Jay Chaudhry on Agents as the New Weakest Link
Jay Chaudhry argues billions of autonomous agents will become the enterprise's weakest link, and that the only workable defense is zero trust: distrust every agent and scope it to the exact apps and services it needs.
The New Weakest Link
The weakest link in enterprise security is shifting <strong>from human users to billions of autonomous agents</strong>.
Today, our user is the weakest link. Tomorrow, there'll be billions of agents. They become the weakest link.
Dangerous at Machine Speed
A rogue agent is far more dangerous than a compromised user because it attacks <strong>at machine speed, around the clock</strong>.
They're far more dangerous because they work at machine speed. They have no coffee break, no weekend, no sleep time, and their number keeps on going.
Don't Trust the Agent
The fix is zero trust: distrust every agent by default, then grant it access to <strong>only the specific apps and services it needs</strong>.
Don't trust agent. But give them this much trust for certain application and services. And that's it.
If They Can't Reach You, They Can't Breach You
Hiding applications behind the exchange and blocking lateral movement <strong>limits what a breached agent can reach and how far it can spread</strong>.
If they can't reach you, they can't breach you.
An Identity That Changes in a Second
Securing agents is far harder than securing users because <strong>an agent's identity can change in a second and one agent can spawn five more</strong>.
Agents can change identity in a second. And they have skills, they have tools. One agent can spawn five more agents. What permission should they have?
Responsibility, Not a Slowdown
Chaudhry rejects both 'accept some bad things' and a development slowdown, favoring <strong>shared responsibility across the stack</strong> instead.
So, I believe each party needs to take responsibility to do its own job. Models need to do better work on their side.