Randomized trial demonstrates enhanced security in multi-cloud AI workloads, indicating reliability in identity verification.
AI workloads increasingly span multiple clouds — training on one provider, serving on another, drawing data from several — dissolving the network perimeter on which traditional security relied and multiplying non-human identities. Zero-trust architecture (ZTA), codified in NIST SP 800-207 and extended for multi-cloud, cloud-native settings in SP 800-207A, answers this by removing implicit trust and verifying every request from identity and context. This paper specializes ZTA for multi-cloud AI workloads. We extend the notion of identity beyond users and generic workloads to AI-specific artifacts — model identity (bound to weight hashes and provenance), dataset identity (lineage and integrity), pipeline identity (via SPIFFE workload attestation), and environment identity — and map zero-trust controls onto the AI lifecycle attack surface (data poisoning, pipeline compromise, model tampering and theft, and inference manipulation including prompt injection). We present a reference architecture in which a policy decision point authorizes every request per session, a policy enforcement point (sidecar/gateway with mutual TLS) enforces it, and a SPIFFE/SPIRE identity fabric federates workload identity across cloud trust domains without long-lived secrets. We formalize the access decision, a quantitative trust score, and a blast-radius (lateral-movement) reduction model, and discuss maturity across the seven zero-trust pillars. Public sources are cited throughout.
No takes yet. Share an insight, caveat, or question.
Sushma Sunkollu Nagaraj (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: