Guide | The Case for Al Zero Trust

Guide | The Case for Al Zero Trust

Discover why traditional security models fall short in the age of AI. This guide explores AI Zero Trust, outlining strategies to secure AI agents, models, and enterprise networks while reducing cyber risk and limiting attack impact.

Guide | The Case for Al Zero Trust

AI

Zero Trust

The Case for AI Zero Trust

A Security Leader's Guide to AI-Native Trust Enforcement

For CTOs, CISOs, and Enterprise Security ArchitectsFor CTOs, CISOs, and Enterprise Security Architects

AI Zero Trust

The Case for AI Zero Trust

A Security Leader's Guide to AI-Native Trust Enforcement

The Case for AI Zero Trust 2

1. Exec Summary: A Changed Threat Landscape The threat environment has shifted. The capabilities demonstrated by Anthropic's Claude Mythos mark a step-change in the offensive use of AI. This was the first frontier model to be classified as a national security risk and raised major concerns for having "crossed the AI cyber security Rubicon”. Attackers now discover vulnerabilities faster than defenders can patch them, executing multi-stage attacks at machine speed. They can penetrate environments to depths that previously required skilled human operators. Consequently, the window between vulnerability exposure and business disruption has permanently shrunk from weeks to minutes.

At the same time, a new attack surface is emerging. AI agents, large language models, and the infrastructure that powers them introduce risks that exist in the context and intent of a request, not its port or protocol — the layer that conventional network controls were never built to inspect. A compromised agent, for example, can execute in seconds what once required months of human effort. This changes not only how we secure networks, but how we protect the business they support.

Traditional Security asks: "Who sent this, and where is it going?"

AI Zero Trust adds: "What is this actually saying, and what does it intend to do?"

The attack isn't in the envelope—it's in the meaning.

AI Zero Trust stops attacks like prompt injections by analyzing the context of the data.

Zero Trust remains the right security model for this environment. Its three principles—never trust, always verify; least privilege access; and assume breach—remain correct. The assume-breach approach takes on particular importance in the Mythos era, because compromise has shifted from possible to probable. The architecture must now be designed around that reality rather than treating breach as an edge case.

Under a Zero Trust posture, every defensive decision resolves to three operational objectives:

reduce the attack surface and the exposure of critical assets,

minimize the impact and blast radius of any successful compromise; and react,

mitigate and recover fast.

Based on today’s realities, there is a clear mandate to expand Zero Trust to AI Zero Trust by defining explicit new trust zones for AI gateways, model environments living in private AI factories, AI agents and users, and MCP-connected services. These new zones must be protected not only by conventional network controls, but by AI-native enforcement technologies designed for the unique risks created by AI interactions, autonomous actions, and model-driven workflows.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

1. Exec Summary: A Changed Threat Landscape

The threat environment has shifted. The capabilities demonstrated by Anthropic's Claude Mythos mark a

step-change in the offensive use of AI. This was the first frontier model to be classified as a national security risk and raised major concerns for having "crossed the AI cyber security Rubicon”.

Attackers now discover vulnerabilities faster than defenders can patch them, executing multi-stage

attacks at machine speed. They can penetrate environments to depths that previously required skilled human operators. Consequently, the window between vulnerability exposure and business

disruption has permanently shrunk from weeks to minutes.

At the same time, a new attack surface is emerging. AI agents, large language models, and the

infrastructure that powers them introduce risks that exist in the context and intent of a request, not its port or protocol — the layer that conventional network controls were never built to inspect. A compromised agent, for example, can execute in seconds what once required months of human

effort. This changes not only how we secure networks, but how we protect the business they support.

Zero Trust remains the right security model for this environment. Its three principles—never trust, always verify; least privilege access; and assume breach—remain correct. The assume-breach approach takes on particular importance in the Mythos era, because compromise has

shifted from possible to probable. The architecture must now be designed around that reality rather than treating breach as an edge case.

Under a Zero Trust posture, every defensive decision resolves to three operational objectives:

reduce the attack surface and the exposure of critical assets, minimize the impact and blast radius of any successful compromise; and react, mitigate and recover fast.

Based on today’s realities, there is a clear mandate to expand Zero Trust to AI Zero Trust by defining explicit new trust zones for AI gateways, model environments living in private AI factories, AI agents and users, and MCP-connected services. These new zones must be protected not only by conventional network controls, but by AI-native enforcement technologies designed for the unique risks created by AI interactions, autonomous actions, and model-driven workflows.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

Traditional Security asks: "Who sent this, and where is it going?"

AI Zero Trust adds: "What is this actually saying, and what does it intend to do?"

The attack isn't in the envelope—it's in the meaning.

AI Zero Trust stops attacks like prompt injections by analyzing the context of the data.

The Case for AI Zero Trust 2

The Case for AI Zero Trust

In this architecture, AI Zero Trust is enforced through two new strategic control points:
 the AI Network Firewall and the Secure LLM Gateway.

3

AI Network Firewall Secure LLM Gateway

Extends the role of the traditional NGFW by adding AI-aware inspection and segmentation capabilities, including prompt-injection detection, and policy enforcement between users, agents, models, and sensitive enterprise systems.

Acts as the dedicated control point for AI and model interactions, providing secure LLM routing, prompt defense, content and policy inspection, and governance over how AI applications and agents connect to internal and external models.

Together, these controls reduce attack surface, contain blast radius, and help protect the enterprise

against both conventional network threats and emerging AI-driven attacks.

AI Network Firewall: On-Premise, in the Cloud, & Virtual

AI Frontier Model

OpenAI

AI Agents & Users

Users

GenAI applications

Agents

MCP clients

LLM API call

Data Traffic

AI network Firewall

AI Prompt Defense

AI Application Traffic Inspection (NGFW)

Agentic AI & RAG access control

Management plane & observability

Secured Validated Prompts

LLM API Call

AI Factory

LLM workloads

GPU servers

Data Center

IT systems

MCP servers

Practically speaking, the AI Network Firewall acts like a circuit breaker for semantic and data traffic. For example, it enforces your security policy for communication between AI agents, LLMs, and your core enterprise applications. This is a key capability introduced with Check Point's R82.20 software release which enables critical AI security measures.

The AI Firewall is the Central enforcement layer for Prompt protection, AI-Enabled Application traffic inspection, Access control for RAGs & Agentic AI security, telemetry, and Management, enabling safer enterprise AI adoption.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 3

Together, these controls reduce attack surface, contain blast radius, and help protect the enterprise

against both conventional network threats and emerging AI-driven attacks.

