Guide | The Case for Al Zero Trust
Discover why traditional security models fall short in the age of AI. This guide explores AI Zero Trust, outlining strategies to secure AI agents, models, and enterprise networks while reducing cyber risk and limiting attack impact.

AI
Zero Trust
The Case for AI Zero Trust
A Security Leader's Guide to AI-Native Trust Enforcement
For CTOs, CISOs, and Enterprise Security ArchitectsFor CTOs, CISOs, and Enterprise Security Architects
AI Zero Trust
The Case for AI Zero Trust
A Security Leader's Guide to AI-Native Trust Enforcement
The Case for AI Zero Trust 2
1. Exec Summary: A Changed Threat Landscape The threat environment has shifted. The capabilities demonstrated by Anthropic's Claude Mythos mark a step-change in the offensive use of AI. This was the first frontier model to be classified as a national security risk and raised major concerns for having "crossed the AI cyber security Rubicon”. Attackers now discover vulnerabilities faster than defenders can patch them, executing multi-stage attacks at machine speed. They can penetrate environments to depths that previously required skilled human operators. Consequently, the window between vulnerability exposure and business disruption has permanently shrunk from weeks to minutes.
At the same time, a new attack surface is emerging. AI agents, large language models, and the infrastructure that powers them introduce risks that exist in the context and intent of a request, not its port or protocol — the layer that conventional network controls were never built to inspect. A compromised agent, for example, can execute in seconds what once required months of human effort. This changes not only how we secure networks, but how we protect the business they support.
Traditional Security asks: "Who sent this, and where is it going?"
AI Zero Trust adds: "What is this actually saying, and what does it intend to do?"
The attack isn't in the envelope—it's in the meaning.
AI Zero Trust stops attacks like prompt injections by analyzing the context of the data.
Zero Trust remains the right security model for this environment. Its three principles—never trust, always verify; least privilege access; and assume breach—remain correct. The assume-breach approach takes on particular importance in the Mythos era, because compromise has shifted from possible to probable. The architecture must now be designed around that reality rather than treating breach as an edge case.
Under a Zero Trust posture, every defensive decision resolves to three operational objectives:
reduce the attack surface and the exposure of critical assets,
minimize the impact and blast radius of any successful compromise; and react,
mitigate and recover fast.
Based on today’s realities, there is a clear mandate to expand Zero Trust to AI Zero Trust by defining explicit new trust zones for AI gateways, model environments living in private AI factories, AI agents and users, and MCP-connected services. These new zones must be protected not only by conventional network controls, but by AI-native enforcement technologies designed for the unique risks created by AI interactions, autonomous actions, and model-driven workflows.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
1. Exec Summary: A Changed Threat Landscape
The threat environment has shifted. The capabilities demonstrated by Anthropic's Claude Mythos mark a
step-change in the offensive use of AI. This was the first frontier model to be classified as a national security risk and raised major concerns for having "crossed the AI cyber security Rubicon”.
Attackers now discover vulnerabilities faster than defenders can patch them, executing multi-stage
attacks at machine speed. They can penetrate environments to depths that previously required skilled human operators. Consequently, the window between vulnerability exposure and business
disruption has permanently shrunk from weeks to minutes.
At the same time, a new attack surface is emerging. AI agents, large language models, and the
infrastructure that powers them introduce risks that exist in the context and intent of a request, not its port or protocol — the layer that conventional network controls were never built to inspect. A compromised agent, for example, can execute in seconds what once required months of human
effort. This changes not only how we secure networks, but how we protect the business they support.
Zero Trust remains the right security model for this environment. Its three principles—never trust, always verify; least privilege access; and assume breach—remain correct. The assume-breach approach takes on particular importance in the Mythos era, because compromise has
shifted from possible to probable. The architecture must now be designed around that reality rather than treating breach as an edge case.
Under a Zero Trust posture, every defensive decision resolves to three operational objectives:
reduce the attack surface and the exposure of critical assets, minimize the impact and blast radius of any successful compromise; and react, mitigate and recover fast.
Based on today’s realities, there is a clear mandate to expand Zero Trust to AI Zero Trust by defining explicit new trust zones for AI gateways, model environments living in private AI factories, AI agents and users, and MCP-connected services. These new zones must be protected not only by conventional network controls, but by AI-native enforcement technologies designed for the unique risks created by AI interactions, autonomous actions, and model-driven workflows.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
Traditional Security asks: "Who sent this, and where is it going?"
AI Zero Trust adds: "What is this actually saying, and what does it intend to do?"
The attack isn't in the envelope—it's in the meaning.
AI Zero Trust stops attacks like prompt injections by analyzing the context of the data.
The Case for AI Zero Trust 2
The Case for AI Zero Trust
In this architecture, AI Zero Trust is enforced through two new strategic control points: the AI Network Firewall and the Secure LLM Gateway.
3
AI Network Firewall Secure LLM Gateway
Extends the role of the traditional NGFW by adding AI-aware inspection and segmentation capabilities, including prompt-injection detection, and policy enforcement between users, agents, models, and sensitive enterprise systems.
Acts as the dedicated control point for AI and model interactions, providing secure LLM routing, prompt defense, content and policy inspection, and governance over how AI applications and agents connect to internal and external models.
Together, these controls reduce attack surface, contain blast radius, and help protect the enterprise
against both conventional network threats and emerging AI-driven attacks.
AI Network Firewall: On-Premise, in the Cloud, & Virtual
AI Frontier Model
OpenAI
AI Agents & Users
Users
GenAI applications
Agents
MCP clients
LLM API call
Data Traffic
AI network Firewall
AI Prompt Defense
AI Application Traffic Inspection (NGFW)
Agentic AI & RAG access control
Management plane & observability
Secured Validated Prompts
LLM API Call
AI Factory
LLM workloads
GPU servers
Data Center
IT systems
MCP servers
Practically speaking, the AI Network Firewall acts like a circuit breaker for semantic and data traffic. For example, it enforces your security policy for communication between AI agents, LLMs, and your core enterprise applications. This is a key capability introduced with Check Point's R82.20 software release which enables critical AI security measures.
The AI Firewall is the Central enforcement layer for Prompt protection, AI-Enabled Application traffic inspection, Access control for RAGs & Agentic AI security, telemetry, and Management, enabling safer enterprise AI adoption.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 3
Together, these controls reduce attack surface, contain blast radius, and help protect the enterprise
against both conventional network threats and emerging AI-driven attacks.
Practically speaking, the AI Network Firewall acts like a circuit breaker for semantic and data traffic. For example, it enforces your security policy for communication between AI agents, LLMs, and
your core enterprise applications. This is a key capability introduced with Check Point's R82.20 software release which enables critical AI security measures.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
In this architecture, AI Zero Trust is enforced through two new strategic control points:
the AI Network Firewall and the Secure LLM Gateway.
AI Network Firewall
Extends the role of the traditional NGFW by
adding AI-aware inspection and
segmentation capabilities, including
prompt-injection detection, and policy
enforcement between users, agents,
models, and sensitive enterprise systems.
Secure LLM Gateway
Acts as the dedicated control point for AI and model interactions, providing secure LLM routing, prompt defense, content and policy inspection, and governance over how AI applications and agents connect to internal and external models.
AI Network Firewall: On-Premise, in the Cloud, & Virtual
The AI Firewall is the Central enforcement layer for Prompt protection, AI-Enabled Application
traffic inspection, Access control for RAGs & Agentic AI security, telemetry, and Management, enabling
safer enterprise AI adoption.
AI Agents & Users
Users
GenAI applications
Agents
MCP clients
LLM API call
Data Traffic
Secured Validated Prompts
LLM API Call
AI network Firewall
AI Prompt Defense
AI Application Traffic Inspection (NGFW)
Agentic AI & RAG access control
Management plane & observability
AI Factory
LLM workloads
GPU servers
Data Center
IT systems
MCP servers
AI Frontier Model
OpenAI
The Case for AI Zero Trust 4
2. AI Zero Trust Principals Zero Trust is the established architectural principle of our time, well known and respected as a cornerstone of cyber security architecture, consequently we should not abandon it as a core security principle but update it to reflect the changes brought about by AI transformation We propose an expand model that reflects a new class of assets, a new set of interactions, and a new range of attack paths. The logic is the same; the surface it must govern is not.
The standard Zero Trust model of today is built on three core principles — never trust, always verify; least privilege access; assume breach — which remain correct. In the expanded AI Zero Trust model, developed for AI ecosystems, what changes is the weight each principle carries. ‘Assume breach’ takes a more central role; compromise has shifted from possible to probable, and the architecture must be built around that reality.
Principle What it requires in the AI era
Never trust, always verify No user, prompt, model output, or agent action is trusted by
default. Every access request is authenticated, every boundary
crossing is inspected, every AI interaction is verified against policy
before it proceeds.
Least privilege access Every agent, model, and tool operates with the narrowest
permission set that allows it to function. Action scope is declared
explicitly and enforced at runtime. No AI component inherits the
permissions of the user who triggered it.
Architecture is built on the assumption that compromise will occur.
Every boundary is an enforcement point designed to contain blast
radius. Every critical path is monitored so compromise is detected
in minutes, not months.
Why Zero Trust Must Expand to AI
Legacy Zero Trust checks AI Zero Trust adds
Who is this user or system? What is this prompt actually asking for?
Is this the right port, right protocol? Is this content trying to manipulate the model?
Does the signature match a known threat? Does the meaning carry a hidden instruction?
Assume breach
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 4
Principle What it requires in the AI era
Never trust, always verify No user, prompt, model output, or agent action is trusted by default. Every access request is authenticated, every boundary crossing is inspected, every AI interaction is verified against policy before it proceeds.
Least privilege access Every agent, model, and tool operates with the narrowest permission set that allows it to function. Action scope is declared explicitly and enforced at runtime. No AI component inherits the permissions of the user who triggered it.
Assume breach Architecture is built on the assumption that compromise will occur. Every boundary is an enforcement point designed to contain blast radius. Every critical path is monitored so compromise is detected in minutes, not months.
Legacy Zero Trust checks AI Zero Trust adds
Who is this user or system? What is this prompt actually asking for?
Is this the right port, right protocol? Is this content trying to manipulate the model?
Does the signature match a known threat? Does the meaning carry a hidden instruction?
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
2. AI Zero Trust Principals
Zero Trust is the established architectural principle of our time, well known and respected as a
cornerstone of cyber security architecture, consequently we should not abandon it as a core security
principle but update it to reflect the changes brought about by AI transformation We propose an
expand model that reflects a new class of assets, a new set of interactions, and a new range of attack
paths. The logic is the same; the surface it must govern is not.
The standard Zero Trust model of today is built on three core principles — never trust, always verify; least privilege access; assume breach — which remain correct. In the expanded AI Zero Trust
model, developed for AI ecosystems, what changes is the weight each principle carries. ‘Assume breach’
takes a more central role; compromise has shifted from possible to probable, and the architecture must
be built around that reality.
Why Zero Trust Must Expand to AI
The Case for AI Zero Trust 5
AI Zero Trust Principles - Mapped to Check Point Solutions
AI Zero Trust
Principle
What it means for AI security Check Point products & capabilities
01
Never trust prompts, outputs, or identities
Every prompt, retrieved document, model response, user identity, and agent request must be inspected before it crosses an AI trust boundary.
Prompt Defense
AI Network Firewall
Secure LLM Gateway
WAF / API Security
Workforce AI Security
02
Enforce least privilege for agents and tools
AI agents should not inherit broad user permissions. Every API call, MCP tool use, write action, and data request must be scoped and authorized at runtime.
AI Agent Securit y
AI Network Firewall
MCP / Tool Inspection
ZTNA / SASE
Microsegmentation
03
Assume breach and contain blast radius
Any AI component, prompt path, agent, gateway, or model zone may be compromised. The architecture must segment AI zones and enforce prevention at each transition.
Secure LLM Gatewa y
AI Network Firewall
AI Factory Firewall
Maestro Hyperscale
Cloud Security
04
Continuously validate and recover fast
AI systems must undergo continuous vulnerability testing including across live attack paths, prompts, reasoning chains, RAG content, tool calls, model behavior, and abnormal activity
AI Red Teamin g
ThreatCloud AI
Exposure Management
AI-Ops & Telemetry
Each principle has its own unique business implication; the chart shows how Check Point closes the gap.
Key message: The same Zero Trust logic is expanded to AI Zero Trust, for new assets and new enforcement points — all from one platform.
The central argument:
AI Zero Trust is the policy logic. Segmentation is the enforcement architecture. Both remain right for the AI era — but new segments are required to govern a threat surface that conventional networks did not contain. Same principles, new assets, new zones, new controls.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 5
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
01
Never trust
prompts, outputs, or identities
AI Zero Trust
Principle
02 Enforce least
privilege for agents and tools
03 Assume breach and contain blast radius
04
Continuously validate and recover fast
Every prompt, retrieved document, model response, user identity, and agent request must be inspected before it crosses an AI trust boundary.
What it means for AI security
AI agents should not inherit broad user permissions. Every API call, MCP tool use, write action, and data request must be scoped and authorized at runtime.
Any AI component, prompt path, agent, gateway, or model zone may be compromised. The architecture must segment AI zones and enforce prevention at each transition.
AI systems must undergo continuous vulnerability testing including across live attack paths, prompts, reasoning chains, RAG content, tool calls, model behavior, and abnormal activity
Prompt Defense AI Network Firewall
Secure LLM Gateway WAF / API Security
Check Point products & capabilities
AI Agent Security AI Network Firewall
MCP / Tool Inspection
ZTNA / SASE
Secure LLM Gateway AI Network Firewall
AI Factory Firewall Maestro Hyperscale Cloud Security
AI Red Teaming ThreatCloud AI
Exposure Management AI-Ops & Telemetry
The central argument:
AI Zero Trust is the policy logic. Segmentation is the enforcement architecture. Both remain right for the AI era —
but new segments are required to govern a threat surface that conventional networks did not contain. Same
principles, new assets, new zones, new controls.
Each principle has its own unique business implication; the chart shows how Check Point closes the gap.
Key message: The same Zero Trust logic is expanded to AI Zero Trust, for new assets and new
enforcement points — all from one platform.
AI Zero Trust Principles - Mapped to Check Point Solutions
The Case for AI Zero Trust 6
3. Defining Segmentation and Ownership If AI Zero Trust is our conceptual model for AI security, then segmentation is the mechanism by which those objectives become an enforceable architecture. Before we look at how the AI ZT principles impact our architecture it is important to first define what we mean by segmentation. Segmentation is the mechanism by which Zero Trust principles become enforceable architecture. It operates at three levels, each with a different set of attributes, and conflating them is the most common cause of confusion when a segmentation project hits the real world, which is why defining them in terms of ownership and function is an important step. Each level answers a different question, has a different owner, and requires a different implementation timeline. All three are required for an AI-enabled enterprise, however for network and security team's macro segmentation often has the highest technical and security value.
Macro-Segmentation Micro-Segmentation Nano-Segmentation
Owned by Network & Security
teams
Application & Business
teams
AI/ML engineering &
DevOps teams
Traffic direction North-south, east-
west: between zones
and workload groups
Within zones, segments, and Kubernetes namespaces
Within Kubernetes, between pods and containers
Primary goal Minimize breach blast
radius at the network
layer
Prevent lateral movement between application components (Web, App, DB)
Prevent malware spread inside an application group of servers
Implementation Firewalls, API / AI
gateways, AI Firewall
Agent installed on each server / VM and application-centric access control — SDN / Cisco ACI
Container Network Interface (CNI)
access control
Macro-segmentation protects workload groups from each other. Micro-segmentation protects components within a workload from one another. Nano-segmentation governs what an individual AI process is permitted to do at the instruction level — which APIs it may call, which data it may read, which actions it may take.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 6
Macro-Segmentation Micro-Segmentation Nano-Segmentation
Owned by Network & Security teams
Application & Business teams AI/ML engineering &
Traffic direction North-south, east- west: between zones
and workload groups
Within zones, segments, and Kubernetes
namespaces
Within Kubernetes,
between pods and containers
Primary goal Minimize breach blast radius at the network
layer
Prevent lateral movement between
application components (Web, App, DB)
Prevent malware
spread inside an application group of servers
Implementation Firewalls, API / AI
gateways, AI Firewall Agent installed on each server / VM and
application-centric access control — SDN / Cisco ACI
Container Network
Interface (CNI) access control
Macro-segmentation protects workload groups from each other. Micro-segmentation protects
components within a workload from one another. Nano-segmentation governs what an individual AI
process is permitted to do at the instruction level — which APIs it may call, which data it may read, which actions it may take.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
3. Defining Segmentation and Ownership
If AI Zero Trust is our conceptual model for AI security, then segmentation is the mechanism by which
those objectives become an enforceable architecture. Before we look at how the AI ZT principles
impact our architecture it is important to first define what we mean by segmentation. Segmentation is
the mechanism by which Zero Trust principles become enforceable architecture. It operates at three
levels, each with a different set of attributes, and conflating them is the most common cause of confusion when a segmentation project hits the real world, which is why defining them in terms
of ownership and function is an important step. Each level answers a different question, has a different owner, and requires a different implementation timeline. All three are required for an AI-enabled enterprise, however for network and security team's macro segmentation often has the
highest technical and security value.
