IRM Consulting & Advisory
AI & Machine Learning Security

AI-Enhanced Zero Trust

AI can make zero trust smarter, but only after the basics. A vCISO's view of identity risk scoring, anomaly detection, AI agents and a 90-day rollout.

Where AI strengthens zero trust for a growing SaaS company, where it is hype, and what to do first

AI-enhanced zero trust is a zero trust architecture in which machine learning feeds the access decision: it scores each login, session or API call against learned behavior, device posture and threat signals, then steps up, limits or blocks access in real time. It sharpens "never trust, always verify". It does not replace identity basics.

A CTO called me on a Thursday afternoon. Her 70-person SaaS company had just lost a week to a security questionnaire from an enterprise prospect, and question 41 asked, "Describe your zero trust architecture and how you use AI for adaptive access." Two vendors had already pitched her "AI-powered zero trust" platforms. Both demos looked impressive. Neither could tell her what to switch on first.

Every few weeks we get some version of that call. After 25+ years in security and a long run of identity reviews across SaaS, healthcare and financial services, my answer is always the same: AI makes a good zero trust program better and makes a weak one more expensive. This post separates the two.

What does zero trust actually require before AI enters the picture?

Zero trust is not a product. NIST SP 800-207 defines it as a set of tenets: no implicit trust based on network location, access granted per session, decisions driven by dynamic policy that weighs identity, device state and behavioral attributes, and continuous monitoring of every asset. The CISA Zero Trust Maturity Model v2.0 organizes the same idea into five pillars (identity, devices, networks, applications and workloads, data) with four maturity stages from Traditional to Optimal.

Notice what sits at the center of NIST's design: a policy engine running a "trust algorithm". That is exactly where AI plugs in. But a trust algorithm can only reason about identities you have inventoried, devices you can see and logs you actually collect.

The Canadian Centre for Cyber Security puts the starting line in plain language: enforce strong MFA (it recommends aiming for Level of Assurance 3); base access on user and device information rather than location; use just-in-time, just-enough access; and use dedicated workstations for admin work. None of that needs machine learning.

The threat data explains why identity comes first. In the 2026 Verizon DBIR, credential abuse appeared at some point in 39% of breaches in the dataset, even though vulnerability exploitation overtook it as the top initial access vector. Breaches with third-party involvement rose 60% to 48% of the total. Stolen logins and over-trusted partners are an identity problem before they are an AI problem.

Where does AI genuinely help zero trust?

Across our assessments, three uses of AI consistently earn their place in a 30 to 200 person SaaS company.

1. Identity risk scoring at sign-in and during the session

This is the most mature use. The identity provider scores each sign-in on signals like impossible travel, a new device, an anonymizing network or a leaked credential, then triggers step-up MFA or blocks the session. The value is not the score itself. It is that a risky admin sign-in at 3 a.m. gets challenged instead of waved through because the password was correct. Most mid-market identity platforms include some form of this in their higher license tiers, so check what you already own before you buy anything new.

2. Anomaly detection on privileged and production access

Behavioral baselines work well on a small, high-value population: admins, engineers with production access, and service accounts. A support agent who suddenly exports 40,000 customer records, or a CI/CD token calling an API it has never touched, is the kind of deviation NIST describes as "measured deviations from observed usage patterns". The model flags it; a human decides.

3. Policy tuning and access reviews

The quietest win. AI-assisted analysis of who actually uses which permissions makes quarterly access reviews faster and turns "remove standing privilege" from a slogan into a list of specific grants to revoke. It also supports the continuous access monitoring evidence that SOC 2 and ISO 27001 auditors ask for.

There is also a measurable payoff in incident response. IBM's 2026 Cost of a Data Breach report found that organizations using security AI and automation saved an average of $1.93 million per breach, against a record global average breach cost of $4.99 million.

Where is "AI-powered zero trust" mostly vendor hype?

This is the table I draw on the whiteboard when a founder shows me a vendor deck. Vendors will dispute the right-hand column. I stand by it.

Vendor claim

What it usually means

Our verdict for a 30 to 200 person SaaS

"AI replaces your access policies"

A model suggests rules; someone still approves them

Hype. You need written policy first, or the model learns your bad habits

"Autonomous response blocks attacks in real time"

Automated session revocation on high-confidence signals

Useful for clear cases, risky for everything else. Keep a human on account lockouts for executives and customers

"Behavioral AI across every user from day one"

Baselines that need weeks of clean data

Overkill for most staff. Start with admins and production access only

"Zero trust in a box"

One platform covering one or two CISA pillars

Hype. No single product covers identity, devices, networks, workloads and data

"Risk-based sign-in with AI"

Identity provider risk scoring plus step-up MFA

Real value. Often already in your license

A useful test: ask the vendor which NIST SP 800-207 component their product implements (policy engine, policy administrator or policy enforcement point) and which CISA pillar and maturity stage it moves you to. Vague answers tell you what you need to know.

