Zero Trust Was Built for a World Like Mythos

AI-accelerated threats

Schedule a Portnox Cloud demo today.

Contents

Zero trust has been called a lot of things over the past decade: a buzzword, a compliance checkbox, a rebrand of network segmentation. What it hasn’t been called, until now, is essential. Look closer at what it actually assumes. Continuous verification, not a one-time check at login, sits at the center of it. That single assumption makes zero trust look less like a framework catching up to AI-accelerated threats and more like one that’s been waiting for them.

The Framework Nobody Built for AI

John Kindervag coined “zero trust” at Forrester in 2010, and NIST formalized it in SP 800-207 nearly a decade later. Neither one anticipated autonomous vulnerability discovery. What they were solving for was simpler and, it turns out, more durable: the perimeter is a fiction, and trust granted by network location is trust misplaced.
The canonical example is the Target breach: attackers got in through a third-party HVAC vendor’s credentials, then moved laterally because that vendor’s access, once inside, was trusted more or less like anyone else’s. Nobody designed that outcome. It fell out of a model that verified identity once, at the door, and assumed good behavior after that. Zero trust’s founding argument was that this model breaks down the moment you have more entry points than you can watch, which, even in 2010, was already true.
Takeaway: Zero trust wasn’t a response to a specific attacker. It was a response to the idea that trust, once granted, tends to get used for more than it was meant for.

Same Assumption, Bigger Population

Article 1 in this series covered how Mythos-class discovery collapsed the patch window: thousands of high-severity vulnerabilities found at once, working exploits on the first try more often than not. Article 2 covered what that does to the clock security teams operate on: a 29-minute breakout time doesn’t leave room for a human-paced response.

Neither of those problems is really about patching or speed on their own. They’re about population. AI-accelerated threats don’t do anything different, they just do it faster, but faster is enough to change who’s capable of pulling it off. When exploitation only required rare skill, the number of entities capable of doing real damage was naturally limited. Lower that skill floor, and everyone connected to the network, every laptop, every service account, every AI agent, becomes a slightly more plausible source of the next incident. Zero trust never assumed a safe subset of identities that didn’t need watching. It assumed all of them might eventually earn distrust. That was a strange thing to build a framework around in 2010. It’s a completely unremarkable thing to build one around now, and it’s exactly why continuous verification, not a one-time gate, has to be the default.

Takeaway: Zero trust’s least-privilege posture never depended on knowing in advance which identity would go bad. That happens to be exactly the assumption an AI-accelerated threat landscape requires.

Continuous Verification Was the Point All Along

The metric Article 2 proposed, time-to-adapt, asks how long it takes to restrict access once something stops being trustworthy. That question only makes sense if trust was never a one-time decision in the first place. Zero trust said this before there was a Mythos-shaped reason to say it: verification isn’t a gate you pass once at login, it’s a condition you keep meeting for as long as you’re connected.

Device trust follows the same logic. It rose to prominence during the BYOD and mobile explosion, when the population of things connecting to a network stopped being predictable. That population is expanding again, this time to include ephemeral, non-human identities: agent processes spun up for minutes, given a task, and torn down. An identity that only exists for the length of a single operation still has to be verified for the length of that operation, and still has to lose access the moment its posture changes. Zero trust’s insistence on continuous, not point-in-time, verification wasn’t written with that identity in mind. It scales to it anyway.

Takeaway: “Continuous” was always the operative word in zero trust. It just took a threat landscape moving at machine speed to make that word load-bearing.

What’s Actually New

Zero trust didn’t come with a crystal ball. Nobody at Forrester in 2010 saw Mythos-class discovery coming, and NIST wasn’t drafting SP 800-207 with autonomous exploit generation in mind. What they built was something better than foresight: a set of assumptions general enough to survive a change in who or what is doing the attacking. What’s new isn’t the logic, it’s the population the logic has to be applied to: non-human identities without a fixed shape, access decisions that can’t wait on a ticket queue, and a volume of connecting entities that makes manual review a losing strategy. A framework built to distrust by default and verify continuously doesn’t need to be rewritten for that population. It needs to be operationalized for it.

Closing the Loop

This series started with a hard truth: AI vulnerability discovery broke the assumption that defenders had time. It continued with a harder one: the clock that matters now drains like sand through an hourglass, gone in minutes, while most security programs are still checking it in months. The honest conclusion is that the fix was never going to be a faster patch cycle. It was always going to be a framework that doesn’t rely on getting to a vulnerability before someone else does, because it never grants enough access for that race to matter in the first place. That’s the only kind of framework that holds up against AI-accelerated threats: one that never bet on winning the race to begin with.

That’s the framework zero trust already was. Portnox Cloud operationalizes continuous verification the way it was meant to work from the start: cloud-native, applied to every identity that connects, human or not, patched or not, permanent or provisioned for the length of a single task. The organizations that hold up best in a Mythos-shaped world won’t be the ones that discovered zero trust because of AI. They’ll be the ones who already had continuous verification running when AI changed who they needed it against.

Share

About the Author

Picture of Kate Asaff

Kate Asaff

Kate Asaff is a Technical Product Marketing Manager at Portnox with more than two decades of experience spanning networking, enterprise IT, and cybersecurity. Before moving into product marketing, she spent over 15 years at SolarWinds in technical support and program management, helping bridge the gap between engineering and the people who rely on technology every day. Today, she writes about network access control, zero trust, AI, identity security, and passwordless authentication for the practitioners who implement them.

About the Author

Picture of Kate Asaff

Kate Asaff

Kate Asaff is a Technical Product Marketing Manager at Portnox with more than two decades of experience spanning networking, enterprise IT, and cybersecurity. Before moving into product marketing, she spent over 15 years at SolarWinds in technical support and program management, helping bridge the gap between engineering and the people who rely on technology every day. Today, she writes about network access control, zero trust, AI, identity security, and passwordless authentication for the practitioners who implement them.

Related Reading

Artificial IntelligenceSecurity Trends

NVIDIA’s New Agent Watchdog Can Quarantine an Agent. It Can’t Revoke Its Credentials.

September 29, 2026
Security TrendsZero Trust

Microsoft Just Proved the Passwordless Argument

September 28, 2026
Network Access ControlNetwork SecuritySecurity Trends

Visibility Isn’t Control

September 28, 2026

Portnox Closes the Gap on Shadow AI

X