The Case for AI Zero Trust 7
Macrosegment Zone Interconnection Point
Ingress Egress
North-South
Workloads Workloads
Traditional Perimeter Firewall
Microsegment Microsegment
Subnet B
Microsegment
Workloads Workloads
Subnet A
East-West
Using a Network/Cloud Fabric or Agents in the EndPoint
Nano segment
Backend
East
West APIGateway
UtilitiesFrontend
Zone Interconnection Point Zone Interconnection Point
Cloud Native Networking
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
Workloads
<API>
The Case for AI Zero Trust 7
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
Zone Interconnection PointMacrosegment
Traditional Perimeter Firewall
North-South
Workloads
Ingress Egress
Workloads
Workloads Workloads
East-West
Microsegment
Microsegment
Subnet A
Subnet B
Using a Network/Cloud Fabric or Agents in the EndPoint
Zone Interconnection Point Zone Interconnection Point
Cloud Native Networking
Workloads
<API>
East
West APIGateway
Frontend Utilities
Backend
Microsegment
Nano segment
The Case for AI Zero Trust 8
Why nano-segmentation matters for AI
For any organization running AI agents in production, the absence of nano-segmentation means there is no enforceable limit on what a compromised or manipulated agent can do once it has been granted its initial access. Macro and micro controls contain the zone and the application. Nano controls contain the agent itself.
4. Segmentation and the AI Trust Boundary At the network security level, the mechanism of Zero Trust enforcement is macro-segmentation, in practical terms this allows the division of the enterprise network and the AI ecosystem into zones, each containing workloads of a similar trust level, with controlled traffic between them. Within a trust zone more granular levels of access can be enforced using micro and nano segmentation. For the purposes of this design pattern the macro boundary is a chokepoint between zones of trust so it's the natural place to apply threat prevention, within a zone the micro and macro security functions reduce the paths between assets of the same trust.
In our model, we define the AI trust boundary as that which sites between trust zones, as this is where we will apply threat prevention capabilities, however we can still enforce segment inside the trust zone, so that traffic between assets is visible and can be subjected to enforcement.
What is important is that trust boundaries and microsegment must be enforced by a security function capable of inspecting and authorizing the traffic that crosses it and that as traffic types change so too should the enforcement capability.
Core principle
A macro-segment boundary is a trust boundary. Every trust boundary must be enforced by a security function. Macro- segmentation contains a breach between zones, micro-segmentation contains it within one — between the individual components of a single application.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 8
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
4. Segmentation and the AI Trust Boundary
At the network security level, the mechanism of Zero Trust enforcement is macro-segmentation, in
practical terms this allows the division of the enterprise network and the AI ecosystem into zones, each containing workloads of a similar trust level, with controlled traffic between them. Within a trust zone more granular levels of access can be enforced using micro and nano segmentation. For the purposes of this design pattern the macro boundary is a chokepoint between zones
of trust so it's the natural place to apply threat prevention, within a zone the micro and macro security functions reduce the paths between assets of the same trust.
In our model, we define the AI trust boundary as that which sites between trust zones, as this is where
we will apply threat prevention capabilities, however we can still enforce segment inside the trust zone,
so that traffic between assets is visible and can be subjected to enforcement.
What is important is that trust boundaries and microsegment must be enforced by a security function
capable of inspecting and authorizing the traffic that crosses it and that as traffic types change so too should the enforcement capability.
Core principle
A macro-segment boundary is a trust boundary. Every trust boundary must be enforced by a security function.
Macro-segmentation contains a breach between zones, micro-segmentation contains it within one — between the
individual components of a single application.
Why nano-segmentation matters for AI
For any organization running AI agents in production, the absence of nano-segmentation means there is no
enforceable limit on what a compromised or manipulated agent can do once it has been granted its initial access.
Macro and micro controls contain the zone and the application. Nano controls contain the agent itself.
The Case for AI Zero Trust 9
AI Security Functions to enforce macro and micro segmentation.
