Zscaler unveiled what it calls the industry’s first complete zero trust platform for agentic AI on June 9 at Zenith Live 2026 in Las Vegas, shipping three new capabilities that extend identity-aware access controls to the communication paths between autonomous AI agents. The products, AI Broker, Endpoint AI Security, and AI Access Graph, collectively address a security gap that emerged as enterprises moved from pilot AI deployments to production-scale agentic systems communicating over Model Context Protocol (MCP) and agent-to-agent (A2A) frameworks.
The timing matters. Enterprises running autonomous agents that call external APIs, access internal databases, and coordinate with other agents over MCP have effectively created a new class of machine identity traffic that existing network and endpoint security controls were not designed to inspect or govern. Zscaler’s response applies the same zero trust brokered-access model it uses for human identity traffic to this new category of machine-to-machine communication.
AI Broker for Agent Communications
AI Broker sits between autonomous AI agents and the resources they request, enforcing access policies on MCP and A2A communications in real time. The product treats every agent action as an access request that must be authenticated, authorized, and inspected before the connection is established. This mirrors the user-to-application model that Zscaler’s Zero Trust Exchange already enforces for human users, but extends it to machine identities operating at machine speed.
The design philosophy is explicit about one assumption: an AI agent should never inherit the broad access permissions of the user or service account that launched it. AI Broker allows organizations to define granular policies that scope each agent’s access based on its declared function, the specific resources it needs, and the sensitivity classification of the data it will process. An agent designed to summarize support tickets should not have the same access privileges as an agent authorized to modify financial records, regardless of which user account spawned both.
Endpoint AI Security
The second product targets threats that live inside browsers, extensions, and local AI tools on endpoint devices. Traditional endpoint detection and response platforms were built to identify process-level and file-system-level malicious behavior. They are structurally limited when threats operate within the browser runtime, manipulate AI-powered extensions, or exploit local LLM instances that run inference on device.
Endpoint AI Security monitors AI tool activity on managed devices, detects prompt injection attempts against local AI applications, identifies unauthorized AI extensions, and enforces data loss prevention policies on content flowing into and out of local AI tools. The product addresses the reality that employees are installing AI browser extensions and local inference tools faster than IT departments can evaluate and approve them.
AI Access Graph
The third product is a mapping layer that provides continuous visibility into the relationships between data stores, identity principals, and AI agents across an organization. Built on technology from Zscaler’s acquisition of Symmetry Systems, AI Access Graph creates a real-time topology of who and what can access which data through which paths, including paths created by AI agent configurations that may not appear in traditional access control lists or identity governance tools.
The product addresses a specific operational gap. Many organizations have deployed AI agents that access data stores using service accounts or API keys provisioned months ago during initial development. AI Access Graph discovers these relationships, maps effective permissions, and identifies cases where an agent’s actual access exceeds its documented or intended scope.
Broader SASE Expansion
The following day, Zscaler announced additional Zero Trust SASE innovations including ZAgent, an agentic framework for automating SASE administration itself, a Zero Trust Browser Extension for unmanaged and BYOD devices, and Zero Trust B2B Connectivity for partner access scenarios. The multi-day announcement cadence positions the company as building a comprehensive security platform that covers human users, managed devices, unmanaged devices, autonomous AI agents, and cloud workloads under a single zero trust policy engine.
Market Context and Competitive Dynamics
Zscaler’s announcement follows CrowdStrike’s AgentWorks launch and Palo Alto Networks’ integration of Protect AI, forming a pattern where every major security platform vendor is racing to claim the AI agent security layer. The differentiator Zscaler is emphasizing is its position as a network-level broker. Rather than securing agents at the endpoint or within a specific SIEM platform, Zscaler intercepts agent communications at the network layer where all traffic must transit, regardless of which AI framework, model provider, or orchestration tool generated the request.
For enterprise security teams, the practical takeaway is that AI agent governance is no longer an emerging concern to track. It is a current operational requirement with production tooling available from multiple vendors. Organizations deploying autonomous agents without explicit access policies, communication inspection, and behavioral monitoring are accepting risk that quantifiable controls now exist to mitigate.
Source: Zscaler Product Blog.