Practically speaking, the AI Network Firewall acts like a circuit breaker for semantic and data traffic. For example, it enforces your security policy for communication between AI agents, LLMs, and

your core enterprise applications. This is a key capability introduced with Check Point's R82.20 software release which enables critical AI security measures.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

In this architecture, AI Zero Trust is enforced through two new strategic control points:

the AI Network Firewall and the Secure LLM Gateway.

AI Network Firewall

Extends the role of the traditional NGFW by

adding AI-aware inspection and

segmentation capabilities, including

prompt-injection detection, and policy

enforcement between users, agents,

models, and sensitive enterprise systems.

Secure LLM Gateway

Acts as the dedicated control point for AI and model interactions, providing secure LLM routing, prompt defense, content and policy inspection, and governance over how AI applications and agents connect to internal and external models.

AI Network Firewall: On-Premise, in the Cloud, & Virtual

The AI Firewall is the Central enforcement layer for Prompt protection, AI-Enabled Application

traffic inspection, Access control for RAGs & Agentic AI security, telemetry, and Management, enabling

safer enterprise AI adoption.

AI Agents & Users

Users

GenAI applications

Agents

MCP clients

LLM API call

Data Traffic

Secured Validated Prompts

LLM API Call

AI network Firewall

AI Prompt Defense

AI Application Traffic Inspection (NGFW)

Agentic AI & RAG access control

Management plane & observability

AI Factory

LLM workloads

GPU servers

Data Center

IT systems

MCP servers

AI Frontier Model

OpenAI

The Case for AI Zero Trust 4

2.  AI Zero Trust Principals Zero Trust is the established architectural principle of our time, well known and respected as a cornerstone of cyber security architecture, consequently we should not abandon it as a core security principle but update it to reflect the changes brought about by AI transformation We propose an expand model that reflects a new class of assets, a new set of interactions, and a new range of attack paths. The logic is the same; the surface it must govern is not.

The standard Zero Trust model of today is built on three core principles — never trust, always verify; least privilege access; assume breach — which remain correct. In the expanded AI Zero Trust model, developed for AI ecosystems, what changes is the weight each principle carries. ‘Assume breach’ takes a more central role; compromise has shifted from possible to probable, and the architecture must be built around that reality.

Principle What it requires in the AI era

Never trust, always verify No user, prompt, model output, or agent action is trusted by

default. Every access request is authenticated, every boundary

crossing is inspected, every AI interaction is verified against policy

before it proceeds.

Least privilege access Every agent, model, and tool operates with the narrowest

permission set that allows it to function. Action scope is declared

explicitly and enforced at runtime. No AI component inherits the

permissions of the user who triggered it.

Architecture is built on the assumption that compromise will occur.

Every boundary is an enforcement point designed to contain blast

radius. Every critical path is monitored so compromise is detected

in minutes, not months.

Why Zero Trust Must Expand to AI

Legacy Zero Trust checks AI Zero Trust adds

Who is this user or system? What is this prompt actually asking for?

Is this the right port, right protocol? Is this content trying to manipulate the model?

Does the signature match a known threat? Does the meaning carry a hidden instruction?

Assume breach

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 4

Principle What it requires in the AI era

Never trust, always verify No user, prompt, model output, or agent action is trusted by default. Every access request is authenticated, every boundary crossing is inspected, every AI interaction is verified against policy before it proceeds.

Least privilege access Every agent, model, and tool operates with the narrowest permission set that allows it to function. Action scope is declared explicitly and enforced at runtime. No AI component inherits the permissions of the user who triggered it.

Assume breach Architecture is built on the assumption that compromise will occur. Every boundary is an enforcement point designed to contain blast radius. Every critical path is monitored so compromise is detected in minutes, not months.

Legacy Zero Trust checks AI Zero Trust adds

Who is this user or system? What is this prompt actually asking for?

Is this the right port, right protocol? Is this content trying to manipulate the model?

Does the signature match a known threat? Does the meaning carry a hidden instruction?

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

2. AI Zero Trust Principals

Zero Trust is the established architectural principle of our time, well known and respected as a

cornerstone of cyber security architecture, consequently we should not abandon it as a core security

principle but update it to reflect the changes brought about by AI transformation We propose an

expand model that reflects a new class of assets, a new set of interactions, and a new range of attack

paths. The logic is the same; the surface it must govern is not.

The standard Zero Trust model of today is built on three core principles — never trust, always verify; least privilege access; assume breach — which remain correct. In the expanded AI Zero Trust

model, developed for AI ecosystems, what changes is the weight each principle carries. ‘Assume breach’

takes a more central role; compromise has shifted from possible to probable, and the architecture must

be built around that reality.

Why Zero Trust Must Expand to AI

The Case for AI Zero Trust 5

AI Zero Trust Principles - Mapped to Check Point Solutions

AI Zero Trust

Principle

What it means for AI security Check Point products & capabilities

01

Never trust prompts, outputs, or identities

Every prompt, retrieved document, model response, user identity, and agent request must be inspected before it crosses an AI trust boundary.

Prompt Defense

AI Network Firewall

Secure LLM Gateway

WAF / API Security

Workforce AI Security

02

Enforce least privilege for agents and tools

AI agents should not inherit broad user permissions. Every API call, MCP tool use, write action, and data request must be scoped and authorized at runtime.

AI Agent Securit y

AI Network Firewall

MCP / Tool Inspection

ZTNA / SASE

Microsegmentation

03

Assume breach and contain blast radius

Any AI component, prompt path, agent, gateway, or model zone may be compromised. The architecture must segment AI zones and enforce prevention at each transition.

Secure LLM Gatewa y

AI Network Firewall

AI Factory Firewall

Maestro Hyperscale

Cloud Security

04

Continuously validate and recover fast

AI systems must undergo continuous vulnerability testing including across live attack paths, prompts, reasoning chains, RAG content, tool calls, model behavior, and abnormal activity

AI Red Teamin g

ThreatCloud AI

Exposure Management

AI-Ops & Telemetry

Each principle has its own unique business implication; the chart shows how Check Point closes the gap.

Key message: The same Zero Trust logic is expanded to AI Zero Trust, for new assets and new enforcement points — all from one platform.

The central argument:

AI Zero Trust is the policy logic. Segmentation is the enforcement architecture. Both remain right for the AI era — but new segments are required to govern a threat surface that conventional networks did not contain. Same principles, new assets, new zones, new controls.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 5

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

01

Never trust

prompts, outputs, or identities

AI Zero Trust

Principle

02 Enforce least

privilege for agents and tools

03 Assume breach and contain blast radius

04

Continuously validate and recover fast

Every prompt, retrieved document, model response, user identity, and agent request must be inspected before it crosses an AI trust boundary.

