Zero Day Room
Live
Regulation & compliance

Teleport's Chris Webber on securing zero trust AI agents

Teleport's Chris Webber argues traditional zero trust principles are insufficient for AI agents, requiring new architectural runtimes and continuous

Teleport's Chris Webber argues traditional zero trust principles are insufficient for AI agents, requiring new...

Chris Webber, Vice President of Product Marketing at Teleport, states that foundational zero trust cybersecurity principles must evolve to secure autonomous AI agents. In an interview with HelpNetSecurity, Webber explained that agents operate with a speed and persistence that existing frameworks for human and machine identities cannot govern, necessitating a shift from detection to continuous enforcement.

Webber outlined three core zero trust principles that require adaptation for the agentic era. The first is "Verify explicitly." He notes that point-in-time authentication is inadequate for agents that can act anonymously or impersonate users. Verification must extend into the runtime environment itself, architecturally enforcing access and communication boundaries based on a unique, attestable identity for each agent.

The second principle is "Use least privileged access." While still valid for individuals, this concept must expand to govern collective behavior. "Actions that are individually authorized at a single agent level can be collectively destructive," Webber said. Security must now set decision boundaries around what groups or swarms of agents can accomplish together, not only what one agent can do alone.

The third principle is "Assume breach." This must be extended to account for agents potentially drifting from their programmed objectives. Such misalignment could result from malicious attacks like goal hijacking or from benign errors in generalization as context shifts over time. The security outcome required is the same regardless of the cause.

Teleport's architectural approach

Teleport's proposed solution involves two interconnected components: Trusted Runtimes and Identity Security. Every AI agent must operate within a Trusted Runtime, an environment that architecturally enforces strict boundaries for access, execution, and external communication. Crucially, each runtime starts with zero initial privileges, ensuring every connection and action must be explicitly authorized.

These runtimes are also ephemeral. They are designed to persist only as long as the agent's task requires and are fully destroyed upon task completion or when risk is identified. This design prevents runaway agents, eliminates standing privileges, and destroys any stored data, mitigating long-term exposure.

Continuous monitoring and response

The second component, Teleport Identity Security, provides the continuous monitoring needed to match agent behavior. It captures and assesses every interactive action an agent takes, evaluating them against the agent's declared objectives rather than in isolation. This allows the system to immediately flag sessions that result in real risk.

When risk is identified, the system can take automated action at machine speed. The appropriate response can include terminating the agent session and destroying the Trusted Runtime it operated within. This moves security from a model of anomaly detection after the fact to one of real-time intervention.

A necessary strategic shift

Webber argues that the entire security strategy must shift from detection-based models to continuous, agent-level enforcement. Traditional Identity Threat Detection and Response tools were built for a landscape of human users and service accounts with relatively static permissions. They watch for anomalies but are ill-equipped for scenarios where an agent acts with a human's credentials or spawns numerous clones to complete a task.

In this new paradigm, governance and execution must be inextricably linked. Systems must be designed from the ground up to uniquely identify agents, capture their objectives, and continuously enforce rules based on whether their actions remain consistent with those goals. The capability to intervene at machine speed, rather than routing alerts for human review, becomes essential for containing agentic risk.

Related coverage

More from Regulation & compliance