Blog de Zscaler

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Products & Solutions

Closing the Endpoint Zero Trust Gap

DHAWAL SHARMA, VIVEK RAMACHANDRAN
October 08, 2026 - 10 min read
>Closing the Endpoint Zero Trust Gap

At Zenith Live in Las Vegas, we introduced Zscaler AI Endpoint Security, a new product that extends Zscaler's AI protection to the endpoint. If you already use Zscaler to secure AI usage across your network, cloud, and SaaS applications, this product applies the same zero-trust approach to the AI applications and agents now running directly on your users' devices.

This post covers why we built it: what's actually changing on the endpoint, why the tools most organizations already run there aren't designed for this problem, and how Zscaler is approaching it.

What we're seeing on the endpoint

A new AI application layer has been forming on enterprise endpoints, and it has grown faster than most inventory processes can track.

It started with frontier AI applications: Claude Code, Cowork, OpenAI Codex, Gemini, Microsoft Copilot. What's notable isn't just the adoption rate; it's who is adopting them. These are no longer developer tools. Finance teams, marketers, and HR teams are using them to do work that previously required a technical specialist, and they're getting real results. That's exactly why this trend won't reverse.

The part that concerns security teams is everything these applications bring with them:

  • Configuration and extension sprawl: Plugins, skill files, prompt libraries, MCP servers, subagent definitions, memory files, and background telemetry processes. These components install and update outside your normal software lifecycle.
  • AI-powered IDEs: VS Code, Cursor, and Windsurf, each with extension marketplaces where third-party code runs with the user's full privileges.
  • Local models: Ollama, LM Studio, and llama.cpp put multi-gigabyte model files on disk. We've seen model files that carry serialized code execution, embedded backdoors, content that violates policy, and models renamed to look like something they're not.
  • Package dependencies: Python, npm, and Homebrew packages pulled in by the hundreds to support AI workflows, with the supply-chain exposure that implies.
  • AI assistants and browsers: Tools like OpenClaw, Hermes, and Microsoft Scout, plus AI-enabled browsers such as Chrome, Edge, Comet, and Atlas with embedded models and agent capabilities.

Underneath all of this sits the change that matters most: agents act as the user. An agent runs under the user's identity, with the user's permissions, touching the user's files and network connections. When we talk to security teams, this is the point where the conversation usually slows down, because most of their controls and audit trails assume that an action taken under a user's identity was taken by that user. That assumption no longer holds.

This is AI asset sprawl: applications that create applications, files created faster than they can be classified, and identities that are no longer only human.

Why existing endpoint tools weren't built for this

The reasonable first question is: don't EDR, DLP, and MDM already cover the endpoint? They do, and none of them should go anywhere. But each one was designed around assumptions that AI asset sprawl breaks. This isn't a criticism of those products. It's a scoping observation.

EDR watches files, processes, and threads, and it's very good at recognizing attack patterns and stopping malware and ransomware. 

But walk through a typical AI incident: a user types a prompt, an agent modifies local files and sends data over the network. From EDR's perspective, there is no malware signature, no process injection, no privilege escalation—just a signed application from a major vendor doing normal application things. The context that would tell you something is wrong lives at the AI application layer: the prompt, the skill file that shaped the behavior, the MCP server involved, the agent's goal. EDR was never designed to see any of that.

DLP was built for an environment where you could catalog your files, trace when each was created and modified, and scan content against known patterns. 

Those steps still work; the environment changed. On an endpoint with active agents, hundreds of new files can appear per minute: generated reports, working datasets, code, memory files. Classification pipelines sized for human document-creation rates fall behind immediately. 

Lineage breaks too — a file an agent synthesized from six sources and rewrote twice has no ancestry a traditional DLP can reconstruct. And pattern matching struggles when agents constantly reshape and re-encode the data they touch.

MDM gave IT a reliable answer to "what is installed on this machine?" Sanctioned apps, managed versions, change control. 