What it means for AI security

AI agents should not inherit broad user permissions. Every API call, MCP tool use, write action, and data request must be scoped and authorized at runtime.

Any AI component, prompt path, agent, gateway, or model zone may be compromised. The architecture must segment AI zones and enforce prevention at each transition.

AI systems must undergo continuous vulnerability testing including across live attack paths, prompts, reasoning chains, RAG content, tool calls, model behavior, and abnormal activity

Prompt Defense AI Network Firewall

Secure LLM Gateway WAF / API Security

Check Point products & capabilities

AI Agent Security AI Network Firewall

MCP / Tool Inspection

ZTNA / SASE

Secure LLM Gateway AI Network Firewall

AI Factory Firewall Maestro Hyperscale Cloud Security

AI Red Teaming ThreatCloud AI

Exposure Management AI-Ops & Telemetry

The central argument:

AI Zero Trust is the policy logic. Segmentation is the enforcement architecture. Both remain right for the AI era —

but new segments are required to govern a threat surface that conventional networks did not contain. Same

principles, new assets, new zones, new controls.

Each principle has its own unique business implication; the chart shows how Check Point closes the gap.

Key message: The same Zero Trust logic is expanded to AI Zero Trust, for new assets and new

enforcement points — all from one platform.

AI Zero Trust Principles - Mapped to Check Point Solutions

The Case for AI Zero Trust 6

3.  Defining Segmentation and Ownership  If AI Zero Trust is our conceptual model for AI security, then segmentation is the mechanism by which those objectives become an enforceable architecture. Before we look at how the AI ZT principles impact our architecture it is important to first define what we mean by segmentation. Segmentation is the mechanism by which Zero Trust principles become enforceable architecture. It operates at three levels, each with a different set of attributes, and conflating them is the most common cause of confusion when a segmentation project hits the real world, which is why defining them in terms of ownership and function is an important step. Each level answers a different question, has a different owner, and requires a different implementation timeline. All three are required for an AI-enabled enterprise, however for network and security team's macro segmentation often has the highest technical and security value.

Macro-Segmentation Micro-Segmentation Nano-Segmentation

Owned by Network & Security

teams

Application & Business

teams

AI/ML engineering &

DevOps teams

Traffic direction North-south, east-

west: between zones

and workload groups

Within zones, segments, and Kubernetes namespaces

Within Kubernetes, between pods and containers

Primary goal Minimize breach blast

radius at the network

layer

Prevent lateral movement between application components (Web, App, DB)

Prevent malware spread inside an application group of servers

Implementation Firewalls, API / AI

gateways, AI Firewall

Agent installed on each server / VM and application-centric access control — SDN / Cisco ACI

Container Network Interface (CNI)

access control

Macro-segmentation protects workload groups from each other. Micro-segmentation protects components within a workload from one another. Nano-segmentation governs what an individual AI process is permitted to do at the instruction level — which APIs it may call, which data it may read, which actions it may take.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 6

Macro-Segmentation Micro-Segmentation Nano-Segmentation

Owned by Network & Security teams

Application & Business teams AI/ML engineering &

Traffic direction North-south, east- west: between zones

and workload groups

Within zones, segments, and Kubernetes

namespaces

Within Kubernetes,

between pods and containers

Primary goal Minimize breach blast radius at the network

layer

Prevent lateral movement between

application components (Web, App, DB)

Prevent malware

spread inside an application group of servers

Implementation Firewalls, API / AI

gateways, AI Firewall Agent installed on each server / VM and

application-centric access control — SDN / Cisco ACI

Container Network

Interface (CNI) access control

Macro-segmentation protects workload groups from each other. Micro-segmentation protects

components within a workload from one another. Nano-segmentation governs what an individual AI

process is permitted to do at the instruction level — which APIs it may call, which data it may read, which actions it may take.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

3. Defining Segmentation and Ownership

If AI Zero Trust is our conceptual model for AI security, then segmentation is the mechanism by which

those objectives become an enforceable architecture. Before we look at how the AI ZT principles

impact our architecture it is important to first define what we mean by segmentation. Segmentation is

the mechanism by which Zero Trust principles become enforceable architecture. It operates at three

levels, each with a different set of attributes, and conflating them is the most common cause of confusion when a segmentation project hits the real world, which is why defining them in terms

of ownership and function is an important step. Each level answers a different question, has a different owner, and requires a different implementation timeline. All three are required for an AI-enabled enterprise, however for network and security team's macro segmentation often has the

highest technical and security value.

The Case for AI Zero Trust 7

Macrosegment Zone Interconnection Point

Ingress Egress

North-South

Workloads Workloads

Traditional Perimeter Firewall

Microsegment Microsegment

Subnet B

Microsegment

Workloads Workloads

Subnet A

East-West

Using a Network/Cloud Fabric or Agents in the EndPoint

Nano segment

Backend

East

West APIGateway

UtilitiesFrontend

Zone Interconnection Point Zone Interconnection Point

Cloud Native Networking

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

Workloads

<API>

The Case for AI Zero Trust 7

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

Zone Interconnection PointMacrosegment

Traditional Perimeter Firewall

North-South

Workloads

Ingress Egress

Workloads

Workloads Workloads

East-West

Microsegment

Microsegment

Subnet A

Subnet B

Using a Network/Cloud Fabric or Agents in the EndPoint

Zone Interconnection Point Zone Interconnection Point

Cloud Native Networking

Workloads

<API>

East

West APIGateway

Frontend Utilities

Backend

Microsegment

Nano segment

The Case for AI Zero Trust 8

Why nano-segmentation matters for AI

For any organization running AI agents in production, the absence of nano-segmentation means there is no enforceable limit on what a compromised or manipulated agent can do once it has been granted its initial access. Macro and micro controls contain the zone and the application. Nano controls contain the agent itself.

4. Segmentation and the AI Trust Boundary At the network security level, the mechanism of Zero Trust enforcement is macro-segmentation, in practical terms this allows the division of the enterprise network and the AI ecosystem into zones, each containing workloads of a similar trust level, with controlled traffic between them. Within a trust zone more granular levels of access can be enforced using micro and nano segmentation. For the purposes of this design pattern the macro boundary is a chokepoint between zones of trust  so it's the natural place to apply threat prevention, within a zone the micro and macro security functions reduce the paths between assets of the same trust.

