Zero Networks puts guardrails on AI agents at the network layer

Zero Networks puts guardrails on AI agents at the network layer

Most AI security tools focus on prompts and model outputs. Zero Networks does something different: they put the guardrails at the network layer, where a compromised agent hits a wall before it can move laterally.

Least Agency gets real

On Monday, Zero Networks launched “Least Agency Enforcement.” It runs on their identity-based micro-segmentation platform. The name comes from OWASP’s Least Agency principle for agentic AI — the idea that an agent’s autonomy, tool access, and decision-making authority need explicit limits.

The distinction matters. Application-layer controls govern what an agent was asked to do. Network-layer enforcement governs what the agent can actually reach when those controls fail.

The gap nobody talks about

Zero Networks found that nearly 80% of enterprises have already deployed internal AI agents. Roughly two-thirds have no governance policies for them. That gap is where prompt injection, privilege abuse, and compromised agents do damage.

OWASP’s Agentic Applications Top 10 recently spelled this out. The Least Agency principle says organizations should explicitly limit what an agent can touch, what tools it can invoke, and when human approval is required.

How it works

Least Agency Enforcement maps what an agent identity should be allowed to touch, then enforces it at the host firewall. Everything outside that set is denied by default. The system relies on:

  • Identity-based microsegmentation to define authorized communication paths
  • Automated policy generation so rules don’t need manual tuning
  • Just-in-time MFA on sensitive protocols — RDP, SMB, WinRM — so a stolen agent credential can’t quietly move sideways

“We’re doing for AI agents what least privilege did for people, except it has to be automatic,” said Benny Lakunishok, Zero Networks CEO. “If an agent gets fooled or misused, it should hit a wall almost immediately, not wander around the network looking for something valuable.”

Not another IAM or PAM tool

Zero Networks positions this as complementary to identity providers and privileged access management. IAM and PAM govern whether an AI gets access. Once a session starts, those tools generally don’t control where the agent moves across the network.

Least Agency Enforcement works on both the identity and network layers. It restricts communication to authorized agents, with sensitive protocols routed through MFA as a backup against compromise.

Why this matters in Africa

The agent governance gap isn’t unique to Silicon Valley. South African banks, Kenyan fintechs, and Nigerian telcos are deploying AI agents for fraud detection, customer onboarding, and network optimization. The same lateral-movement risk applies. An agent with valid credentials that gets tricked into calling an internal API it shouldn’t touch becomes an insider threat — one that moves at machine speed.

Network-layer enforcement changes the math. The agent still has its credentials. The network just says no.

Where eHawu fits

This is the problem eHawu’s network-layer architecture solves. Our VPN gateway enforces least-privilege connectivity at the packet level — identity-aware, zero-trust, and indifferent to whether the endpoint is a human, a server, or an AI agent. When an agent tries to reach a resource outside its policy, the connection dies at the gateway. No lateral movement, no credential reuse, no wandering.

AI agents will keep getting more capable. The networks they run on need to stay paranoid.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *