Beyond Zero: Google Publishes Successor to BeyondCorp
| Source: InfoQ AI/ML
Tags: Beyond Zero, BeyondCorp, Google, Zero Trust, AI agents, enterprise security, agentic AI
Google's research paper "Beyond Zero" proposes a successor to its 2014 BeyondCorp Zero Trust model, built for AI agents acting at machine speed. Rather than trusting at the application boundary, it authorizes every individual action and API call continuously — treating autonomous agents as first-class security principals alongside humans.
Details
Google's 2014 BeyondCorp framework replaced perimeter security with zero-trust access built on three assumptions: accessors are human, actions occur at human speed, and applications are the right trust boundary. All three now fail in enterprises running autonomous AI agents. Beyond Zero is Google's proposed successor: authorization moves down to individual actions and API calls, applied continuously to both humans and agents. The model rests on five principles: action-level authorization across all interfaces and APIs; blending static policies with dynamic AI-driven controls for higher-risk scenarios; automatic context enrichment about users, data, and risk; automated investigation triggered by risk signals; and challenge or containment mechanisms that can demand additional verification from agents or humans when something looks anomalous. The paper carries credibility — co-authored by Heather Adkins (VP Security Engineering, Google), Archana Ramamoorthy (Senior Director, Google), Joseph Valente (former PM director), and Michal Zalewski (distinguished security researcher). But adoption hurdles are significant: SaaS vendors must expose action-level authorization APIs (most don't today), industry standards need to mature, and smaller security teams face genuine costs around false positives and audit trails at agent scale. The practical takeaway for enterprises: start mapping which systems your AI agents touch, and pressure SaaS vendors for action-level authorization controls before your agent footprint scales.