The zero trust security layer for AI agents

To embed our video on your website copy and paste the code below:

<iframe src="https://www.youtube.com/embed/veCdvtU1cd4?modestbranding=1&rel=0" width="970" height="546" frameborder="0" scrolling="auto" allowfullscreen></iframe>
Guy Daniels, TelecomTV (00:23):
Hello, you're watching the Network APIs and Agents Summit and our programme on the Zero Trust Security Layer for AI agents. I'm Guy Daniels and, as external agents begin to autonomously negotiate network resources, there are huge security implications around agent-to-agent communication. So how should telecom security models evolve, and is Zero Trust architecture now becoming a mandatory requirement for AI-native telecom platforms? Well, I'm delighted to say that joining me on the programme to discuss these issues are Sophie Greaves, who is Associate Director, Digital Infrastructure, for techUK; Scott Cadzow, who is Chair of the ETSI Securing AI Technical Committee; Francis Haysom, Principal Analyst with Appledore Research; and Leonard Lee, Executive Analyst at neXt Curve. Hello, it's good to see you all. Thanks so much for taking part in our discussion today. So let's dive straight in, shall we? I'd like to ask: how do telecom security models need to evolve when, as we've said, autonomous agents begin negotiating for resources directly? Big question, this. Leonard, let me put this straight to you.

(01:40):
Big question, this. Leonard, let me put this straight to you.

Leonard Lee, neXt Curve (01:45):
Well, hey, first I want to thank you for having me. In addressing that question, I think first off, you probably don't want anything that is agentic in your environment before you have some of the safeguards and security capabilities to instil trust in whatever is agentic in your environment. And I think that's really the first principle of arriving at a Zero Trust policy as well as a posture. And so I think one of the challenges right now is identifying what those capabilities are, because a lot of the practices as well as the tooling haven't really come into place yet, because agentic AI in and of itself is still an evolving topic. It's an evolving technology with frameworks and standards that are still in the process of gelling. And so one of the challenges everyone has — and it's not just the telco industry — is figuring out what a safe adoption of agentic AI looks like, and also what are some of those policies for allowing third-party or external agents to have access to your services that are either exposed through APIs or MCP, or what have you.

(03:19):
And so it's a big question. I think it's one of the questions that does need to start having some substantial answers before you consider exposing yourself to the inherent risks related to agentic AI.

Guy Daniels, TelecomTV (03:40):
Great. Thanks very much, Leonard. And as you say, this is an evolving area — it's quite a challenge. I'm going to come to Scott in a moment, but first of all, Francis, what are you seeing? How do you see telecom security models needing to evolve?

Francis Haysom, Appledore Research (03:57):
Well, I think a useful place to start is: where are telecom security models today? I think there are sort of four areas I'd focus on where the problems exist. The first is that telco historically has always been a kind of special case in networking — it has special technology, specialist expertise and so on — but that is increasingly under pressure, and the behaviours within a telco are still based on the idea of a secure castle and moat. That's already been stressed, as it were, but that's a key issue with agents. Suddenly you can't rely on that castle wall any more. The invaders are already inside the castle wall, and so you need to be evolving — and we'll come on to this later — a Zero Trust architecture for what is going on there. I think you've also got the issue that we're still an industry that relies on devices and clear endpoints.

(05:02):
The identity of autonomous agents is a very different thing from the identity of devices, and again, that's a change that needs to be addressed.

(05:12):
Again, most systems in telcos are built on integration — my background is in OSS systems. Typically you're building integrations on the assumption that you're within the castle wall, but even then you're making a very clear contract between two things. Agents, if you want to implement them at their fullest level, need to be far more dynamic, and again you need to deal with that. The other thing is we still rely on the fact that there is a human somewhere checking things. Agents are capable of interacting dynamically, and again that becomes a challenge that we need to address in terms of our security architecture.

Guy Daniels, TelecomTV (05:59):
Great. Thanks so much, Francis. So let's put this to Scott. Scott, what's the industry doing? How do we account for the rising growth of these autonomous agents in terms of security?

