Zero Trust as the AI Control Plane: What Zscaler's Vienna Pitch Means for APAC CISOs
AI agents are joining the workforce whether security teams are ready or not. At Zenith Live 2026, Zscaler made its case for why zero trust should govern them the same way it governs humans.

Vienna, mid-June. Zscaler's Zenith Live 2026 conference offered a fairly blunt message for anyone running security in Southeast Asia: AI agents are already inside your organisation, acting like employees, and most of your controls weren't written with them in mind.
The company used the event to extend its Zero Trust Exchange and SASE platform explicitly to cover AI agents — not just users and workloads. That framing matters. An AI agent that can query a database, invoke an API, or pass instructions to another agent is, from an access-control standpoint, a privileged identity. Treat it like one, or don't complain when it becomes a blast radius.
Three specific additions stood out. First, an AI Broker with Agent Registry that sits in the path between agents and the data or applications they touch, inspecting prompts and responses and enforcing least-privilege in real time. This is essentially a policy enforcement point for model I/O — closer to a web application firewall than to anything novel, but applied to a layer that almost nobody is currently watching. Second, Endpoint AI Security that surfaces the shadow-AI problem: local tools, browser extensions, and plugins spreading across distributed workforces and contractor networks. Classic shadow-IT, new skin. Third, an AI Access Graph and AI Protect capability that maps model usage and data flows across SaaS, public cloud, and on-premises systems, backed by red-teaming and prompt hardening across more than 250 GenAI applications.
The cross-border story is arguably just as important for the region. Zscaler's Zero Trust B2B Exchange replaces site-to-site VPNs and MPLS links with policy-controlled application access — partners and subsidiaries never share a network segment, even as data moves between jurisdictions. Southeast Asia's patchwork of data-residency regimes (Singapore's PDPA, Indonesia's PDP Law, Thailand's PDPA, and others) makes this kind of architectural segmentation less optional than it sounds.
Customer deployments from AkzoNobel and Siemens Healthineers gave the announcements some grounding: "dark" branch offices invisible to internet scanning, zero-trust B2B connectivity, and deliberate AI adoption strategies rather than outright bans.
If there's a practical takeaway for CISOs in the region, it breaks into two points. Build a live inventory of AI usage and data flows now, before regulators and auditors force an emergency exercise. Then treat every AI agent you deploy as a new identity with a compliance posture and an attack surface attached — not as a productivity tool that sits outside your threat model.
The second point sounds obvious. Somehow it keeps not being obvious until something goes wrong.