In our model, we define the AI trust boundary as that which sites between trust zones, as this is where we will apply threat prevention capabilities, however we can still enforce segment inside the trust zone, so that traffic between assets is visible and can be subjected to enforcement.

What is important is that trust boundaries and microsegment must be enforced by a security function capable of inspecting and authorizing the traffic that crosses it and that as traffic types change so too should the enforcement capability.

Core principle

A macro-segment boundary is a trust boundary.  Every trust boundary must be enforced by a security function. Macro- segmentation contains a breach between zones, micro-segmentation contains it within one — between the individual components of a single application.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 8

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

4. Segmentation and the AI Trust Boundary

At the network security level, the mechanism of Zero Trust enforcement is macro-segmentation, in

practical terms this allows the division of the enterprise network and the AI ecosystem into zones, each containing workloads of a similar trust level, with controlled traffic between them. Within a trust zone more granular levels of access can be enforced using micro and nano segmentation. For the purposes of this design pattern the macro boundary is a chokepoint between zones

of trust so it's the natural place to apply threat prevention, within a zone the micro and macro security functions reduce the paths between assets of the same trust.

In our model, we define the AI trust boundary as that which sites between trust zones, as this is where

we will apply threat prevention capabilities, however we can still enforce segment inside the trust zone,

so that traffic between assets is visible and can be subjected to enforcement.

What is important is that trust boundaries and microsegment must be enforced by a security function

capable of inspecting and authorizing the traffic that crosses it and that as traffic types change so too should the enforcement capability.

Core principle

A macro-segment boundary is a trust boundary. Every trust boundary must be enforced by a security function.

Macro-segmentation contains a breach between zones, micro-segmentation contains it within one — between the

individual components of a single application.

Why nano-segmentation matters for AI

For any organization running AI agents in production, the absence of nano-segmentation means there is no

enforceable limit on what a compromised or manipulated agent can do once it has been granted its initial access.

Macro and micro controls contain the zone and the application. Nano controls contain the agent itself.

The Case for AI Zero Trust 9

AI Security Functions to enforce macro and micro segmentation.

For conventional enterprise traffic the enforcement function is a next-generation firewall or an authenticating proxy. These controls inspect packet headers, identify applications, apply IPS signatures, and decrypt TLS where policy permits. They are the right tool for traffic whose threats are structural — known exploits, protocol abuse, credential theft.

AI traffic is fundamentally different and so are the “payloads” that can make it malicious. For example, a natural-language prompt carrying an injection payload traveling inside a well-formed HTTPS request will be permitted by a conventional firewall. AI attacks are semantic, and not structural, they are embedded in the meaning of the content, not its format. Where an AI workload sits at a trust boundary, the enforcement function must operate at the semantic layer.

Traffic type Enforcement function Security Capability

General network

traffic

AI Network Firewall, NGFW, SASE, cloud proxy

Layers 3–7, application identity, IPS signatures, TLS inspection

Web & API traffic Web Application Firewall (WAF) / API proxy

HTTP/S, injection attacks, authentication, rate limits

Intra-zone traffic (Micro segmentation)

Container, virtual machine security agent, for example Illumio

access control (lateral-movement prevention)

AI model traffic Secure LLM Gateway with AI-aware policy, Prompt Injection (AI) Firewall

Prompts exchanged with foundation models and carrying semantic meaning and user intent.

MCP Traffic Secure LLM Gateway and/or AI Network firewall

Client-to-server exchanges invoking tools, reading resources, and passing context between MCP hosts and servers.

Agentic Traffic AI Firewall, endpoint agent

Autonomous agent actions that read, write, or modify data and chain tool calls across systems on a user's behalf.

Key Point

Each function above is a Policy Enforcement Point. The first two are well-established. The bottom three are unique to AI networks — and most enterprises haven't built them yet, which means the trust boundaries don't exist either.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 9

Traffic type Enforcement function Security Capability

General network traffic

AI Network Firewall, NGFW, SASE, cloud proxy

Layers 3–7, application identity, IPS signatures, TLS inspection

Web & API traffic Web Application Firewall (WAF) / API proxy

HTTP/S, injection attacks, authentication, rate limits

AI model traffic Secure LLM Gateway with AI-aware

policy, Prompt Injection (AI) Firewall

Prompts exchanged with foundation models and carrying semantic meaning and user intent.

Intra-zone traffic

(Micro segmentation)

Container, virtual machine security agent, for example Illumio

access control (lateral-movement prevention)

MCP Traffic Secure LLM Gateway and/or AI

Network firewall

Client-to-server exchanges invoking tools, reading resources, and passing context between MCP hosts and servers.

Agentic Traffic AI Firewall, endpoint agent

Autonomous agent actions that read, write, or modify data and chain tool calls across systems on a user's behalf.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

AI Security Functions to enforce macro and micro segmentation.

For conventional enterprise traffic the enforcement function is a next-generation firewall or an

authenticating proxy. These controls inspect packet headers, identify applications, apply IPS

signatures, and decrypt TLS where policy permits. They are the right tool for traffic whose threats are

structural — known exploits, protocol abuse, credential theft.

AI traffic is fundamentally different and so are the “payloads” that can make it malicious. For example, a natural-language prompt carrying an injection payload traveling inside a well-formed HTTPS

request will be permitted by a conventional firewall. AI attacks are semantic, and not structural, they are embedded in the meaning of the content, not its format. Where an AI workload sits at

a trust boundary, the enforcement function must operate at the semantic layer.

Key Point

Each function above is a Policy Enforcement Point. The first two are well-established. The bottom three are unique

to AI networks — and most enterprises haven't built them yet, which means the trust boundaries don't exist either.

The Case for AI Zero Trust 10

5.  Practical Implementation: The Five-Zone Topology The conventional three or four zone model — perimeter, DMZ, internal, and restricted — was sufficient for networks of conventional applications operated by human users. It does not describe an AI-driven agentic enterprise. Two new zones are required, each carrying trust characteristics that conventional zone classifications were never designed to handle. The diagram below places the new AI components alongside conventional assets and shows which controls must enforce each zone boundary.