For conventional enterprise traffic the enforcement function is a next-generation firewall or an authenticating proxy. These controls inspect packet headers, identify applications, apply IPS signatures, and decrypt TLS where policy permits. They are the right tool for traffic whose threats are structural — known exploits, protocol abuse, credential theft.
AI traffic is fundamentally different and so are the “payloads” that can make it malicious. For example, a natural-language prompt carrying an injection payload traveling inside a well-formed HTTPS request will be permitted by a conventional firewall. AI attacks are semantic, and not structural, they are embedded in the meaning of the content, not its format. Where an AI workload sits at a trust boundary, the enforcement function must operate at the semantic layer.
Traffic type Enforcement function Security Capability
General network
traffic
AI Network Firewall, NGFW, SASE, cloud proxy
Layers 3–7, application identity, IPS signatures, TLS inspection
Web & API traffic Web Application Firewall (WAF) / API proxy
HTTP/S, injection attacks, authentication, rate limits
Intra-zone traffic (Micro segmentation)
Container, virtual machine security agent, for example Illumio
access control (lateral-movement prevention)
AI model traffic Secure LLM Gateway with AI-aware policy, Prompt Injection (AI) Firewall
Prompts exchanged with foundation models and carrying semantic meaning and user intent.
MCP Traffic Secure LLM Gateway and/or AI Network firewall
Client-to-server exchanges invoking tools, reading resources, and passing context between MCP hosts and servers.
Agentic Traffic AI Firewall, endpoint agent
Autonomous agent actions that read, write, or modify data and chain tool calls across systems on a user's behalf.
Key Point
Each function above is a Policy Enforcement Point. The first two are well-established. The bottom three are unique to AI networks — and most enterprises haven't built them yet, which means the trust boundaries don't exist either.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 9
Traffic type Enforcement function Security Capability
General network traffic
AI Network Firewall, NGFW, SASE, cloud proxy
Layers 3–7, application identity, IPS signatures, TLS inspection
Web & API traffic Web Application Firewall (WAF) / API proxy
HTTP/S, injection attacks, authentication, rate limits
AI model traffic Secure LLM Gateway with AI-aware
policy, Prompt Injection (AI) Firewall
Prompts exchanged with foundation models and carrying semantic meaning and user intent.
Intra-zone traffic
(Micro segmentation)
Container, virtual machine security agent, for example Illumio
access control (lateral-movement prevention)
MCP Traffic Secure LLM Gateway and/or AI
Network firewall
Client-to-server exchanges invoking tools, reading resources, and passing context between MCP hosts and servers.
Agentic Traffic AI Firewall, endpoint agent
Autonomous agent actions that read, write, or modify data and chain tool calls across systems on a user's behalf.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
AI Security Functions to enforce macro and micro segmentation.
For conventional enterprise traffic the enforcement function is a next-generation firewall or an
authenticating proxy. These controls inspect packet headers, identify applications, apply IPS
signatures, and decrypt TLS where policy permits. They are the right tool for traffic whose threats are
structural — known exploits, protocol abuse, credential theft.
AI traffic is fundamentally different and so are the “payloads” that can make it malicious. For example, a natural-language prompt carrying an injection payload traveling inside a well-formed HTTPS
request will be permitted by a conventional firewall. AI attacks are semantic, and not structural, they are embedded in the meaning of the content, not its format. Where an AI workload sits at
a trust boundary, the enforcement function must operate at the semantic layer.
Key Point
Each function above is a Policy Enforcement Point. The first two are well-established. The bottom three are unique
to AI networks — and most enterprises haven't built them yet, which means the trust boundaries don't exist either.
The Case for AI Zero Trust 10
5. Practical Implementation: The Five-Zone Topology The conventional three or four zone model — perimeter, DMZ, internal, and restricted — was sufficient for networks of conventional applications operated by human users. It does not describe an AI-driven agentic enterprise. Two new zones are required, each carrying trust characteristics that conventional zone classifications were never designed to handle. The diagram below places the new AI components alongside conventional assets and shows which controls must enforce each zone boundary.
New AI Zones
Zone 1:
Users & Perimeter
Zone 2:
Applications & Frontend
Zone 3:
AI Orchestration & Models
Zone 4:
AI Agents
Zone 5:
Tools, Data & Core Systems
Assets protected Assets protected Assets protected Assets protected Assets protected
Employees
External Users
Web Apps
Chatbots
Private LLMs
Public LLMs
AI Agents
Agent Workflows
MCP Servers
Business Tools
AI Workspaces / Public AI Copilots
AI Applications
AI Factory / GPU Infrastructure
Autonomous Tasks APIs
Databases
Core Apps
Primary security controls Primary security controls Primary security controls Primary security controls Primary security controls
AI Network Firewall
WAF / API Security
AI Firewall
API Protection
Secure LLM Gateway *
AI Network Firewall *
AI Network Firewall
Agent Identity Awareness
AI Network Firewall
MCP / Tool Inspection
Anti-Bot & DDoS Application Inspection Model Routing & Policy Behavior Monitoring Access Control
Shadow AI Discovery Prompt Inspection DLP / Content Controls Least-Privilege Access Segmentation
Micro-Segmentation DLP
* Prompt Defense
Figure 1 | The five-zone AI Zero Trust topology. Each zone contains the assets it protects and the primary security controls that enforce its boundary.
*Zones 3 and 4 are new — and they must be explicitly created
An organization that deploys AI workloads without establishing Zones 3 and 4 as discrete trust domains has, in effect, created a direct path from untrusted external input to privileged internal systems. The boundary between Zone 2 and Zone 3 can only be meaningfully enforced by an AI-aware gateway capable of inspecting prompt content. The greater exposure in practice is indirect — adversarial instructions embedded in retrieved content — so enforcement at this boundary must inspect both retrieved and tool-returned content, not only end-user prompts.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 10
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
5. Practical Implementation: The Five-Zone Topology
The conventional three or four zone model — perimeter, DMZ, internal, and restricted — was sufficient
for networks of conventional applications operated by human users. It does not describe an AI-driven
agentic enterprise. Two new zones are required, each carrying trust characteristics that conventional zone classifications were never designed to handle. The diagram below places the new AI
components alongside conventional assets and shows which controls must enforce each zone boundary.
New AI Zones
Figure 1 | The five-zone AI Zero Trust topology. Each zone contains the assets it protects and the
primary security controls that enforce its boundary.
*Zones 3 and 4 are new — and they must be explicitly created
An organization that deploys AI workloads without establishing Zones 3 and 4 as discrete trust domains has, in
effect, created a direct path from untrusted external input to privileged internal systems. The boundary between
Zone 2 and Zone 3 can only be meaningfully enforced by an AI-aware gateway capable of inspecting prompt content.
The greater exposure in practice is indirect — adversarial instructions embedded in retrieved content — so
enforcement at this boundary must inspect both retrieved and tool-returned content, not only end-user prompts.
Zone 2:
Applications & Frontend
Zone 3:
AI Orchestration & Models
Zone 4:
AI Agents
Zone 5:
Tools, Data & Core Systems
Zone 1:
Users & Perimeter
Assets protected
Primary security controls
Employees
External Users
AI Workspaces / Public AI
AI Network Firewall
WAF / API Security
Anti-Bot & DDoS
Shadow AI Discovery
Assets protected
Primary security controls
Web Apps
Chatbots
Copilots
AI Applications
AI Firewall
API Protection
Application Inspection
Prompt Inspection
Assets protected
Primary security controls
Private LLMs
Public LLMs
AI Factory /
Secure LLM Gateway *
AI Network Firewall *
Model Routing & Policy
DLP / Content Controls
Assets protected
Primary security controls
AI Agents
Agent Workflows
Autonomous Tasks
AI Network Firewall
Agent Identity Awareness
Behavior Monitoring
Least-Privilege Access
Micro-Segmentation
Assets protected
Primary security controls
MCP Servers
Business Tools
APIs
Databases
Core Apps
AI Network Firewall
MCP / Tool Inspection
Access Control
Segmentation
DLP
* Prompt Defense
The Case for AI Zero Trust 11
AI Trust Zone Transitions
AI ecosystems are complex, with multiple new connections per asset. Securing that complexity requires architects and engineers to identify every point at which traffic crosses a trust boundary — a trust transition.
The table below shows where the most relevant OWASP LLM and Agentic risks arise across these transitions and which controls should be enforced at each boundary. It turns AI risk from a conceptual discussion into an actionable architecture view — showing security and enterprise teams where AI- specific controls (AI Firewall, AI Secured Gateway, prompt defense, agent controls, MCP inspection) must be applied first.
