Organizations: Department of Computer Science, Tennessee Tech University, Cookeville, TN, USA · Department of Computer Science, University of North Carolina Pembroke, Pembroke, NC, USA · Department of Computer Science, The University of Texas at Dallas, Richardson, Texas, USA
Agentic AI is emerging as a promising paradigm for automating complex cybersecurity decisions, yet its use in enforcing zero trust introduces significant challenges in safety, reliability, and policy compliance. This paper presents Agentic AI based zero trust architecture (Agentic-ZTA) that operationalizes the NIST SP 800-207 ZTA architecture control loop through coordinated multi- agent decision pipeline. In the proposed framework, policy knowledge is embedded into a retrieval-augmented generation pipeline and retrieved at inference time as top-k relevant policies. Access requests are intercepted by the Policy Enforcement Point (PEP), enriched with contextual metadata. The request context is routed to a policy engine agent which invokes domain-specialized core agents first followed by supporting agents, if further evaluation needed. AI agents reason over access context, policy constraints and determine trust. The retrieved policies are embedded into agent prompt during inference time and agentic trust scores are aggregated and evaluated by a trust-algorithm, producing the final access decision for enforcement under continuous verification. We implement Agentic-ZTA in a testbed and evaluate it on representative access-control use cases scenarios. Our Agentic-ZTA framework achieves 95.0% accuracy, 93.9% precision, and 96.3% recall, and demonstrate the feasibility of enforcing zero trust using AI agents.
Figures & tables
Work
ZTA
MA
LLM
Trust
Enf.
Impl.
Ameer [ 3 ]
∘
–
–
∘
–
–
Ameer [ 4 ]
+
–
–
∘
–
∘
Chandramouli [ 13 ]
+
–
–
–
–
–
Borchert [ borchert2025implementing ]
+
–
–
–
–
∘
Lewis [ 28 ]
–
–
+
–
–
–
Cardoso & Ferrando [ 12 ]
–
+
–
–
∘
–
Table 1: Comparison of Related Work Against Agentic-ZTA
Figure 1: Agentic-ZTA architecture. The PE agent serves as the orchestrator within the NIST ZTA Policy Decision Point (PDP), invoking core agents, querying supporting agents upon initial clearance, and synthesizing their evaluations via the trust algorithm. The PEP subsequently enforces the access control decision.
Figure 2: Agentic-ZTA access control workflow. Subject need access to a resource. The PEP normalizes and forwards each request. The request is embedded and top-k matched policies are retrieved. Access request is sent to PE agent for evaluation, which invokes core agents first then supporting agents when no core agent Deny . Decision is enforced under continuous verification.
Figure 3: Five-zone IoBT coalition testbed topology. Zone gateways act as distributed PEPs and forward all access requests to the PE Agent at the Shared Data Fabric.
Agent
di
si
ci
Decision
IAM
0
1.0
0.95
ALLOW
Threat Detection
0
1.0
0.70
ALLOW
CDM
0
1.0
0.70
ALLOW
Data Access Policy
0
1.0
0.95
ALLOW
Table 2: Per-Agent Assessment for Use Case 1
Agent
di
si
ci
Decision
PKI
0
1.0
0.85
ALLOW
IAM
1
0.0
0.60
DENY
Table 3: Per-Agent Assessment for Use Case 2
Figure 4: Agentic actions executed by the PE Agent following the trust decision. On Allow , the PE Agent calls issue_access_token() , log_decision() and send_notification() tools. On Deny , it calls revoke_certificate() , quarantine_session() , log_decision() and send_notification() tools.
Figure 5: Confusion matrix for Agentic-ZTA on 160 access-request evaluation samples ( DENY = positive class).
Figure 6: ROC curve for Agentic-ZTA on the 160-sample access-request evaluation dataset. The operating point corresponds to the deployed decision threshold.
Agentic AI networking (AgentNet) systems rely heavily on third-party skillset implementations and distributed multi-agent collaboration, yet they face major claim-to-capability inconsistencies and security vulnerabilities under trust-by-declaration assumptions. To bridge this gap, this paper proposes TrustAgentNet, a dual-tier blockchain-secured zero-trust framework. Specifically, a global Chain of Skillsets (CoS) governs the lifecycle of skillset metadata with protocols empowered by specialized agents to enforce off-chain auditing while maintaining lightweight on-chain cryptographic consensus. Furthermore, transient, task-oriented Chains of Collaboration (CoC) are dynamically established to enable trustless distributed multi-agent collaboration. Theoretical analysis of the three-way trade-off among security level, task performance, and resource overhead is provided and empirically validated. Experimental results on a hardware prototype demonstrate that compared with no-blockchain trust-by-default baselines, the zero-trust overhead of TrustAgentNet is dominated by off-chain inference, while the blockchain layer incurs minor ledger costs via the ledger-IPFS storage and on/off-chain integration design. Crucially, the proposed verification pipeline achieves a flawless 100% accuracy across 50 AI models, correctly validating 40 honest skillsets and intercepting 10 adversarial ones, and generalizes to non-AI domains with an 83.91% accuracy and a 0.85 F1-score across 1478 features from 171 ClawHub skills. Adversarial experiments further show that TrustAgentNet enables autonomous skillset self-recovery against various malicious attacks.
Yayu Gao, Yong Xiao, Hao Hu +5
School of Electronic Information and Communications, the Huazhong University of Science and Technology, Wuhan, China 430074 · Peng Cheng Laboratory, Shenzhen, China · Pazhou Laboratory (Huangpu), Guangzhou, China +4
Autonomous agents are increasingly used to execute consequential tasks in environments governed by operational constraints, organizational policies, regulatory requirements, and technical standards. Their safety is therefore determined not by the correctness of individual actions, but by whether their overall behavior remains consistent with the rules and invariants of the systems in which they operate. As large language model (LLM)-based agents become more autonomous and increasingly delegate tasks across organizational boundaries, securing them evolves from a single challenge into a broad and interconnected landscape spanning the entire agentic stack. At the single-agent level, untrusted inputs through prompts, memory, retrieved knowledge, and tool interfaces create attack surfaces. In multi-agent settings, delegation and communication introduce challenges related to identity, trust, capability control, and decision transparency, while the underlying model routing and execution control plane remains vulnerable to manipulation and to unverified model provenance. Perhaps the most fundamental challenge is behavioral containment: sequences of individually permissible actions may collectively violate system-level constraints and safety invariants. At the broader level, supply-chain integrity, provenance, accountability, and end-to-end observability remain largely open problems. A common principle unifies these directions: security must become a verifiable property of the architectures, protocols, and runtimes that govern agent behavior, rather than an optional layer of guidance. Charting these challenges provides a roadmap toward trustworthy autonomous agent deployment.
Authorizing Large Language Model (LLM)-driven agents to dynamically invoke tools and access protected resources introduces significant security risks, and the risks grow dramatically as agents engage in multi-turn conversations and scale toward distributed collaboration. A compromised or malicious agentic application can tamper with tool calls, falsify results, or request permissions beyond the scope of the subject's intended tasks, which could go unnoticed with current delegated authorization flows given their lack of visibility into the original subject's intent. In light of this, we make the following contributions towards Continuous Agent Semantic Authorization (CASA). First, we propose a hybrid runtime enforcement model that combines deterministic and semantic controls enabled by a zero-trust interception layer. Five deterministic controls enforce structural and data-integrity guarantees over the message flow, while a semantic inspection layer evaluates whether tool call choices align with the intended tasks commissioned to the agent. Second, differently from prior Task-Based Access Control (TBAC) techniques that operate on single-turn interactions, we decompose the semantic layer into two stages: i) a task-extraction step that distills the subject's objectives from multi-turn conversations at the interception layer, and ii) a task-tool semantic matching step at the authorization server that evaluates whether the requested tools are appropriate for the extracted tasks. Third, we extend the ASTRA dataset that we introduced in a prior work, by generating novel conversation-tool datasets with multi-turn interactions containing relevant and irrelevant tool calls for a given task. Lastly, we provide the first experimental results for TBAC under multi-turn conversations.