New AI Zones

Zone 1:

Users & Perimeter

Zone 2:

Applications & Frontend

Zone 3:

AI Orchestration & Models

Zone 4:

AI Agents

Zone 5:

Tools, Data & Core Systems

Assets protected Assets protected Assets protected Assets protected Assets protected

Employees

External Users

Web Apps

Chatbots

Private LLMs

Public LLMs

AI Agents

Agent Workflows

MCP Servers

Business Tools

AI Workspaces / Public AI Copilots

AI Applications

AI Factory /
 GPU Infrastructure

Autonomous Tasks APIs

Databases

Core Apps

Primary security controls Primary security controls Primary security controls Primary security controls Primary security controls

AI Network Firewall

WAF / API Security

AI Firewall

API Protection

Secure LLM Gateway *

AI Network Firewall *

AI Network Firewall

Agent Identity Awareness

AI Network Firewall

MCP / Tool Inspection

Anti-Bot & DDoS Application Inspection Model Routing & Policy Behavior Monitoring Access Control

Shadow AI Discovery Prompt Inspection DLP / Content Controls Least-Privilege Access Segmentation

Micro-Segmentation DLP

* Prompt Defense

Figure 1  |  The five-zone AI Zero Trust topology. Each zone contains the assets it protects and the primary security controls that enforce its boundary.

*Zones 3 and 4 are new — and they must be explicitly created

An organization that deploys AI workloads without establishing Zones 3 and 4 as discrete trust domains has, in effect, created a direct path from untrusted external input to privileged internal systems. The boundary between Zone 2 and Zone 3 can only be meaningfully enforced by an AI-aware gateway capable of inspecting prompt content. The greater exposure in practice is indirect — adversarial instructions embedded in retrieved content — so enforcement at this boundary must inspect both retrieved and tool-returned content, not only end-user prompts.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 10

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

5. Practical Implementation: The Five-Zone Topology

The conventional three or four zone model — perimeter, DMZ, internal, and restricted — was sufficient

for networks of conventional applications operated by human users. It does not describe an AI-driven

agentic enterprise. Two new zones are required, each carrying trust characteristics that conventional zone classifications were never designed to handle. The diagram below places the new AI

components alongside conventional assets and shows which controls must enforce each zone boundary.

New AI Zones

Figure 1 | The five-zone AI Zero Trust topology. Each zone contains the assets it protects and the

primary security controls that enforce its boundary.

*Zones 3 and 4 are new — and they must be explicitly created

An organization that deploys AI workloads without establishing Zones 3 and 4 as discrete trust domains has, in

effect, created a direct path from untrusted external input to privileged internal systems. The boundary between

Zone 2 and Zone 3 can only be meaningfully enforced by an AI-aware gateway capable of inspecting prompt content.

The greater exposure in practice is indirect — adversarial instructions embedded in retrieved content — so

enforcement at this boundary must inspect both retrieved and tool-returned content, not only end-user prompts.

Zone 2:

Applications & Frontend

Zone 3:

AI Orchestration & Models

Zone 4:

AI Agents

Zone 5:

Tools, Data & Core Systems

Zone 1:

Users & Perimeter

Assets protected

Primary security controls

Employees

External Users

AI Workspaces / Public AI

AI Network Firewall

WAF / API Security

Anti-Bot & DDoS

Shadow AI Discovery

Assets protected

Primary security controls

Web Apps

Chatbots

Copilots

AI Applications

AI Firewall

API Protection

Application Inspection

Prompt Inspection

Assets protected

Primary security controls

Private LLMs

Public LLMs

AI Factory /

Secure LLM Gateway *

AI Network Firewall *

Model Routing & Policy

DLP / Content Controls

Assets protected

Primary security controls

AI Agents

Agent Workflows

Autonomous Tasks

AI Network Firewall

Agent Identity Awareness

Behavior Monitoring

Least-Privilege Access

Micro-Segmentation

Assets protected

Primary security controls

MCP Servers

Business Tools

APIs

Databases

Core Apps

AI Network Firewall

MCP / Tool Inspection

Access Control

Segmentation

DLP

* Prompt Defense

The Case for AI Zero Trust 11

AI Trust Zone Transitions

AI ecosystems are complex, with multiple new connections per asset. Securing that complexity requires architects and engineers to identify every point at which traffic crosses a trust boundary — a trust transition.

The table below shows where the most relevant OWASP LLM and Agentic risks arise across these transitions and which controls should be enforced at each boundary. It turns AI risk from a conceptual discussion into an actionable architecture view — showing security and enterprise teams where AI- specific controls (AI Firewall, AI Secured Gateway, prompt defense, agent controls, MCP inspection) must be applied first.

Zones / Trust

transition

OWASP LLM Risks OWASP Agentic Risks

Zone 1 → 2

Users to frontend

LLM01 Prompt Injection;

LLM04 Model Denial of Service; LLM09 Overreliance

ASI01 Agent Goal Hijack (indirect, seeded at input); ASI09 Human-Agent Trust Exploitation

Zone 2 → 3 Applications to orchestration

LLM01 Prompt Injection;

LLM06 Sensitive Information Disclosure; LLM04 Model Denial of Service; LLM10 Model Theft

ASI01 Agent Goal Hijack; ASI03 Identity & Privilege Abuse

Inside Zone 3 LLM03 Training Data Poisoning; LLM05 Supply Chain Vulnerabilities; LLM10 Model Theft; LLM06 Sensitive

Information Disclosure

ASI04 Agentic Supply Chain Compromise; ASI06 Memory & Context Poisoning

Zone 3 → 4

Models to agents

LLM02 Insecure Output Handling; LLM08 Excessive Agency; LLM09 Overreliance

ASI01 Agent Goal Hijack; ASI05 Unexpected Code Execution; ASI09 Human-Agent Trust Exploitation

Zone 4 → 5

Agents to tools, MCP, APIs, data

LLM07 Insecure Plugin Design; LLM08 Excessive Agency; LLM02 Insecure Output Handling; LLM06 Sensitive Information Disclosure

ASI02 Tool Misuse & Exploitation; ASI03 Identity & Privilege Abuse; ASI05 Unexpected Code Execution; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI10 Rogue Agents

Zone 5 → 3 / 4 Retrieval and enterprise data returning

LLM01 Prompt Injection; LLM06 Sensitive Information Disclosure; LLM02 Insecure Output Handling

ASI06 Memory & Context Poisoning; ASI01 Agent Goal Hijack (indirect); ASI04 Agentic Supply Chain Compromise

NOTE: For Product mapping see pages 13, 14

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 11

AI Trust Zone Transitions

AI ecosystems are complex, with multiple new connections per asset. Securing that complexity

requires architects and engineers to identify every point at which traffic crosses a trust boundary — a trust transition.

The table below shows where the most relevant OWASP LLM and Agentic risks arise across these

transitions and which controls should be enforced at each boundary. It turns AI risk from a conceptual discussion into an actionable architecture view — showing security and enterprise teams

where AI-specific controls (AI Firewall, AI Secured Gateway, prompt defense, agent controls, MCP

inspection) must be applied first.

