Blog Zscaler

Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception

News & Announcements

Zscaler Joins the Blueprint Alliance to Help Secure the Agentic Enterprise

image
MASON COFFMAN
septembre 22, 2026 - 7 min read

The tectonic shift toward enterprise AI adoption is happening, and it’s happening fast. According to the Zscaler ThreatLabz 2026 AI Security Report, enterprise AI and ML transactions skyrocketed by 83% year-over-year. AI is no longer a nice-to-have tool. It is a persistent operating layer.

As part of broader enterprise adoption trends, AI agents are moving quickly from experimentation to real-world deployments. Unlike traditional software, agents can reason, execute multi-step plans, call APIs, and take action across technology environments. That potential creates significant opportunity, but it also introduces a new governance challenge for organizations.

The harsh reality is that cybersecurity teams are simply underprepared. Earlier this year, the Zscaler ThreatLabz red team conducted realistic adversarial testing on enterprise AI deployments. Every single enterprise AI system that was tested failed at least once under realistic adversarial pressure, with those failures surfacing quickly.

Introducing the Blueprint Alliance

Customers need proactive guidance on how to adapt their technology stacks for the agentic era. But securing AI agents cannot be addressed by a single control point or a single vendor. It requires connected capabilities across identity, data, applications, cloud infrastructure, networks, endpoints, and security operations.

That is why Zscaler is proud to join the Blueprint Alliance as a founding member.

The Blueprint Alliance is a cross-industry coalition advancing an open, multi-vendor reference architecture to secure and govern AI agents at enterprise scale. It helps organizations implement a zero-trust, agentic control plane so they can continue to scale their AI deployments.

AI agent security is an ecosystem challenge

AI agents work across the enterprise stack. They may inherit human or agent identities and permissions, interact with cloud infrastructure, retrieve sensitive data, connect to SaaS apps and APIs, or operate through endpoints and networks. They can also act asynchronously, potentially continuing work after the human who initiated a task has logged off. 

This changes what customers need from their security and technology providers. Organizations need an integrated approach that can help them:

  • Treat every agent as a first-class identity
  • Scope access to the task rather than granting standing access
  • Keep delegation traceable
  • Monitor runtime behavior continuously
  • Enable containment that’s instant and reversible
  • Ensure governance adapts at the speed AI moves

Guided by these principles, the Blueprint Alliance aligned on a common framework for helping organizations answer four foundational questions:

  1. Where are my agents?
  2. What can they do?
  3. What are they doing?
  4. How do I respond? 

Let’s take a closer look at these foundational questions, including a sample of specific activities and capabilities security teams should consider to address each. 

1. Where are my agents? (discovery and visibility) 

As the adage goes, you can’t protect what you can’t see. The first step toward securing agents and other AI tools or apps is to identify and assess every AI-related interaction traversing the corporate infrastructure—whether sanctioned or unapproved.   

You must continuously scan and discover all AI integrations, APIs, and automated agents running in both development and production. This includes the ability to map out all connected dependencies such as LLMs, MCP servers, software libraries, data flows, and how the agents are imported into the enterprise environment. 

Once discovered, agents should be classified and audited according to their use. Are they employee-facing—deployed to automate internal workflows—or are they external-facing, designed to execute supply chain transactions or help deliver end-customer services? 

Identifying which components your agents are connecting to and classifying their use gives security teams an up-to-date, centralized inventory. Being able to see every AI asset and trace its lineage in a single view will help your organization proactively assess and mitigate risk while protecting future AI deployments. 

2. What can they do? (connection and blast radius)

Once you find and classify AI agents, you have to define their boundaries. In a world where AI agents are rapidly becoming the new “users” on your networks, the core philosophy of zero trust security remains the same: never trust, always verify. 

Don’t grant agents broad access to the network and other enterprise systems. Instead, set and enforce adaptive, context-aware policies that dictate exactly which data repositories, APIs, microservices, or cloud resources an agent is allowed to interact with. 

Policies can range from broader, role-based controls that define the high-level environments an agent can subscribe to; to network-based segmentation that restricts the flow of agentic traffic; to guardrails that prevent non-compliant actions or block suspected risky behavior. 

Setting policies that specify what an agent is allowed to read, write, or execute provides a baseline for compliance and a continuous oversight loop that can scale at the velocity today’s AI initiatives often require. 

3. What are they doing? (runtime authorization and control)

Boundaries aren’t effective if you are blind to the actual content of an agentic transaction. You must be able to monitor, assess, and authorize agent actions to prevent misuse, malicious behavior, and sensitive data leaks.