Scott Cadzow, ETSI TC Securing AI (06:11):
I think I'm going to be rather more positive about this. I think we've actually been doing this for a long, long time. The telecoms model has changed significantly over the past 15 to 20 years. We are now much more based on virtualisation. We're much more a software-based network. We already have much more in the way of micro-operators providing services. We have much more in the way of over-the-top services. So we've already taken major steps to provide a platform that will allow us to accommodate agentic AI if agentic AI ever becomes dominant. And there is significant risk — these are critical infrastructures; they can't be allowed to run completely without oversight. That's something we need to think about. Also, the Zero Trust model, which we'll talk about in more detail later, is essentially a much more formal way of looking at the two basic principles we have of least persistence and least privilege.

(07:10):
And if you think of how we're doing virtualised networks, virtualisation already moves towards least persistence and operates in a trusted environment. So I think we can be confident that we're going to go in the right direction, because we understand that we are no longer in a telephone world — we're in a connected apps world, a connected services world — and we've already taken huge steps down that path. We'll make more steps; we need to do more, but at least we've begun to recognise that. And I think if you look critically at it, we're not in that bad a shape for where we have to go.

Guy Daniels, TelecomTV (07:48):
Well, that's great to hear, Scott. And as you say, we are in a different world now. So let me come straight back to you with my next question, and that is the way we approach and deal with APIs at the moment. Are static API keys now fundamentally inadequate for a future where we have agent-to-agent telecom environments?

Scott Cadzow, ETSI TC Securing AI (08:08):
The short answer is yes, they're inadequate. We have to think of much more than static analysis. You cannot afford to have fixed links based on day-long contracts; you can't afford fixed contracts during the day. So one thing that we'll see evolve with agentic AI — with much more use of agents, whether they're AI or not — is much more dynamicism. They have to be open to finding services where they need them, rather than just relying on fairly well-established, months-old SLAs tied into a fixed API and a fixed key. That's not going to work. That's not how the world will work. We've already moved away from that largely in the real world of Web 2 and the Semantic Web and all the rest.

(09:03):
The Semantic Web has already gone. We're no longer doing fixed API keys. We're already in a much more dynamic world. The telecoms industry — I won't say it's lagging; it's got a different pace — is paced slightly differently from the computing world and the internet world, but ultimately it underpins the entire connected world. And so it has to make the same advances. So they will abandon anything that's static and move towards a much more dynamic model, but that requires much more dynamic proofs of trust, dynamic proof of who you're talking to — and that's where Zero Trust comes in.

Guy Daniels, TelecomTV (09:36):
Fantastic. Thanks very much, Scott. And Francis, can I come to you as well on this one? Do we need a more dynamic model for these A2A environments?

Francis Haysom, Appledore Research (09:48):
I don't need to add much to Scott's points — the answer is yes, we do. But I think the other important thing, in terms of dynamics, is not just the static relationship but also the ongoing relationship of the data that has been transmitted across it. So we need to be looking not just at how an agent is consuming that data, but at how that agent is protecting that data from onward movement to other agents as you go through that chain. And again, that's not something that's bound up in a static relationship.

Guy Daniels, TelecomTV (10:23):
Thank you very much, Francis. And Sophie, I'll come across to you as well for your thoughts on whether we need to move on from the static to a more dynamic environment.

Sophie Greaves, techUK (10:30):
Yes, thanks, Guy. And if I may just come back on something that Scott said — I think it's a really interesting point in terms of what sets apart the telco model from others, computing being the example mentioned. I think it's the scale of this, in terms of it being such a critical live network, that the opportunity to amend or bring in a new framework is extremely challenging. So we should recognise that challenge. When you're talking about evolution and moving something towards something very dynamic, you're talking about doing that in an environment that, because of its criticality, needs to be always on and needs to serve many people in many places. And that's something that's quite key when we're talking about the new world that may be unlocked by agentic AI.

Guy Daniels, TelecomTV (11:22):
Yes, certainly. Thanks very much for that, Sophie. Well, if we are looking at a more dynamic world, let me just look at our next talking point, which is around how we verify these AI agents. So what does dynamic identity verification for AI agents actually look like in practice, in the real world? Scott, are you working in this area?