NOTE: For Product mapping see pages 13, 14

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

Zones / Trust transition

OWASP LLM Risks OWASP Agentic Risks

Users to frontend LLM01 Prompt Injection; LLM04 Model Denial of Service; LLM09 Overreliance

ASI01 Agent Goal Hijack (indirect, seeded at

input); ASI09 Human-Agent Trust Exploitation

Applications to orchestration

LLM01 Prompt Injection; LLM06 Sensitive Information

Disclosure; LLM04 Model Denial of Service; LLM10 Model Theft

ASI01 Agent Goal Hijack; ASI03 Identity &

Privilege Abuse

Inside Zone 3 LLM03 Training Data Poisoning; LLM05 Supply Chain Vulnerabilities; LLM10 Model Theft; LLM06 Sensitive Information Disclosure

ASI04 Agentic Supply Chain Compromise;

ASI06 Memory & Context Poisoning

Models to agents LLM02 Insecure Output Handling; LLM08 Excessive Agency; LLM09 Overreliance

ASI01 Agent Goal Hijack; ASI05 Unexpected

Code Execution; ASI09 Human-Agent Trust Exploitation

Agents to tools, MCP, APIs, data

LLM07 Insecure Plugin Design; LLM08 Excessive Agency; LLM02

Insecure Output Handling; LLM06 Sensitive Information Disclosure

ASI02 Tool Misuse & Exploitation; ASI03 Identity & Privilege Abuse; ASI05 Unexpected

Code Execution; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI10 Rogue Agents

Retrieval and

enterprise data returning

LLM01 Prompt Injection; LLM06 Sensitive Information Disclosure; LLM02 Insecure Output Handling

ASI06 Memory & Context Poisoning; ASI01 Agent Goal Hijack (indirect); ASI04 Agentic Supply Chain Compromise

The Case for AI Zero Trust

Management-Plane Trust Transitions

Transitions fall into two categories. Data-plane transitions carry user and application traffic through the running system. Management-plane transitions are how the system itself is built, changed, and observed — and their compromise is often more damaging, because it rewrites the rules the data plane operates under. Both must be enumerated; most organisations enforce only a subset of either.

A single compromised CI/CD pipeline or model registry can silently weaken every data-plane control the organisation has deployed — which is exactly why sophisticated attackers target it first. Management-plane traffic is how the AI system gets built, changed, and observed. It originates outside the zone topology — from corporate admin networks, CI/CD platforms, model registries, observability services — and its compromise is often more damaging than a data-plane breach: it doesn't evade the rules, it rewrites them.

Conventional Controls Remain Necessary

AI-specific controls do not replace conventional ones — they sit alongside them. NGFWs continue to enforce zone boundaries for non-AI traffic. WAFs continue to protect web and API layers. Identity- based policy, IPS, TLS inspection, MFA, and SIEM all retain their existing roles. The two sets of controls are additive, not substitutive, and both are required in a Zero Trust architecture that includes AI workloads.

12

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 12

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

Management-Plane Trust Transitions

Transitions fall into two categories. Data-plane transitions carry user and application traffic through the running system. Management-plane transitions are how the system itself is built, changed, and observed — and their compromise is often more damaging, because it rewrites the rules the data plane

operates under. Both must be enumerated; most organisations enforce only a subset of either. A single compromised CI/CD pipeline or model registry can silently weaken every data-plane control

the organisation has deployed — which is exactly why sophisticated attackers target it first. Management-plane

traffic is how the AI system gets built, changed, and observed. It originates outside the zone topology — from

corporate admin networks, CI/CD platforms, model registries, observability services — and its compromise is often

more damaging than a

data-plane breach: it doesn't evade the rules, it rewrites them.

Conventional Controls Remain Necessary AI-specific controls do not replace conventional ones — they sit alongside them. NGFWs continue to enforce zone boundaries for

non-AI traffic. WAFs continue to protect web and API layers. Identity-based policy, IPS, TLS inspection, MFA, and SIEM all retain their

existing roles. The two sets of controls are additive, not substitutive, and both are required in a Zero Trust architecture that

includes AI workloads.

The Case for AI Zero Trust 13

6. Check Point AI Zero Trust Solutions At the component layer, Check Point implements AI Zero Trust through a full-stack portfolio of AI security technologies designed to protect every zone in the enterprise AI ecosystem, from workforce use of GenAI and AI applications to agentic workflows, AI firewalls, and GPU-based AI infrastructure. By mapping Check Point technology to zones we enable organizations to protect AI interactions, govern autonomous behaviour, secure models and data paths, and enforce Zero Trust controls across the entire AI ecosystem.

AI Zero Trust

principle / risk

Check Point

product

Zone /

boundary

What it contributes

Assume breach at

the AI interaction

layer

AI Network Firewall / Web

Application

Firewall

Zone 1 → 2

and Zone 2 →

3

Extends conventional firewall /

WAF enforcement into AI

interactions, with AI-aware

protection for GenAI apps and

APIs.

Govern workforce

use of GenAI

Workforce AI

Security

Zone 1 Visibility and governance of

employee use of AI tools,

copilots, and AI-enabled

applications.

Discover and govern

AI applications and

agents

AI Agent Security

Zones 3 & 4 Unified architecture to discover,

protect, and govern AI across

workforce, applications, and

agents

Micro- segmentation

Check Point Security Mgmt + Illumio microsegmentation

Zones 3 & 4 Prevent lateral movement between and within the micro segments & Kubernetes

Continuously validate

AI systems

AI Red Teaming Zones 3 & 4

(validation)

Continuous adversarial testing

across prompts, reasoning

paths, workflows, tool use, and

agent behaviour.

Segment and protect

private LLM and GPU

environments:

AI Factory

Firewall (AIFF)

Inside Zone 3

(east-west)

Check Point NGFW for AI workloads, running on NVIDIA BlueField DPUs.

Reduce blast radius

across the network

AI Network Firewall & Maestro Hyperscale Firewall

All zone

boundaries

Foundational enforcement layer

for hybrid mesh and enterprise

network Zero Trust

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 13

AI Zero Trust

principle / risk Check Point

product Zone / boundary

What it contributes

Assume breach at the AI interaction

layer

AI Network

Firewall / Web Application Firewall

3

Extends conventional firewall / WAF enforcement into AI interactions, with AI-aware protection for GenAI apps and APIs.