The new failure mode is simple to state: AI applications create other applications. One prompt produces a finance dashboard app in its own folder. Another folder fills up with PowerShell scripts that modify system settings. None of it went through change management, none of it appears in the software inventory, and MDM has no mechanism to version it or determine what it's for. The gap between what IT believes is on the endpoint and what is actually running there widens every day.

The common thread: all three product categories assume a predictable endpoint—known applications, human-speed file creation, human-only identity. AI asset sprawl breaks all three assumptions at once. That's not a feature gap you close with a release; it's a different problem that needs a purpose-built product.

How Zscaler AI Endpoint Security works

We built this product from the ground up for this new AI-native application layer, around the same zero trust principles that run through the rest of the Zscaler platform: verify rather than assume, tie every action to an identity, and enforce policy inline. 

The Zscaler agent on the endpoint gains visibility into the AI application layer itself, and delivers three capabilities.

1. AI Asset Inventory

First, discovery. The product builds and maintains a complete inventory of AI assets on each endpoint:

  • Frontier model applications (Claude, Codex, Copilot, Gemini)
  • Local model applications (Llama, Ollama, LM Studio, custom models)
  • AI browsers and AI-powered IDEs
  • Package managers and other channels bringing AI components onto the device
  • The entire ecosystem installed within these apps, including plugins, extensions, skills, and add-ons

Inventory goes below the application level, to the components that determine what these apps can actually do: config files, skill files and prompts, MCP servers, agent definitions, memory and knowledge stores, model files, telemetry and persistence mechanisms. 

The output is a structured map of your AI footprint per endpoint, with high-risk findings flagged—unapproved agents, risky plugins, unknown model files, and shadow AI your inventory has never seen.

2. AI Agent Runtime Monitoring

Inventory tells you what's present. Runtime monitoring tells you what it's doing. While AI applications run, Zscaler captures the events that matter at the AI application layer:

  • Prompts and responses
  • Tool and function calls
  • Skill files invoked and MCP servers connected
  • File access and data movement
  • Process and data lineage
  • System interactions and network connections

Because these events are captured with full context, you can reconstruct a complete agent run—the main agent and every subagent it spawned—and correlate it to identity: which user, which agent, which device, which data. This is the piece that directly addresses the ‘agents act as the user’ problem. When something anomalous happens, you're not left guessing whether the human did it; you can see exactly which agent acted, on whose behalf, and what it touched.

3. Enterprise AI Policy Enforcement

Visibility on its own doesn't change outcomes, so the third capability is inline enforcement—the control point IT and security teams have been missing on this layer. Policies apply in real time to:

  • Block rogue or unauthorized agents before they act
  • Stop malicious skill files and instructions
  • Halt dangerous commands and code execution via agents
  • Prevent data exfiltration and protect sensitive or critical files
  • Monitor and police extensions within frontier AI apps
  • Flag PII inside prompts before it leaves the device
  • Enforce acceptable-use, data-protection, compliance, and custom enterprise policies consistently across frontier AI apps, AI-powered IDEs, AI assistants, and AI browsers alike

Taken together: inventory answers “what is here”, runtime monitoring answers “what is it doing,” and enforcement answers “what will we allow.” The same questions zero trust has always asked—now asked of AI assets and agents on the endpoint.

Why the need is so urgent

Three things convinced us this needed to be a must-build product—and that it couldn't wait.

The endpoint is becoming a software factory. "Apps that create apps" is not an edge case we found in testing; it is the stated product direction of every major AI vendor. 

And it is exactly how AI asset sprawl compounds, as every new application arrives with its own configs, skills, models, and agents. Subagents, background agents, agents embedded in browsers and IDEs: hundreds of agents will soon be running on endpoints on behalf of users, just as they already are in the cloud. 

Any governance model built on "one identity, one human" stops scaling; agent identity and lineage have to become first-class objects in your security model. The gap between installed software and existing software will keep growing, and only continuous discovery paired with runtime observation can keep up with software that didn't exist an hour ago.