Scott Cadzow, ETSI TC Securing AI (11:49):
Yeah, this is kind of core to — in my view — Zero Trust. Essentially, the old models are very static models. You'd build up a relationship, business to business, you'd establish a contract and an SLA that says, "This connection will be available at this time, for this period, at this capacity," and it was set up and then left to run. And that's basically a security nightmare because you don't have IT controls. What we're moving to — and it's something we've been doing in the wider security world for a long time — is looking at much more of a "prove who you are now" model, and I want you to prove it again and again and again. You don't do one-shot authentication any more. You don't do one-off authorisation. And once you go beyond the simple large-scale model you have in traditional telecoms and come on to the service-based architectures we have, the much more dynamic architectures where you're maybe picking up a service in, say, Uzbekistan, connecting it to a service in the US, connecting it to a service somewhere in Europe, all within milliseconds of each other —

(12:58):
and then you're going to tear those down — you can't afford to assume that the previous time you talked to that agent it's the same agent. You've got to recheck it, you've got to come back and retest it. So if I went into the bank and put on a moustache one day and a beard the next, they should ask me every time who I am. They really need to verify my identity. I expect that in my critical interactions with systems. Now expect that of agents — and that's where we have to really push this whole Zero Trust model. I simply will trust no one until I verify them. I'm not going to trust them for very long either, because they're going to change because my connections will change. And so that's where we have to come to.

(13:45):
We've got to look at how we restructure ourselves, based on our trust model, on non-persistent trust. And that's where Zero Trust comes in. Zero Trust is really non-persistent trust and reverification of trust every second, every minute.

Guy Daniels, TelecomTV (14:02):
Excellent. Thanks, Scott. Trust no one until you verify them, and then you keep reverifying. Leonard, let's come across to you next on this question.

Leonard Lee, neXt Curve (14:10):
Yeah. And I think Scott makes a great point there about having the ability to trust an agentic counterpart. One of the challenges with Zero Trust is this: you might be able to trust the identity, but you can't trust the behaviour. I think that's one of the big concerns and frankly a significant challenge, because agents will hallucinate, they'll drift, there may be alignment issues. So being able to monitor the behaviour of agents is another important element to layer on top of existing Zero Trust frameworks. Having that observability to be able to layer on controls, having a system for evaluating agents and their behaviour during development and also when they're in production and affecting your environment — those are things that need to be in place. And going back to my earlier comment, these are things that are in development but will be critical going forward if you want to have trustworthy agentic AI operating in your network or in your operations.

Guy Daniels, TelecomTV (15:54):
Thanks, Leonard. Good point there about behaviour as well. Right. We're going to go around to our other guests as well. Sophie, I think we're going to come to you first, then we'll go to Francis, and we might even finish up with Scott. So let's go to Sophie next.

Sophie Greaves, techUK (16:08):
Yes. Just on this, just following Leonard's point, I think it's really important to bring in the human element to this dynamic identity question — just in terms of how we can consider, at this early stage, where the delegation is. So making that link to what the agent is doing, who gave it that authority, and for whom it's acting, because I think that's the important connection that we need here in terms of evolving these security models towards more intelligent, perhaps Zero Trust, approaches. But essentially, if that behaviour as discussed is permitted, who does that link back to, and who is the delegating authority? So that would be my final thought on that question.

Guy Daniels, TelecomTV (16:53):
Who indeed — a good question. Thanks very much, Sophie. Francis, we'll come to you next.

Francis Haysom, Appledore Research (16:59):
Yeah, it's a slight sidebar conversation here, but I think there's a lot that can be learned from a very similar process that is having to go on at the moment in terms of post-quantum securing of the network. A lot of this is about — as you say — agents being inherently ephemeral and being made massively scalable, which is not quite like human beings and classic system integration. So a lot of the problems of post-quantum are about the lifespan of keys, how often they're updated, how often you're reauthenticating. And I think a lot of the learnings from that can be brought back into this — in terms of simply knowing where a key is being used, what its lifespan is, what its reiteration cycle is — so that you have a view of your network, before you start putting agents on it, as to where the security weaknesses are before you start exposing it to an agent environment.

(17:59):
You may well have some areas that are very compliant; you'll have other areas that are very dangerous in which to deploy agents. And that goes back to Scott's point: you've got things already being deployed well in security, but you've also got a lot of holes left over from the legacy environment.

Guy Daniels, TelecomTV (18:20):
Indeed. Thanks, Francis. Well, let's bring this full circle and go back to Scott. Scott, do you want to wrap up this particular talking point?