Govern workforce use of GenAI

Workforce AI

Security Zone 1 Visibility and governance of

employee use of AI tools, copilots, and AI-enabled applications.

Discover and govern AI applications and agents

AI Agent Security

Zones 3 & 4 Unified architecture to discover, protect, and govern AI across workforce, applications, and agents

Micro-segmentation Check Point

Security Mgmt + Illumio

microsegmentation

Zones 3 & 4 Prevent lateral movement between and within the

micro segments & Kubernetes

Continuously validate

AI systems

AI Red Teaming Zones 3 & 4

(validation) Continuous adversarial testing across prompts, reasoning paths, workflows, tool use, and agent behaviour.

Segment and protect private LLM and GPU environments:

AI Factory Firewall (AIFF)

Inside Zone 3

(east-west) Check Point NGFW for AI

workloads, running on NVIDIA BlueField DPUs.

Reduce blast radius across the network

AI Network Firewall & Maestro

Hyperscale Firewall

All zone boundaries

Foundational enforcement layer for hybrid mesh and enterprise network Zero Trust

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

6. Check Point AI Zero Trust Solutions

At the component layer, Check Point implements AI Zero Trust through a full-stack portfolio of AI

security technologies designed to protect every zone in the enterprise AI ecosystem, from workforce

use of GenAI and AI applications to agentic workflows, AI firewalls, and GPU-based AI infrastructure. By mapping Check Point technology to zones we enable organizations to protect

AI interactions, govern autonomous behaviour, secure models and data paths, and enforce Zero Trust

controls across the entire AI ecosystem.

The Case for AI Zero Trust

Architectural Summary: Five trust zones, each with dedicated Check Point controls

Zone 1:

Users & Perimeter

Zone 2:

Applications & Frontend

Zone 3:

AI Orchestration & Models

Zone 4:

AI Agents

Zone 5:

Tools, Data & Core Systems

AI Network Firewall AI Network Firewall AI Network Firewall Prompt defense AI Factory Firewall/BlueField

Workforce AI security Secure LLM Gateway AI Red Teaming AI Red Teaming Maestro Hyperscale

ZTNA / SASE WAF / API security ThreatCloud AI ThreatCloud AI Check Point + Illumio

Identity access control

Never trust

user / agent

Inspect

all traffic

Least

privilege

Never trust

prompts / output

Assume

breach

14

AI Zero Trust | Architectural Summary

Five trust zones, each with dedicated Check Point security controls.

From Left to Right: users (and machines) enter through ZTNA, cross the AI Network Firewall, reaching agents governed by agentic security, and then reach LLMs defended by prompt defense. AI compute workload runs on GPU clusters inside the AI Data Center ("AI Factory"). The AI data center is protected by AI Factory Firewalls along with multiple overlapping AI security layers including AI runtime inspection from beginning to end. One platform, with every boundary enforced.

Two control points carry most of this load.

AI Network Firewall: extends the traditional NGFW with AI-aware inspection and segmentation, including prompt- injection detection and policy enforcement between users, agents, models, and sensitive enterprise systems.

Secure LLM Gateway: the dedicated control point for AI and model interactions, covering secure LLM routing, prompt defense, content and policy inspection, and governance over how AI applications and agents connect to internal and external models.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 14

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

AI Zero Trust | Architectural Summary

Five trust zones, each with dedicated Check Point security controls.

From Left to Right: users (and machines) enter through ZTNA, cross the AI Network Firewall, reaching

agents governed by agentic security, and then reach LLMs defended by prompt defense. AI compute

workload runs on GPU clusters inside the AI Data Center ("AI Factory"). The AI data center is protected by AI Factory Firewalls along with multiple overlapping AI security layers including AI runtime inspection from beginning to end. One platform, with every boundary enforced.

Architectural Summary: Five trust zones, each with dedicated Check Point controls

AI Network Firewall

Secure LLM Gateway

WAF / API security

Zone 2:

Applications & Frontend

AI Network Firewall

AI Red Teaming

ThreatCloud AI

Zone 3:

AI Orchestration & Models

Prompt defense

AI Red Teaming

ThreatCloud AI

Zone 4:

AI Agents

AI Factory Firewall/BlueField

Maestro Hyperscale

Check Point + Illumio

Zone 5:

Tools, Data & Core Systems

AI Network Firewall

Workforce AI security

ZTNA / SASE

Identity access control

Zone 1:

Users & Perimeter

Never trust user / agent

Inspect all traffic

Least

privilege Never trust

prompts / output Assume

breach

Two control points carry most of this load.

AI Network Firewall: extends the traditional NGFW with AI-aware inspection and segmentation, including prompt-injection detection and policy enforcement between users, agents, models, and sensitive enterprise systems. Secure LLM Gateway: the dedicated control point for AI and model interactions, covering secure LLM routing, prompt defense, content and policy inspection, and governance over how AI applications

and agents connect to internal and external models.

The Case for AI Zero Trust 15

7.  Where to Start – A Five-Phase Executive Approach to AI Zero Trust

01 Conduct a risk-based AI security assessment

Start by understanding where AI creates material business and cyber risk. Leadership should direct a structured assessment of AI use cases, agents, models, applications, and supporting infrastructure against recognized frameworks such as OWASP LLM, OWASP Agentic risks, and MITRE ATLAS, to identify the most relevant threats, control gaps, and priority exposures.

Check Point has published the following assets to help you:

Check Point AI Risk Matrix Tool

White Paper | Agentic AI Security: The Enterprise Playbook

AI Data Center & AI Factory Security Blueprint

02 Make the AI estate visible

Once risk has been framed, the next step is to build visibility into where AI already exists or

is planned. This means identifying major AI use cases, model connections, agents, AI-

enabled applications, and critical tool or data dependencies across the enterprise, including

informal or shadow deployments that may sit outside current governance.

03 Define the trust zones

With visibility established, the organization should classify AI components into a clear trust

model. Architecture and security teams should use the five-zone approach to distinguish AI

orchestration, model environments, agents, and MCP or tool access from existing DMZ and

internal zones, creating the policy and segmentation foundation for AI Zero Trust.

04 Prioritize and protect the highest-risk boundaries

Not every boundary carries the same business impact, so leadership should focus first on

the trust transitions that matter most. Priority should be given to the boundaries where

compromise could expose sensitive data, enable autonomous action, or create systemic

operational risk — such as application-to-model, model-to-agent, and agent-to-core-

system interactions — and where AI-specific controls such as AI firewalls, AI secured

gateways, prompt defence, and tool inspection are required.

