Beyond Zero Trust: What Google’s New AI Security Framework Means for Your Controls

— by

If you’re using Claude, ChatGPT, Copilot, or Cursor at your firm right now, those tools are already doing more than you’d probably approve of if you watched it happen in real time. Not because anyone did anything wrong — because of how they work. They start wide, they poke around to find context, and they make a lot more calls than a person would to answer the same question.

That’s the starting point for a piece Google and Alphabet’s security team put out recently called Beyond Zero. It’s their framework for thinking about security in a world where AI agents, not just humans, are the ones touching your systems. I want to walk through it, because a lot of what it points to lands directly on the part of our job that’s about controls and governance.

Why this matters to you specifically

A big piece of the CPA role is controls: making sure the right people have access to the right things, for the right reasons, and that you can prove it later. Google’s argument is that AI agents break the assumptions most control environments were built on. The security model most companies run — BeyondCorp, which Google itself put out in 2014 — checks your identity, checks your device, and then trusts the whole session. That model assumes the person accessing the system is human and is operating at human speed.

AI agents aren’t operating at human speed. Google’s number: agents are interacting with systems at roughly 10x the rate of human employees. If you’ve used any of these tools for real work, you’ve probably seen it — they’re making a dozen calls where you’d have made one.

Three forces breaking the old model

Google frames the shift around three forces. Volume — agents hit systems at rates legacy infrastructure wasn’t sized for, often too fast for a human to notice in real time. Data velocity — agents reason across huge structured and unstructured data sets, casting a wide net instead of asking a colleague where to look first, the way a person would. And ambient authority — once you set an agent up, it generally inherits the full permission set of whoever configured it, not a narrower, task-specific slice of access.

That last one is the one I’d flag hardest. Think about what ambient authority actually means in practice: an agent running with your full permissions is functionally close to a shared login credential. Right now, most of the tools we all use — Claude, ChatGPT, Copilot — default to exactly that. Every new chat starts with access to whatever connectors you’ve set up, and you can go turn things off, sometimes down to a granular level, sometimes not. But almost nobody is treating that as an active part of setting up a chat or an agent. It should be.

The question your next SOX or ITGC review might ask

Here’s the part that’s most directly relevant to how we work. The traditional audit question is: who has access to what, and who approved that role? Google’s framework points to a harder, more specific version of that question: can you show what data an agent touched, on whose behalf, and why that specific access was authorized — not just who signed off on a role months ago?

If an agent kicked off by one of your staff made 15 data pulls to answer a question that, pre-AI, would have been a single query, can you explain why? Right now, for most firms, the honest answer is no. Google’s framework argues that a logged reasoning trail behind every access decision needs to replace the static permission spreadsheet as the artifact you’d actually pull in testing.

What to actually check

None of this means you need to overhaul your controls environment tomorrow. But it’s worth sitting with four questions:

  • Resource-level check: Is access authorized per action on a specific resource, or just once at the application level? For almost everyone right now, it’s the application level.
  • Static vs. dynamic: Are your rules fixed, or is there any real-time, context-aware reasoning involved? Almost always static today — the question is whether AI itself could help flag and route unusual requests.
  • Ambient authority: Do the agents your people use inherit the full permission set of the person running them, or a narrower subset? For most firms, it’s the full set.
  • Logged reasoning: Could you produce a log right now showing what an agent did and why? Most firms can’t.

You don’t need answers to all four by next week. But as AI tools go from copilots to agents doing real work inside firm systems, these are the questions that are going to come up — in an audit, in a client conversation, or in your own risk assessment. Better to have thought about them now than to be caught flat-footed later.

Key takeaways

  • AI agents operate at roughly 10x human speed, and most monitoring and controls environments were sized for human-speed activity.
  • Ambient authority — agents inheriting a user’s full permission set — is the biggest quiet control gap in most firms today.
  • The evidence standard is shifting from “who approved this role” to “what did this agent touch, on whose behalf, and why was it authorized.”
  • Start by asking whether your access checks happen at the application level or the resource level — that single question tells you how far you have to go.

Want the CPE credit? Take the full lesson on EverydayCPE and earn 0.2 CPE credits: Beyond Zero Trust for AI Agents.

Today’s lesson


Leave a Reply

Discover more from EverydayCPE

Subscribe now to keep reading and get access to the full archive.

Continue reading