Scott Cadzow, ETSI TC Securing AI (18:28):
Yeah, just to clarify a bit. When we talk about identity, we need to be very clear what we mean by identity. One of the things that agents are going to do is to get semantic and contextual knowledge. And what you want to do is not just connect to Scott because he's Scott — you want to connect to Scott because you know he plays tennis fairly well. So you trust him to play tennis, but you don't trust him to play cricket or to do your accounts. Knowing that behavioural capability and limiting the permission — the authority you grant to that agent is really important. So you've got to have not just a nominal identifier, but also the semantic stuff, the contextual stuff, the geographic stuff. So are you trusting it because of where it is?

(19:16):
Is the agent that the client is really at the edge of the network — who attests to that? There's a whole set of capabilities bound into identity which Zero Trust starts to allow you to address, because if you ask the right questions, then you build the trust up and you've got more assurance. And you've essentially got a temporal contract which says, "You agreed to do this for me at this point in time. Once you've done it, we are going to disappear and discard that." That's where the ephemeral capability comes in, because that entity may not exist the next time you try to reach it. So it becomes much more than just an identity you know beforehand. You've got to discover its semantic, contextual and other capabilities before you begin to connect to it and trust it.

Guy Daniels, TelecomTV (20:07):
Great. Thanks very much for elaborating there, Scott. And we've been teasing this for about the past 20 minutes or so. So let's directly address Zero Trust now. Is Zero Trust architecture now becoming a mandatory requirement for AI-native telecom platforms? And if so, how is it being implemented so far? Sophie, do you want to start us off on this question?

Sophie Greaves, techUK (20:33):
Yes, absolutely. Thanks, Guy. It is now a legal duty in the UK at least for telecoms networks to be secure. And indeed, only a few months ago, Ofcom wrote to all operators in scope of the Telecom Security Act to warn against the cyber threat as it relates to frontier AI models. So it's very much not voluntary or an ambition — it's very much a legal duty. And I think it just comes back to that last point that Scott made in terms of attestation, which I think is an excellent point, because so much of how telcos are required to comply with the TSA is around showing their working. So if they say that they have implemented a new process or a new technology into their networks, the regulator is going to want to see the impact of that, how it's working, the timelines as to when it may complete, for instance.

(21:27):
So actually, if we're talking about ephemeral badges of identity, or permissions, or delegations, how are we actually capturing that and showing that information as part of that legal duty that networks will have? And that's another additional, non-technical challenge that I think it's important to talk about as we go to Zero Trust and AI-native telecom platforms, because currently I don't think the AI-native telecoms operation is where we would all like it to be. But as we improve and greater autonomy comes into the networks, we just need to ensure that it's working within the compliance framework — certainly in the UK we have the Telecom Security Act.

Guy Daniels, TelecomTV (22:10):
Sophie, thanks so much indeed. Good update on what's happening in the UK especially. Francis, what are you seeing? What are you hearing? Is Zero Trust now mandatory?

Francis Haysom, Appledore Research (22:22):
I think we're still in an evolving situation. As I say, there are areas of telco that are implementing Zero Trust. There are other areas that are still — and it's a separate subject — but a lot of the issues in terms of just preparing for post-quantum is that many areas in telco simply are not ready for this type of dynamic environment and rapid key transitions, and they're still highly based on static access control. I think the other key point to make about the Zero Trust environment — and Scott really put a key point here — is not just who you are, but what are you doing and why are you doing it? And I think we haven't really discussed this: one of the challenges of AI agents is the potential for insertion of malicious AI code within an agent.

(23:31):
So it's not simply a matter of knowing who you are, but also tracing the evolution of that agent. Has this agent changed since the last time I interacted with it? And I think we're a little way away from that at the moment, but we need to be aware — just in terms of the cybersecurity area — that the agent I'm talking to now, yes, they are the right role, this is the right access that they require, but also: do I trust that they haven't changed in some way? Am I aware of whether they've changed in that environment?

Guy Daniels, TelecomTV (24:05):
Yes. Thanks very much, Francis. And we can't afford to be behind on this, can we? It's so critical. Scott, can I bring this back to you and your thoughts on the state of Zero Trust as the whole industry seems to be converging on an AI-native evolution path?

