Sozzi Unleashed

Jay Chaudhry on Agents as the New Weakest Link

Jay Chaudhry· Founder and CEO of Zscaler at Zscaler
·~8 min·English·Yahoo Finance
AgentsAI SafetyAI InfrastructureBusiness Strategy
TL;DR

Jay Chaudhry argues billions of autonomous agents will become the enterprise's weakest link, and that the only workable defense is zero trust: distrust every agent and scope it to the exact apps and services it needs.

01Core Mental Model

The New Weakest Link

The weakest link in enterprise security is shifting <strong>from human users to billions of autonomous agents</strong>.

Today, our user is the weakest link. Tomorrow, there'll be billions of agents. They become the weakest link.

— Jay Chaudhry, Sozzi Unleashed
Key Insight
The shift inverts the security math. A workforce is bounded by headcount, so the human attack surface grows slowly; agents are provisioned on demand, so the agent attack surface grows with your compute budget. The weakest link stops being a person you can train and becomes a population you can only constrain with policy.

02The Threat

Dangerous at Machine Speed

A rogue agent is far more dangerous than a compromised user because it attacks <strong>at machine speed, around the clock</strong>.

They're far more dangerous because they work at machine speed. They have no coffee break, no weekend, no sleep time, and their number keeps on going.

— Jay Chaudhry, Sozzi Unleashed
Key Insight
Machine speed collapses the defender's response window. Incident-response playbooks assume human-paced intrusions with time to detect and contain. An agent exfiltrating continuously, with no downtime and a growing population, means containment has to be automatic and pre-authorized, not a pager escalation a human answers in the morning.

03The Principle

Don't Trust the Agent

The fix is zero trust: distrust every agent by default, then grant it access to <strong>only the specific apps and services it needs</strong>.

Don't trust agent. But give them this much trust for certain application and services. And that's it.

— Jay Chaudhry, Sozzi Unleashed
Key Insight
This is least privilege re-stated for non-human identities. The unit of authorization moves from the network ('where are you') to the action ('what app or service can you touch') — the same move cloud IAM made for people, now forced down to every agent that gets spawned.

04The Architecture

If They Can't Reach You, They Can't Breach You

Hiding applications behind the exchange and blocking lateral movement <strong>limits what a breached agent can reach and how far it can spread</strong>.

If they can't reach you, they can't breach you.

— Jay Chaudhry, Sozzi Unleashed
Key Insight
Hiding the app and blocking lateral movement attacks the two phases attackers actually depend on: reach and spread. The design assumes breach rather than trying to prevent it — the goal is to shrink a breached agent's blast radius to the few apps it was explicitly granted, not to keep every agent out, which is why the old firewall-and-VPN perimeter no longer fits.

05The Hard Problem

An Identity That Changes in a Second

Securing agents is far harder than securing users because <strong>an agent's identity can change in a second and one agent can spawn five more</strong>.

Agents can change identity in a second. And they have skills, they have tools. One agent can spawn five more agents. What permission should they have?

— Jay Chaudhry, Sozzi Unleashed
Key Insight
Mutable identity plus self-spawning breaks the assumption every access-control system makes — that a principal is stable and can be enumerated in advance. If one agent becomes five, each needing its own scoped grant, authorization has to be issued programmatically at spawn time, not configured by an admin beforehand.

06On Regulation

Responsibility, Not a Slowdown

Chaudhry rejects both 'accept some bad things' and a development slowdown, favoring <strong>shared responsibility across the stack</strong> instead.

So, I believe each party needs to take responsibility to do its own job. Models need to do better work on their side.

— Jay Chaudhry, Sozzi Unleashed
Key Insight
Rejecting Altman's 'accept some bad things' while also rejecting a slowdown is a bet that security can be engineered in parallel with capability. The implied business logic is pointed: regulation or a pause freezes the market Zscaler sells into, so distributed responsibility — models test harder, enterprises add guardrails, a security layer joins them — is both his safety argument and his go-to-market.