This level of inspection must be done inline, directly in the execution path. Here, AI gateways can serve as the runtime control plane—governing access and providing context based on the requested actions. 

For example, an agent attempts to retrieve and send software source code or a customer’s personally identifiable information (PII) to a non-approved external resource. The gateway can scan the prompt and strip any intellectual property before reaching the destination, or block the request entirely. In essence, your data governance policy is enforced in transit, not after an event has occurred. 

In addition, continuous monitoring and logging of all agent telemetry and event data can fortify inline threat defenses. This includes detecting unusual spikes in data requests or high volumes of calls to an internal API that an agent rarely touches. Being able to see, route, secure, and govern every AI transaction from a central control plane helps you apply zero trust to every model, agent, and API call in real time.

4. How do I respond? (active containment)

The final pillar transforms telemetry and risky behavior into automated responses for faster containment and remediation. Here, AI guardrails address vulnerabilities by providing an active checkpoint on every agent interaction—blocking malicious threats and moderating content to filter out toxic or unauthorized use of data. 

For example, bad actors are increasingly using prompt injection techniques that cause AI agents to behave differently than intended. AI guardrails can help detect and mitigate prompt injection patterns, flagging suspicious instructions. Additionally, the guardrails can analyze the semantic meaning of both the input prompt and the returned response to validate that the agent’s output matches its expected behavior before the data reaches its target destination. 

It’s worth mentioning that having precise guardrails in place is often favorable to broad-based blocking. While overall blocking declined year-over-year—suggesting progress toward more policy-driven AI governance—enterprises still blocked 39% of all AI/ML access attempts in 2025.

Instead, security teams can instantly isolate a compromised agent, revoke its specific access token, sandbox or quarantine it, or block its connection to a targeted application—and then safely restore it once the threat is mitigated. These more surgical mechanisms promote safer use of agents, deter users from seeking unapproved alternatives, and provide IT with a full trace for auditing and compliance.   

What Zscaler brings to the Blueprint Alliance

At Zscaler, we help customers safely embrace AI by providing a unified, comprehensive set of solutions to see every asset and secure every connection in the path of AI. 

We deliver many of the core capabilities outlined above through our AI Security solution suite, including: 

  • AI Asset ManagementMaintain an up-to-date, comprehensive inventory of AI apps, models, infrastructure, and agents to detect shadow AI, understand what data AI touches, and assess risk with a 360-degree view into AI usage.
     
  • Secure Access to AI: Govern access and content across popular GenAI apps, embedded AI in SaaS apps, agents, LLMs, and developer tools with user-based controls, prompt classification, inline inspection, and content moderation to reduce data loss and misuse while preserving productivity. 
     
  • Secure AI Apps and Infrastructure: Protect AI development across the lifecycle with automated AI red teaming, prompt hardening, runtime guardrails, and continuous risk posture assessments from build to runtime.

Looking ahead to secure the agentic AI era

The agentic era is here, and secure adoption will require industry-wide collaboration. As a founding member of the Blueprint Alliance, we will bring our expertise in zero trust security to help customers build a more connected and governed approach to agentic AI. 

We will also explore opportunities for deeper interoperability with our technology partners and fellow Blueprint Alliance members by building and testing cross-vendor signal sharing across open standards, as well as contributing to joint reference patterns and integrations.

For customers, this means a stronger foundation for adopting AI agents with confidence, combining the capabilities they need across their existing technology ecosystem rather than managing AI governance through disconnected point products.

Ready to learn more? Visit the Blueprint Alliance web page and download the Blueprint for the Secure Agentic Enterprise at blueprintalliance.ai.

form submtited
Merci d'avoir lu l'article

Cet article a-t-il été utile ?

Clause de non-responsabilité : Cet article de blog a été créé par Zscaler à des fins d’information uniquement et est fourni « en l’état » sans aucune garantie d’exactitude, d’exhaustivité ou de fiabilité. Zscaler n’assume aucune responsabilité pour toute erreur ou omission ou pour toute action prise sur la base des informations fournies. Tous les sites Web ou ressources de tiers liés à cet article de blog sont fournis pour des raisons de commodité uniquement, et Zscaler n’est pas responsable de leur contenu ni de leurs pratiques. Tout le contenu peut être modifié sans préavis. En accédant à ce blog, vous acceptez ces conditions et reconnaissez qu’il est de votre responsabilité de vérifier et d’utiliser les informations en fonction de vos besoins.

Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception

En envoyant le formulaire, vous acceptez notre politique de confidentialité.