"A security architecture that grants no implicit trust to any user or device, verifying every access request regardless of whether it originates inside or outside the network perimeter."

Zero Trust is a cybersecurity model built on the principle that no user, device or application should be trusted by default, whether it sits inside or outside an organisation's network boundary, and that every access request must be explicitly verified before it is granted. This replaced the older 'perimeter' model of enterprise security, in which anything inside the network firewall was implicitly trusted and defence was concentrated at the network's edge, an approach that failed once attackers routinely gained an initial foothold inside networks through phishing or compromised credentials. Under Zero Trust, verification typically combines multiple factors, identity authentication, device health, location and behavioural context, and access is granted on a least-privilege basis for the specific resource requested rather than for the network as a whole. This limits the damage an attacker can do even after breaching one credential or device, since lateral movement across the network requires passing further verification at each step. Zero Trust's structural limitation, increasingly discussed in 2026, is that it verifies identity and credentials but cannot by design distinguish a legitimate user from an autonomous malicious AI agent that has obtained genuinely valid credentials (through phishing, compromise or misconfiguration) and behaves in ways statistically consistent with an authorised user. Such an agent satisfies every verification check because there is nothing wrong with its credentials; it occupies the insider-threat vector that credential-based verification was never designed to reach. The proposed response, often termed 'Zero Trust 2.0,' extends the model to non-human identities through per-agent identity, short-lived and narrowly scoped credentials, continuous runtime authorisation and behavioural monitoring, rather than abandoning the Zero Trust principle altogether.

A high-value, currently examinable GS3 cybersecurity concept; useful for distinguishing implementation failures from assumption failures in security architecture, and for connecting AI risk to established cyber-defence frameworks.

  • 1 Zero Trust: no implicit trust for any user/device, inside or outside the network; every access request is explicitly verified.
  • 2 Replaced the older 'perimeter' security model, where anything inside the firewall was trusted by default.
  • 3 Grants access on a least-privilege, per-resource basis rather than trusting an entire network session.
  • 4 Structural weakness: cannot distinguish a legitimate user from an autonomous AI agent using genuinely valid, stolen or misconfigured credentials.
  • 5 Such an agent occupies the 'insider threat' vector, since verification succeeds despite the actor being illegitimate.
  • 6 Proposed extension, 'Zero Trust 2.0,' adds per-agent identity, short-lived scoped credentials and continuous behavioural monitoring for non-human/AI identities.
  • 7 India's CERT-In handled about 29.44 lakh cyber incidents in 2025, up roughly 44 per cent on 2024, underscoring the stakes of the debate.
M.K. Narayanan's 2026 essay argued that an autonomous malicious AI agent operating with legitimate, stolen credentials defeats Zero Trust not by breaking its verification but by satisfying it, since the model was never designed to catch a credentialed insider.
GS Paper 3
Economy, Environment, S&T, Security
← All Terms
A new key term every day Key Term of the Day at 1pm, plus daily current affairs and free PDFs
Join Channel
BharatNotes