Zscaler Blog

Get the latest Zscaler blog updates in your inbox

Products & Solutions

Zscaler and OpenAI: Bringing Frontier AI-Powered Security to the Enterprise

image

The security industry has been adapting to AI faster than any previous technology shift, and Zscaler has been at the forefront of that effort. But the nature of the challenge keeps evolving. Attackers are deploying AI to reason over complex environments and find paths that traditional tooling doesn't see. Meeting that requires more than faster detection or broader coverage. It requires security that can reason the same way: understanding how an enterprise can be compromised, not just flagging that something looks wrong.

That's why our partnership with OpenAI matters. Through OpenAI’s Daybreak Defense Network, Zscaler built two new capabilities using OpenAI GPT cyber models, and today, I'm excited to showcase what enterprise security can do and what it should look like in an AI-first world.

We presented both of these at OpenAI Intelligence at Work: Cyber on September 3, and you can learn more about them below.

Innovation Showcase 1: Endpoint AI Security — Attack Chain Analysis

AI agents, assistants, and AI coding IDEs are now part of the standard developer workflow. They're powerful. They're also a new and largely unmapped attack surface, one that now extends to local and web MCP servers, locally-run models, and AI running directly inside the browser. Our new Endpoint AI Security Attack Chain Analysis capability, powered by OpenAI GPT cyber models, changes how organizations understand device risk. Instead of surfacing a flat list of misconfigurations and CVEs, it reads the full state of an endpoint — AI agents, coding assistants, IDE and browser extensions, installed software, packages, and system configuration — and reasons over all of it to construct a realistic attack chain.

What does that mean in practice? It means the output isn't, "you have a vulnerable extension." It's: here is the path from an initial lure, to code execution under this user's account, to credential and source code theft, to persistence, to re-entry, and here is what you need to close first.

Findings are backed by evidence, and all steps are labelled, confirmed on the host, inferred from state, or flagged for verification. The result is a prioritized remediation roadmap that gives security teams something unique: a defender's view of their own devices that resembles potential paths of an attacker.

This capability runs as an endpoint agent, either independently or as a module within the current Zscaler client running on more than 70M devices, fully controlled and policy-scoped. Zscaler controls the policy-scoped endpoint context submitted for analysis. It simply does something that has historically been very hard to do at scale: performs authorized analysis of potential attack paths so your defenders don't have to.

Innovation Showcase 2: Identity Risk Analysis in the Zscaler AI Access Graph

The other major attack surface that's grown faster than security teams can manually track is identity, specifically, non-human identities. Service accounts, AI copilots, and agentic workloads now outnumber human users in many enterprise environments. Their permissions sprawl across cloud, SaaS, and on-prem systems in ways that no human team can reason over at speed.

Our second integration embeds OpenAI GPT cyber models directly into the AI Access Graph to perform Identity-Permission Risk Analysis at enterprise scale.

The AI Access Graph already maps identities across the enterprise (human, service account, and AI agent) to data objects throughout the environment and model endpoints they can reach across Azure, AWS, OCI, and GCP. What OpenAI GPT cyber models add is the reasoning layer: they trace the paths through that graph, identify risky combinations — overprivileged access, toxic permission pairings, excessive inherited scope — and rank them not by a generic severity score but by business impact, blast radius, confidentiality, integrity, and availability of what's actually reachable.

Critically, the graph distinguishes agent and bot behavior from human behavior. That distinction matters for agentic identity governance: you need to know not just what access exists, but who or what is using it, and whether that behavior matches the role and peer baselines you'd expect.

Remediation is deliberately decoupled from the model's reasoning. All remediation actions run through a human-approval workflow. The model surfaces the risk and explains it; humans decide what to do. That's the right design.

What This Means for Our Partnership with OpenAI

Both of these capabilities required a model that could reason about how systems get compromised; not abstractly, but concretely and at the specific context of a customer's environment. Standard models weren't up to that task. OpenAI GPT cyber models are purpose-built for this kind of security reasoning, and it's the foundation that makes both of these innovations possible.

Our partnership with OpenAI is about building the AI security infrastructure that enterprises actually need: deep, specific, evidence-grounded, and human-reviewed before anything consequential happens. That's what we’ve showcased on September 3.

The pace of change in this space isn't slowing down. Neither are we.

FAQs

The Zscaler and OpenAI partnership integrates purpose-built OpenAI GPT cyber models into Zscaler's security architecture. This enables security systems to reason like human defenders. Instead of just flagging isolated, suspicious events, the system analyzes entire IT environments to reconstruct complex, multi-stage attack paths and evaluate their business impact in real time.

Powered by OpenAI GPT cyber models, this capability evaluates an endpoint's entire state—including local AI agents, browser extensions, packages, and system configurations. Rather than presenting a flat list of CVEs, it constructs a realistic attack chain from initial lure to code execution. This provides defenders with a prioritized remediation roadmap.

The Zscaler AI Access Graph maps human, service account, and AI agent identities to data objects and cloud endpoints. By integrating OpenAI GPT cyber models, it traces access paths, flags overprivileged or toxic permission combinations, and ranks these risks by business impact, blast radius, and resource confidentiality across multi-cloud environments.

Local AI agents, coding assistants, and MCP servers introduce a completely unmapped attack surface inside local environments and browsers. Traditional security tools fail to see how minor system misconfigurations, browser extensions, and active coding tools can be chained together by advanced attackers to execute malicious code and compromise enterprise source code.

OpenAI GPT cyber models add a critical reasoning layer to Zscaler's AI Access Graph. They automatically analyze complex permissions across AWS, Azure, OCI, and GCP. The models distinguish human actions from bot or agentic behaviors, identifying toxic pairings and excessive scopes, and ranking them based on potential business disruption and blast radius.

While OpenAI GPT cyber models provide the advanced reasoning necessary to detect and rank critical identity risks, Zscaler deliberately decouples remediation from model reasoning. All security remediation actions require human-in-the-loop approval. This ensures that enterprise administrators retain full oversight and control over high-impact network and access configuration changes.

form submtited
Thank you for reading

Was this post useful?

Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Any third-party websites or resources linked in this blog post are provided for convenience only, and Zscaler is not responsible for their content or practices. All content is subject to change without notice. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs.

Get the latest Zscaler blog updates in your inbox

By submitting the form, you are agreeing to our privacy policy.