Scott Cadzow, ETSI TC Securing AI (24:23):
Yeah. Well, I think the first obvious question is: is it mandatory? And the answer is no. And the reason it's no is because we've got so many other things to do. It's a really good shortcut because it forces you to think about things. One of the things we did in ETSI, we prepared something called the ZT Kipling Method, and the Kipling method is basically asking Kipling's questions: who, what, why, where, when and how are you connecting to something? So why are you using that thing? When are you using it? Where are you using it? What are you using it for? How are you using it? All those things — if you ask them of everything you connect to — will give you knowledge that builds up your trust. So that gives you your behavioural picture, gives you your contextual knowledge, it'll give you the limitations of what it can and cannot do,

(25:11):
it'll give you an idea of who it's trusted by, where this agent or piece of software comes from. So you've got that provenance that you can bring into trust. And once you add all that together, you start to get to the point where, for this period in time, for this particular action, I can trust you. But then we have wider challenges. The point about the UK's Telecom Security Act — a lot of that is about proof and how you develop that proof. So how do we build in repudiation and non-repudiation services that are lightweight enough to make the system work at the speeds it's going to operate at, with the massive dynamicism of these agents? These are going to be ephemeral for maybe milliseconds or microseconds — and how do you gather proof for that to make it work? That's our challenge. So Zero Trust is not going to be mandatory, but it is probably the most mature approach we have to making a better understanding of the network we're connecting to, the devices we're connected to, the agents we're connecting to, to make them possibly secure.

(26:18):
But we're not going to give you a guarantee of security — that will not work simply because these are evolving areas and we've got the post-quantum problem, which has been nicely pointed out by Francis. We've also got other issues — just the scale. We have no clear idea of how big the scale is. We already have, what, 20 billion, 100 billion devices on the network. With agentic AI, that'll move into the trillions of agents, trillions of entities in the network that we have to trust at any one point in time. The scale is beyond our imagination just now, and that's where we're going to have a problem. So Zero Trust will give us a hint as to what we can trust; understanding the scaling problem and understanding the ephemeral issues will give us the next dimension, which is the important one.

Guy Daniels, TelecomTV (27:08):
Great. Thanks very much, Scott. And I do think the vast scale of agents and the ephemeral nature of them are a couple of major points that haven't really been fully acknowledged yet and that we need to make more of. Francis, I'll come across to you on what's going to be our final question for this particular programme.

Francis Haysom, Appledore Research (27:27):
Yeah, just to come back on a key point that Sophie made, and backed up by Scott: we can't assume that we can make all of our network ready and compliant for agents immediately. A lot of this will be about understanding where we can introduce them. And also I think a word that we haven't actually talked about a lot, but it's risk — what is the risk versus the reward? There will be areas where we can have a high reward and a low risk, where it's very obvious to put agents in. And coming back to Scott's point about who, what, why and the rest of it: we need an understanding of where we're strong — maybe with Zero Trust, maybe with something else as well — and that's where we can introduce agentic AI safely. And we need to know where we're weak, and understand that, and either address that within the system that we're integrating with, or we need to back away from it — recognising that this is too much risk in terms of putting that type of engagement on to that system.

Guy Daniels, TelecomTV (28:39):
Great. Well, this has been a fantastic discussion, but we do have to leave it there for now — that's all the time we have. Hopefully we'll pick up this conversation thread later on, but thank you so much for taking part in the programme today. If you're watching this live as part of our Network APIs and Agents Summit, then please stay with us because we have our live wrap-up show coming next, so don't go away. If you are watching this on demand, you'll find links to the other programmes on the summit homepage on TelecomTV. For now though, thank you for watching, and goodbye.

Please note that video transcripts are provided for reference only – content may vary from the published video or contain inaccuracies.

Panel discussion

Examining how dynamic AI agents challenge legacy security, techUK’s Sophie Greaves, ETSI’s Scott Cadzow, Appledore’s Francis Haysom and neXt Curve’s Leonard Lee argue that identity verification, behavioural monitoring, and ephemeral trust contracts must replace static defences. The panel addresses UK Telecommunications Security Act compliance, post-quantum parallels and malicious code risks, and note the massive architectural hurdle of scaling zero-trust across trillions of network entities.

Broadcast Live July 2026

Participants

Francis Haysom

Principal Analyst, Appledore Research

Leonard Lee

Managing Director, neXt Curve

Scott Cadzow

Chair of ETSI TC Securing AI (ETSI TC SAI)

Sophie Greaves

Associate Director, Digital Infrastructure, techUK