05 Assign ownership and operational accountability

Finally, AI Zero Trust must be turned into an operating model, not left as an architectural

concept. Security and enterprise architecture teams should define the framework. AI and

application teams should define intended behaviour and acceptable action scope. And

infrastructure and network teams should enforce segmentation and resilience. These

responsibilities must be explicitly assigned before AI workloads scale into production.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

The Case for AI Zero Trust 15

01 Conduct a risk-based AI security assessment

Start by understanding where AI creates material business and cyber risk. Leadership

should direct a structured assessment of AI use cases, agents, models, applications, and

supporting infrastructure against recognized frameworks such as OWASP LLM, OWASP

Agentic risks, and MITRE ATLAS, to identify the most relevant threats, control gaps, and priority exposures.

Check Point has published the following assets to help you:

Check Point AI Risk Matrix Tool

White Paper | Agentic AI Security: The Enterprise Playbook

AI Data Center & AI Factory Security Blueprint

02 Make the AI estate visible

Once risk has been framed, the next step is to build visibility into where AI already exists or

is planned. This means identifying major AI use cases, model connections, agents, AI-

enabled applications, and critical tool or data dependencies across the enterprise, including

informal or shadow deployments that may sit outside current governance.

03 Define the trust zones

With visibility established, the organization should classify AI components into a clear trust

model. Architecture and security teams should use the five-zone approach to distinguish AI

orchestration, model environments, agents, and MCP or tool access from existing DMZ and

internal zones, creating the policy and segmentation foundation for AI Zero Trust.

© 2026 Check Point Software Technologies Ltd. All Rights Reserved

7. Where to Start – A Five-Phase Executive Approach to AI Zero Trust

04 Prioritize and protect the highest-risk boundaries

Not every boundary carries the same business impact, so leadership should focus first on

the trust transitions that matter most. Priority should be given to the boundaries where

compromise could expose sensitive data, enable autonomous action, or create systemic

operational risk — such as application-to-model, model-to-agent, and agent-to-core- system interactions — and where AI-specific controls such as AI firewalls, AI secured

gateways, prompt defence, and tool inspection are required.

05 Assign ownership and operational accountability

Finally, AI Zero Trust must be turned into an operating model, not left as an architectural

concept. Security and enterprise architecture teams should define the framework. AI and

application teams should define intended behaviour and acceptable action scope. And

infrastructure and network teams should enforce segmentation and resilience. These

responsibilities must be explicitly assigned before AI workloads scale into production.

https://airiskmatrix.org/ https://www.checkpoint.com/resources/all-assets-460c/white-paper-agentic-ai-security-the-enterprise-playbook https://engage.checkpoint.com/ai-data-center-ai-factory-security-blueprint https://airiskmatrix.org/ https://www.checkpoint.com/resources/all-assets-460c/white-paper-agentic-ai-security-the-enterprise-playbook https://engage.checkpoint.com/ai-data-center-ai-factory-security-blueprint

The Case for AI Zero Trust

8.  Conclusion Anthropic Mythos and other advanced frontier AI models have raised the risk level for all enterprises: AI-driven attacks are becoming faster, cheaper, and harder to contain, while many enterprise AI systems remain highly vulnerable. Meeting the challenges of AI cybersecurity demands adaptation.
 AI Zero Trust is the required evolution of Zero Trust principles applied to AI systems. It's an effective model for practitioners because it's built on the assumptions that now matter most: assume breach, enforce least privilege, and contain compromise at every boundary.

The priority for leadership is to move quickly, treat AI security as a business resilience issue, and extend AI Zero Trust across the AI estate before gaps in protection result in costly business disruption and loss of trust or confidence.

About Check Point Check Point Software Technologies Ltd. is a global cyber security leader protecting more than 100,000
 organizations worldwide. Its mission is to secure enterprises’ AI transformation. Built on a prevention
 first approach and an open ecosystem architecture, Check Point helps organizations reduce risk,
 simplify operations, and innovate with confidence. This unified security architecture continuously adapts to evolving threats and expanding AI attack surfaces, protecting hybrid networks, cloud environments, digital workspaces, and AI systems. Structured around four strategic pillars, Hybrid Mesh Network Security, Workspace Security, Exposure Management, and AI Security, Check Point delivers consistent protection and visibility across complex multivendor environments.

Learn More

16

Securing the AI Data Center & AI Factory Contact Us

Worldwide Headquarters

5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599

U.S. Headquarters

100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391

www.checkpoint.com

© 2026 Check Point Software Technologies Ltd. All rights reserved. | Updated v.0 July 28, 2026

The Case for AI Zero Trust 16

8. Conclusion

Anthropic Mythos and other advanced frontier AI models have raised the risk level for all enterprises: AI-driven attacks are becoming faster, cheaper, and harder to contain, while many

enterprise AI systems remain highly vulnerable. Meeting the challenges of AI cybersecurity demands adaptation.

AI Zero Trust is the required evolution of Zero Trust principles applied to AI systems. It's an effective model for practitioners because it's built on the assumptions that now matter most: assume

breach, enforce least privilege, and contain compromise at every boundary.

The priority for leadership is to move quickly, treat AI security as a business resilience issue, and

extend AI Zero Trust across the AI estate before gaps in protection result in costly business disruption and loss of trust or confidence.

About Check Point

Check Point Software Technologies Ltd. is a global cyber security leader protecting more than 100,000

organizations worldwide. Its mission is to secure enterprises’ AI transformation. Built on a prevention

first approach and an open ecosystem architecture, Check Point helps organizations reduce risk,

simplify operations, and innovate with confidence. This unified security architecture continuously adapts to evolving threats and expanding AI attack surfaces, protecting hybrid networks, cloud environments, digital workspaces, and AI systems. Structured around four strategic

pillars, Hybrid Mesh Network Security, Workspace Security, Exposure Management, and AI Security,

Check Point delivers consistent protection and visibility across complex multivendor environments.

Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599

U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391

www.checkpoint.com

© 2026 Check Point Software Technologies Ltd. All rights reserved. | Updated v.0 July 28, 2026

Learn More

Securing the AI Data Center & AI Factory Contact Us

https://engage.checkpoint.com/executive-guide-securing-the-ai-data-center-ai-factory https://pages.checkpoint.com/2026-mar-ww-ai-factory-and-data-center-security.html https://engage.checkpoint.com/executive-guide-securing-the-ai-data-center-ai-factory https://pages.checkpoint.com/2026-mar-ww-ai-factory-and-data-center-security.html


Item Type: pdf