Traditional Zero Trust asks systems to avoid granting implicit trust because of network location or asset ownership. Autonomous AI introduces additional boundaries: one agent can delegate to another, select a tool, call an API, act through a service, and affect a digital or physical resource. In that environment, authenticating the first participant does not establish that every downstream action is legitimate. This article develops a public, high-level SGAEIA model for applying Zero Trust to multi-agent systems. It separates identity from authority, capability from permission, delegation from trust propagation, and model reasoning from policy enforcement. It then derives practical architectural questions for continuous authorization, evidence generation, revocation, and operation at the edge. Imagine a human asking Agent A to prepare a customer report. Agent A delegates data retrieval to Agent B. Agent B discovers a file tool, which calls an API, which reaches a service holding both the requested records and unrelated confidential data. Every component may be functioning as designed, and the human may have been authenticated correctly. The security failure appears when that initial authentication is treated as permission for every later choice in the chain. This is the central Zero Trust problem for multi-agent AI. A workflow can begin with a legitimate user, contain individually legitimate components, and still produce an unauthorized outcome because authority was broadened, inherited, or applied outside its original purpose. NIST Zero Trust Architecture rejects implicit trust based solely on network location or asset ownership and treats access as a resource-centered decision informed by identity and policy. NIST SP 800–207A extends that reasoning to cloud-native applications and service identities. [1][2] Autonomous agents make this principle more demanding because they can select actions dynamically. They can plan, delegate, invoke tools, combine context, and continue operating while conditions change. The relevant question is therefore not simply, “Is this an authenticated agent?” It is: Is this specific action, against this specific resource, permitted under the current identity, delegated authority, purpose, policy, time, and context? The thesis of this article is that trust must not propagate merely because agents collaborate. Identity must be explicit, authority bounded, policy externally enforceable, decisions evidenced, and derived authority revocable.
No takes yet. Share an insight, caveat, or question.
Aridio Silva (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: