Urgent.News

What's breaking now, across thousands of outlets.

Tech

Beyond Zero: Google Publishes Successor to BeyondCorp

In a recent research paper, Google introduced Beyond Zero, a “security model for the AI era” that extends Zero Trust to autonomous AI agents. The new approach moves access decisions from the application level to individual resources and actions, combining static authorization controls with dynamic AI-driven decisions to enable machine-speed enforcement for humans and agents. By Renato Losio

Google has published a research paper detailing Beyond Zero, an advanced security model designed for the era of artificial intelligence. This model expands upon Zero Trust, Google's approach to enterprise security, by introducing a new paradigm for protecting AI agents.

Key differences from traditional Zero Trust include authorization at the individual action and resource level, a blend of static policies and dynamic controls for heightened risk scenarios, and the incorporation of extensive contextual and risk-based data. This information is derived from five core principles outlined in the paper: authorization at the action and resource level, combining static policies and dynamic controls for higher-risk situations, continuously updated context about users, actions, data, and risks, automated investigation triggered by risk indicators, and challenges or containment measures that may necessitate additional verification or data from users and AI agents.

The introduction of Beyond Zero comes as AI agents are deployed across the globe, transforming the assumptions surrounding enterprise security. SaaS vendors will need to provide action-level authorization, while standards in this field must evolve. Google notes that smaller security teams will face challenges regarding false positives, intent, auditing, and cost.

Google's approach to Beyond Zero has garnered mixed reactions. While Heather Adkins, VP of security engineering at Google, explains that continuous authorization of every action at scale initially seemed excessive, the scale of users and AI agents has made it necessary. SaaS vendor Canva's security manager, Kane Narraway, expresses cautious optimism about the goals but warns about the challenges smaller enterprises might face in implementing these ideas.

The community's response has largely been skeptical, with concerns raised about the reliability and complexity of AI-driven authorization.

Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at infoq.com →

More in Tech

My GSoC Journey with InVesalius: Bringing PACS Integration to InVesalius

My GSoC Journey with InVesalius: Bringing PACS Integration to InVesalius For the past three months I have been contributing at Invesalius as a GSOC contributor.

  • Implemented PACS integration for InVesalius software
  • Utilized pynetdicom, pydicom libraries for server communication
  • Developed search, retrieval, and storage interface features

More from Saturday 5 September →