New capability enforces OWASP’s emerging AI security guidance into an enforceable policy to prevent AI agents from exceeding their intended autonomy and authority
Zero Networks, the leading provider of Zero Trust security solutions, announced Least Agency Enforcement, a new capability that applies the Open Worldwide Application Security Project’s (OWASP) principle of Least Agency to help organizations safely deploy AI agents.
Also Read: CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight
Zero Networks’ 2026 Lateral Movement Exposure Report research reveals that nearly 80% of enterprises have already deployed internal AI agents, yet two-thirds lack governance policies for them — creating rapidly expanding, unmanaged attack surfaces. As organizations grant AI agents the ability to access enterprise systems, invoke privileged tools, and make decisions with minimal human oversight, they must also define and enforce appropriate levels of autonomy. The OWASP Agentic Applications Top 10 Project’s Least Agency principle recommends constraining an agent’s autonomy, tool access, and decision-making authority to reduce the impact of prompt injection, privilege abuse, and compromised AI agents.
Using identity-based microsegmentation, policy automation, and just-in-time MFA for privileged access, Zero Networks’ Least Agency Enforcement ensures that AI agents communicate only with explicitly authorized systems, only access approved resources, and require human approval before performing sensitive administrative actions. Unlike governance frameworks that document policy, Zero Networks enforces Least Agency across cloud, on-premises, Kubernetes, IoT/OT, and hybrid environments.
“Least privilege works because it is simple: give people access to what they need, nothing more. We’re doing the same thing for AI agents, except now it must be automatic, because nobody has time to babysit a thousand agents by hand,” said Benny Lakunishok, CEO and Co-founder of Zero Networks. “If an agent gets fooled or misused, it should hit a wall almost immediately, not wander around the network looking for something valuable. That’s the bet we’re making: less freedom for the agent now, which beats explaining a breach later.”
With Zero Networks’ Least Agency Enforcement, organizations can:
- Limit AI agents to only the systems and services required for their assigned task
- Prevent lateral movement between applications, infrastructure, and administrative systems
- Require Just-in-Time MFA before AI agents access privileged ports or sensitive infrastructure
- Automatically generate and enforce least-privilege communication policies without manual rule creation
- Contain compromised, manipulated, or over-permissioned AI agents before they can impact critical business systems
Least Agency Enforcement builds upon Zero Networks’ AI Security platform, including AI Agent Control, AI Segmentation, AI SaaS Control, and protection for enterprise LLM deployments. Together, these capabilities provide organizations with an enforcement layer that allows AI innovation to proceed without sacrificing security or cyber resilience.
Catch more CIO Insights: How Are CIOs Aligning Technology with Workforce Agility?
[To share your insights with us, please write to psen@itechseries.com ]