Audit requirements are moving toward AI actions. The questions we increasingly hear from compliance teams are concrete: which agent touched this customer data, under whose authority, and what left the device? Those questions can only be answered at the endpoint, at the AI application layer, at runtime. Organizations that can't reconstruct an agent run will struggle to answer them at all.

Productivity and competitiveness cannot slow down. Every organization is watching its peers and competitors adopt AI at full speed. Blocking the tools that make employees more productive is not a viable answer because it simply trades a security risk for a competitive one. 

A security solution built for the AI application layer means people keep doing their best work with the tools that raise the organization's productivity and success, while the enterprise stays in control.

We've seen this pattern before. When perimeters dissolved, zero trust replaced castle-and-moat on the network. When work moved to cloud and SaaS, zero trust followed. The AI application layer arriving on the endpoint is the same story, one layer further in. And it's better to have controls in place while the sprawl is measured in dozens of assets per device rather than hundreds.

EDR will keep stopping malware. DLP will keep protecting the data it can see. MDM will keep managing the software IT deploys. Keep all three. Zscaler Endpoint AI Security covers the layer none of them see: the AI applications, agents, and assets acting on your endpoints under your users' identities.

What's next

Zscaler Endpoint AI Security is rolling out to customers now. If you want to see your own endpoint AI footprint—most teams are surprised by their first inventory report—learn more here or reach out to your account team for a demo.

FAQs

AI asset sprawl is the uncontrolled growth of AI applications, local models, extensions, and agent-driven workflows on user devices. It's an enterprise endpoint security risk because it introduces unauthorized local configurations, unmonitored background telemetry, and unsanctioned code execution that bypasses traditional software lifecycle inventories and security monitoring protocols.

Traditional EDR tools fail to monitor low-level processes and signature-based patterns. Since AI agents run as authorized applications that use legitimate user credentials, EDR can't identify malicious intent within prompts, custom skills, or tool calls. The context needed to detect suspicious AI behaviors exists strictly at the application layer.

Effective endpoint AI security requires continuous, automated discovery of all AI assets. It also includes real-time monitoring of agent runtimes to trace prompts and system actions. Securing AI environments requires organizations to adopt a solution that can block unauthorized agents, sanitize sensitive prompts, and govern third-party application extensions directly at runtime. 

Organizations can reconstruct AI agent actions by capturing full-context runtime telemetry. This process maps prompts, responses, tool executions, and file modifications directly to specific user and agent identities. Documenting this complete operational lineage allows compliance and security teams to verify exactly which agent performed an action, and under whose authority that agent acted.

Securing generative AI prompts against data exfiltration requires inline runtime controls that inspect outgoing traffic in real time. These AI controls must automatically identify and redact PII, intellectual property, and restricted enterprise data within AI prompts before those prompts leave the endpoint. This ensures strict compliance with enterprise acceptable AI usage policies.

Organizations can balance AI productivity and security by implementing a dedicated zero trust security framework that's tailored to secure the AI application layer. Instead of blocking valuable productivity tools, organizations should use solutions that provide continuous asset discovery, agent runtime visibility, and granular inline policy enforcement. This ensures that employees can safely use AI while protecting enterprise data from leakage or exfiltration.

form submtited
Gracias por leer

¿Este post ha sido útil?

Descargo de responsabilidad: Esta entrada de blog ha sido creada por Zscaler con fines únicamente informativos y se proporciona "tal cual" sin ninguna garantía de exactitud, integridad o fiabilidad. Zscaler no asume ninguna responsabilidad por cualquier error u omisión o por cualquier acción tomada en base a la información proporcionada. Cualquier sitio web de terceros o recursos vinculados en esta entrada del blog se proporcionan solo por conveniencia, y Zscaler no es responsable de su contenido o prácticas. Todo el contenido está sujeto a cambios sin previo aviso. Al acceder a este blog, usted acepta estos términos y reconoce su exclusiva responsabilidad de verificar y utilizar la información según convenga a sus necesidades.

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Al enviar el formulario, acepta nuestra política de privacidad.