zscaler is applying lessons from Project Glasswing and other frontier model testing to its own security work. Desai describes AI harnesses as force multipliers, but only when they receive the right context. Models need information about architecture, threat models and business priorities to produce useful findings.
The interview also highlights exposure management, AI asset discovery, red teaming and vulnerability prioritization. Desai argues that teams cannot patch everything. They need to focus on the risks that can be chained into meaningful attacks. That requires technical insight and business context working together.
Security Teams Need to Move Faster
The larger message is practical. Security teams should use AI to improve their own workflows before attackers gain more leverage. That includes better code review, faster patch generation, stronger segmentation and improved SOC response. Desai sees this as a chance to build more secure software, but only if organizations act quickly.
For cybersecurity leaders, the interview offers a clear path forward. Reduce what attackers can see. Contain what they can reach. Use AI to find and fix the highest-risk issues. Then build security programs that can respond at the same speed as the threats they face.
Transcript
Hey everyone, welcome back here to our Black Hat coverage. My next guest is Deepen Desai. Deepen is with Zscaler, and I've actually had Deepen on TechShrug TV before, and as I was telling him, I've been a fan of Zscaler pretty much since Jay Chaudhry started Zscaler.
I guess that'd be around 2005, I would bet. 2006, something like that. 2007, yes.
Yeah. Very close. At RSA, we used to do what they call the America's Growth Capital Conference, AGC.
Yep. And I always moderated the cloud security, this is when cloud first came out, cloud security panel. It would be Jay, and we'd have, I think his name is Evan, the CEO of Cloudflare.
Mm. What a great panel those were. Yeah.
Thinking that, but who knew then what we knew now? We didn't think of AI, I'll tell you that. Deepen, so first of all, well, let's talk a little bit about you.
Give people your role at Zscaler. Yeah. So, I'm EVP cybersecurity.
I'm responsible for our product security compliance. I lead our global threat intelligence team as well, and then, lately, we've been hard at building agentic SecOp solutions to help customers. So that's my role at Zscaler.
Excellent. Now, Zscaler needs no introduction to our audience, right? We've been covering Zscaler, and beyond our coverage, I think most people know Zscaler, right?
You've pioneered so many trends and new ways of doing security. But thinking of trends and new ways, we are in a new era with new trends and new ways, and a lot of people are unsteady about what are we doing? Yeah.
I've been coming to Black Hat for 23 years. I've never seen the kinetic energy that we're seeing here. Are you seeing this too?
You've been here, you know. What do you see? Absolutely.
I think the quick answer to your question, you're seeing a lot of energy because you're dealing with a lot of agents over there. Yeah, okay. That's what it is.
You already have agents on the floor. But no- Who's paying the electric bill? But go ahead.
No. Look, it's amazing. Almost 80% of the companies that I walk by, they're all doing either agentic SOCs or AI SOC, or security for AI.
So how do you protect those agents as adoption is growing in all the enterprises today? So, not surprising. And everyone else is also trying to have a play in that AI world.
You mentioned about trends. A couple of things that I am seeing, being at the front of our threat labs team and our participation in some of the programs like Project Glasswing and Daybreak. Frontier AI models, they're here, and they are the real deal.
The multi-step reasoning ability across a variety of cyber functions, it's a step function change from what we have seen before. So this is where it's no longer when, it's already here, and the organization needs to start thinking security differently. Starting with SDLC, so your dev cycle, your CI/CD pipeline.
Once a product is out there, what do you do? And even on the detection response perspective, because you're already seeing attacks where agents are bypassing sandbox. The HuggingFace example that's been in the news lately.
If you're not able to respond at machine speed when the attacker is attacking you at machine speed, it's game over. So, it's fundamentally changing the way we think about security. And of course, you also need to worry about the new attack surface, which is agents- The agents themselves ...
that are coexisting with your employees. So, not only is your existing attack surface, which is employees and IT infrastructure, under scrutiny from a risk perspective, but you also have a new attack surface that's rapidly expanding and that has a lot of unknowns for most organizations. So, a very interesting time.
We're in- To say the least. You know the old proverb, right? May you live in interesting times.
You mentioned there was a lot packed in there, and I want to jump in here. But I want to start with, let's start at the top and work our way down. You've got CXOs.
I don't care whether you're a CISO, CIO, CTO, chief data officer. There are so many different C-level stake. But how do they make sense of this?
Let's start with them. What should they be doing based upon what we're hearing and learning and seeing? Yeah.
So, in several conversations over the last three months, starting with CTO, for instance, they're in charge of their SDLC and releasing newer product software. Using Frontier AI as part of that SDLC life cycle is something that every global organization CTOs need to enforce in their engineering function. And the simple way of looking at it is you need to use AI to find vulnerabilities and fix them before the attackers use AI to find vulnerabilities and exploit them.
Agreed. It's as simple as that, because they are going to find zero days. I also like to say that zero days are a commodity now.
It's no longer- Agreed ... " There will be tons. Keeping up with CVE is no longer going to be sustainable.
So the SDLC itself, CTOs need to invest And upleveling it to use AI, frontier AI models, and every organization will have to build their harness. There are open source harness out there, but then you need to tweak it, tune it to your environment, your threat model, your architecture, your infrastructure information to make it find really high-risk issues. And then you should use AI to also come up with the remediation patches to fix it at machine speed.
So CTO, they need to focus on making your software infrastructure, all of those hardened to be ready so that before attackers start using AI, they're in a good shape. CISO, they need to leverage AI, again, from product security angle, from detection response angle, the whole SOC piece. You need to assume breach in today's world.
If there was a breach happening in your environment, what is the blast radius from one of the asset, one of the agent that were to get compromised? Yeah. This is where CISO have to prioritize zero trust everywhere strategy.
We've been talking about zero trust- Yeah ... for ages. Yeah.
It becomes even more critical now because the speed at which these things are able to move, you will not be able to react, which means architecture. Having that zero trust architecture will keep you in a very strong position to- Sure ... reduce that impact from these breaches.
Yeah. This is a common theme now. I probably did a half a dozen of these interviews just this morning.
Came up in at least half of them. Just because this AI may be a new thing doesn't mean we leave everything we learned 30 years- Yeah ... 35 years at the door.
Best practices, defense in depth, zero trust, good hygiene, cyber hygiene. Yep. Right.
They don't go out of style. Nope. And they don't become obsolete because everybody's talking about an agent today.
Yeah. As a matter of fact, as you said, it's even more important- Yeah ... that we do these things now.
Yep. Right? If you don't mind though, I want to pivot to Zscaler.
You see it coming. We all see it coming. People look to Zscaler.
You're a leader in this space. What are you doing? How are you respond...
Meaning the company. How are you responding? What can you offer our people watching this?
Yeah. So I'll start by saying, we were among the first few members of Project Glasswing. Yep.
The first action item for us was to make sure we use those powerful models to harden our own application and infrastructure, and there was a lot of learnings that came out of it. First couple months, we went through several iteration. We came up with our own harness.
Harness is a force multiplier. Just pointing a model to an application is not going to result in good findings unless you give it proper context. The way we have been helping the customers, as you rightly mentioned, the old learnings don't go away, the architecture piece.
So number one thing we're helping our customers with is reducing their external attack surface. So anything that is behind Zscaler, you can't attack what you can't see. And our goal is to make sure we make Zscaler infrastructure that is exposed harden against these type of attacks.
So helping customers implement that true zero trust architecture is number two item. So even if it's behind Zscaler, you need to assume that one of those identity, one of those agent, one of those machines will get compromised because employee may make a mistake, or agents are getting phished these days. If you have true zero trust architecture implemented, which is where we help with AI powered segmentation, the blast radius is contained to that identity, that device, that agent that made the mistake.
Third thing is you need to have a good view of your AI investments. Everyone is deploying agents and AI driven application. So we're helping on both red teaming and AI assets discovery phase.
So again, a solution that we're helping our customers with. Number four, vulnerability management. You can't patch everything, right?
Finding vulnerabilities was never an issue. With frontier AI, you're able to find things that are really high risk that can be chained together to breach your application. You need to combine that with business context and start patching some of those.
So that entire workflow, again, it's something that we help our customers using our exposure management solution. And then finally, look, best practices around, as you mentioned, good security hygiene, training your employees. Even if you don't have access to the powerful models like Mito's, you should start leveraging the models that exist out there.
Make your SDLC incorporate those models to start finding issues, to start generating patches, and make your engineers start running it. I think that's one of the biggest change I saw over the past three to four months of us using these powerful models where- Yeah ... there is no longer that debate between product security and engineering teams on, hey, is this a true positive, false positive, noise?
There's a working exploit for everything that gets reported, and engineers are on top of it. So, again, I would recommend going through these five areas, some where Zscaler can help and some where we're partnering with our customers. I love it.
Got to be honest, you're the first person I've spoken to who actually was on Glasswing and... Actually, that's not true. I spoke to people from Cloud Security Alliance and some of the people who were involved in that.
But I appreciate the insight because sometimes seeing how you guys did it yourselves for your own product is the most valuable thing. People can... A blueprint- Yep ...
to copy. And so that's fantastic. Look, first of all, appreciate you coming in.
I know we pulled you off of that crazy floor to come up here. All good. Yeah.
But, also I'm looking forward to seeing how this plays out. Yep. I think we are not necessarily going into troubled water, but as I said, I think before, choppy water, where we're going to cling to certain rafts, right?
We just need to get to the other side of this because I do think we're better off- Yeah ... when we can get through this and incorporate these things. It's going to make us have more secure software.
It's going to force us to do it, and that's something for those of us in security a long time, we've been calling for that. Yeah. So thank you for all you do.
Thank you for all Zscaler does. Thank you for having me on the call. Oh, it was a pleasure as always.
Hey, we are here. We've got a lot more Black Hat coming your way, so stay tuned, and we'll be back with more.