NIST SP 1800-35, finalized in June 2025, demonstrated 19 example zero trust implementations built with 24 technology collaborators. If the reference build needed that many components, no single AI product is your whole architecture.

How do you extend zero trust to AI agents and non-human identities?

Here is the part most zero trust programs miss. Your SaaS company probably now has more non-human identities than employees: API keys, OAuth grants, service accounts, CI/CD tokens and, increasingly, AI agents that read email, query databases and open tickets on someone's behalf.

An AI agent is an identity with delegated authority. Treat it exactly that way. The OWASP Top 10 for Agentic Applications 2026 lists "identity and privilege abuse" (ASI03) as a top risk: agents exploiting delegated trust, inherited credentials or role chains. NIST's NCCoE published a concept paper on software and AI agent identity and authorization in February 2026, which tells you the standards are still forming. Do not wait for them.

Apply the same tenets you apply to people:

  • Give every agent its own identity. No shared API keys, no agent running as a human's account.

  • Scope permissions to the task, with short-lived tokens instead of long-lived secrets.

  • Require human approval for high-impact actions such as payments, data exports, permission changes and customer communications.

  • Log every tool call the agent makes, and feed those logs into the same anomaly detection you use for admins.

  • Inventory AI tools staff connect on their own, the shadow AI your policies never approved. In IBM's 2026 data, 92% of organizations with AI-related breaches lacked proper AI access controls, and fewer than half were actively securing non-human identities.

We cover agent controls in more depth in how to secure AI agents, and the governance side sits within our AI governance practice.

When do you NOT need AI-enhanced zero trust yet?

Honesty saves budget here. Skip the AI layer for now if any of these are true:

  • You cannot list every admin account, service account and third-party integration with production access.

  • MFA is not enforced on 100% of accounts, including break-glass and vendor accounts.

  • Logs from your identity provider and cloud console are not retained or reviewed.

  • You are a team of 10 to 20 on one cloud provider, with no customer-facing API and few contractors. Conditional access in your existing identity provider covers you, and a behavioral model has too little history to learn from.

What AI-enhanced zero trust does not stop: a fully legitimate insider doing something harmful within their normal pattern, a compromised vendor operating inside its granted scope, or an unpatched public-facing system. Those need least privilege, vendor risk management and patching. Revisit the AI layer when you add an external API surface, contractors with production access, or a SOC 2 or ISO 27001 commitment that requires evidence of continuous access monitoring.

What is a realistic 90-day order of operations?

Sequence matters more than tooling. This is the order I use as a virtual CISO:

Days 1 to 30: see everything. Inventory human and non-human identities, including AI agents and OAuth grants. Enforce phishing-resistant MFA on admins first, then everyone. Turn on and centralize identity provider and cloud audit logs. Run a CIS Controls gap assessment; CIS Controls 5 and 6 cover account and access control management.

Days 31 to 60: shrink trust. Remove standing admin rights in favor of just-in-time elevation. Rotate long-lived keys and replace shared secrets. Switch on identity risk scoring and step-up MFA in the license you already pay for. Write a one-page access policy that a model can later enforce.

Days 61 to 90: add intelligence where it pays. Apply anomaly detection to admins, production access and service accounts only. Put AI agents behind scoped identities with approval gates. Track three numbers: risky sign-ins challenged, standing privileges removed, and time to revoke a compromised identity. Map progress to the CISA maturity stages for your board and for the next security questionnaire.

Short version: inventory, then least privilege, then AI.

Frequently asked questions

Is AI required for zero trust?

No. NIST SP 800-207 and the CISA maturity model describe zero trust without requiring machine learning. AI improves the quality and speed of access decisions once identity, device and logging basics are in place.

What is the first AI capability a SaaS SMB should enable?

Identity risk scoring with step-up MFA at sign-in. It is usually included in your identity provider's higher tiers, needs little tuning, and protects against the credential abuse that still shows up in nearly four in ten breaches.

Do AI agents need their own identities?

Yes. Each agent should have a unique identity, task-scoped permissions, short-lived credentials and full logging. Agents that borrow a human's account break attribution and make least privilege impossible to enforce.

How long does an AI-enhanced zero trust rollout take?

For a 30 to 200 person SaaS company, the foundation plus initial AI controls fits in about 90 days. Reaching CISA "Advanced" across all five pillars is a multi-quarter program.

Where should you start this week?

Back to that CTO. She did not buy either platform. In 90 days her team inventoried every identity, removed standing admin access, switched on risk-based sign-in she was already licensed for, and gave her two AI agents their own scoped identities. Question 41 now has a credible answer.

If you want an outside view of where your zero trust program stands, our vCISO cost guide and pricing page show what an engagement looks like, and you can book a consultation to walk through your identity inventory with me.

Keep Reading

Related Articles

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.