Microsoft announced Zero Trust for AI (ZT4AI) on March 19, 2026, extending its zero trust framework to cover the full AI lifecycle. The release includes a dedicated AI pillar in the Zero Trust Workshop, updated Data and Networking pillars in the Zero Trust Assessment tool, a new reference architecture for AI security, and practical implementation patterns for securing AI at enterprise scale.

The expanded Zero Trust Workshop now covers 700 security controls across 116 logical groups and 33 functional swim lanes. The new AI pillar evaluates how organizations secure AI access and agent identities, protect sensitive data used by AI systems, monitor AI usage across the enterprise, and govern AI responsibly.

Mike Adams, Corporate Vice President of Customer Experience Engineering at Microsoft, characterized the driving question from security leaders: “We’re adopting AI fast, how do we make sure our security keeps pace?”

A Zero Trust Assessment for AI pillar is currently in development and will be available in summer 2026, extending automated evaluation to AI-specific scenarios and controls. This tool will allow organizations to benchmark their AI security posture against Microsoft’s control framework.

For defenders deploying AI agents and copilots, the ZT4AI framework provides a structured approach to questions that many security teams are currently addressing ad hoc: which identities should AI agents operate under, what data boundaries apply to model training, and how continuous monitoring extends to automated agent behavior. The framework applies three established principles to AI workloads: verify explicitly, apply least privilege, and assume breach.