Zero Trust as the AI Control Plane: What Zscaler's Vienna Pitch Means for APAC CISOs

AI agents are joining the workforce whether security teams are ready or not. At Zenith Live 2026, Zscaler made its case for why zero trust should govern them the same way it governs humans.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Zero Trust as the AI Control Plane: What Zscaler's Vienna Pitch Means for APAC CISOs
Share

Key points

  • Zscaler extended its Zero Trust Exchange at Zenith Live 2026 (16-17 June, Vienna) to cover AI agents as governed identities, not just users and workloads.
  • Three additions stood out: an AI Broker with Agent Registry, Endpoint AI Security for shadow-AI exposure, and an AI Access Graph backed by red-teaming across more than 250 GenAI applications.
  • The Zero Trust B2B Exchange replaces site-to-site VPNs and MPLS links with policy-controlled application access, keeping partners off shared network segments.
  • Southeast Asia's overlapping data-residency laws make architectural segmentation a compliance necessity, not an architectural preference.
  • AkzoNobel and Siemens Healthineers deployments showed "dark" branches invisible to internet scanning alongside deliberate AI adoption strategies.

Vienna, mid-June. Zscaler's Zenith Live 2026 conference carried a blunt message for anyone running security in Southeast Asia: AI agents are already inside your organisation, acting on its behalf, and most of your controls weren't written with them in mind.

The company used the event to extend its Zero Trust Exchange and SASE platform explicitly to cover AI agents. That framing matters. An AI agent that can query a database or invoke an API is, from an access-control standpoint, a privileged identity. Treat it like one, or don't complain when it becomes a blast radius.

Three additions stood out. First, an AI Broker with Agent Registry sits in the path between agents and the data they touch, inspecting prompts and responses while enforcing least-privilege access in real time. This is essentially a policy enforcement point for model input and output, closer to a web application firewall than to anything novel, applied to a layer that almost nobody is currently watching. Second, Endpoint AI Security surfaces the shadow-AI problem: local tools and browser extensions spreading across distributed workforces and contractor networks. Classic shadow-IT, new skin. Third, an AI Access Graph and AI Protect capability maps model usage and data flows across SaaS, public cloud, and on-premises systems, backed by red-teaming and prompt hardening across more than 250 GenAI applications.

The cross-border story is just as important for the region. Zscaler's Zero Trust B2B Exchange replaces site-to-site VPNs and MPLS links with policy-controlled application access, so partners and subsidiaries never share a network segment. Southeast Asia's patchwork of data-residency regimes, including Singapore's PDPA, Indonesia's PDP Law and Thailand's PDPA, makes that kind of segmentation less optional than it sounds. Our 4 June story on enterprise infrastructure decisions noted exactly this cost: data sensitivity and regulatory pressure forcing architectural rethinks before organisations are ready.

Customer deployments from AkzoNobel and Siemens Healthineers gave the announcements grounding: branches invisible to internet scanning, zero-trust B2B connectivity, and deliberate AI adoption strategies rather than outright bans.

Should you act before the auditors arrive?

Build a live inventory of AI usage and data flows now, before regulators force an emergency exercise. Then treat every AI agent you deploy as a new identity with a compliance posture and an attack surface attached, not as a productivity tool that sits outside your threat model.

That second point sounds obvious. Somehow it keeps not being obvious until something goes wrong.

© 2026 Threat Vectr