Zones / Trust
transition
OWASP LLM Risks OWASP Agentic Risks
Zone 1 → 2
Users to frontend
LLM01 Prompt Injection;
LLM04 Model Denial of Service; LLM09 Overreliance
ASI01 Agent Goal Hijack (indirect, seeded at input); ASI09 Human-Agent Trust Exploitation
Zone 2 → 3 Applications to orchestration
LLM01 Prompt Injection;
LLM06 Sensitive Information Disclosure; LLM04 Model Denial of Service; LLM10 Model Theft
ASI01 Agent Goal Hijack; ASI03 Identity & Privilege Abuse
Inside Zone 3 LLM03 Training Data Poisoning; LLM05 Supply Chain Vulnerabilities; LLM10 Model Theft; LLM06 Sensitive
Information Disclosure
ASI04 Agentic Supply Chain Compromise; ASI06 Memory & Context Poisoning
Zone 3 → 4
Models to agents
LLM02 Insecure Output Handling; LLM08 Excessive Agency; LLM09 Overreliance
ASI01 Agent Goal Hijack; ASI05 Unexpected Code Execution; ASI09 Human-Agent Trust Exploitation
Zone 4 → 5
Agents to tools, MCP, APIs, data
LLM07 Insecure Plugin Design; LLM08 Excessive Agency; LLM02 Insecure Output Handling; LLM06 Sensitive Information Disclosure
ASI02 Tool Misuse & Exploitation; ASI03 Identity & Privilege Abuse; ASI05 Unexpected Code Execution; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI10 Rogue Agents
Zone 5 → 3 / 4 Retrieval and enterprise data returning
LLM01 Prompt Injection; LLM06 Sensitive Information Disclosure; LLM02 Insecure Output Handling
ASI06 Memory & Context Poisoning; ASI01 Agent Goal Hijack (indirect); ASI04 Agentic Supply Chain Compromise
NOTE: For Product mapping see pages 13, 14
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 11
AI Trust Zone Transitions
AI ecosystems are complex, with multiple new connections per asset. Securing that complexity
requires architects and engineers to identify every point at which traffic crosses a trust boundary — a trust transition.
The table below shows where the most relevant OWASP LLM and Agentic risks arise across these
transitions and which controls should be enforced at each boundary. It turns AI risk from a conceptual discussion into an actionable architecture view — showing security and enterprise teams
where AI-specific controls (AI Firewall, AI Secured Gateway, prompt defense, agent controls, MCP
inspection) must be applied first.
NOTE: For Product mapping see pages 13, 14
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
Zones / Trust transition
OWASP LLM Risks OWASP Agentic Risks
Users to frontend LLM01 Prompt Injection; LLM04 Model Denial of Service; LLM09 Overreliance
ASI01 Agent Goal Hijack (indirect, seeded at
input); ASI09 Human-Agent Trust Exploitation
Applications to orchestration
LLM01 Prompt Injection; LLM06 Sensitive Information
Disclosure; LLM04 Model Denial of Service; LLM10 Model Theft
ASI01 Agent Goal Hijack; ASI03 Identity &
Privilege Abuse
Inside Zone 3 LLM03 Training Data Poisoning; LLM05 Supply Chain Vulnerabilities; LLM10 Model Theft; LLM06 Sensitive Information Disclosure
ASI04 Agentic Supply Chain Compromise;
ASI06 Memory & Context Poisoning
Models to agents LLM02 Insecure Output Handling; LLM08 Excessive Agency; LLM09 Overreliance
ASI01 Agent Goal Hijack; ASI05 Unexpected
Code Execution; ASI09 Human-Agent Trust Exploitation
Agents to tools, MCP, APIs, data
LLM07 Insecure Plugin Design; LLM08 Excessive Agency; LLM02
Insecure Output Handling; LLM06 Sensitive Information Disclosure
ASI02 Tool Misuse & Exploitation; ASI03 Identity & Privilege Abuse; ASI05 Unexpected
Code Execution; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI10 Rogue Agents
Retrieval and
enterprise data returning
LLM01 Prompt Injection; LLM06 Sensitive Information Disclosure; LLM02 Insecure Output Handling
ASI06 Memory & Context Poisoning; ASI01 Agent Goal Hijack (indirect); ASI04 Agentic Supply Chain Compromise
The Case for AI Zero Trust
Management-Plane Trust Transitions
Transitions fall into two categories. Data-plane transitions carry user and application traffic through the running system. Management-plane transitions are how the system itself is built, changed, and observed — and their compromise is often more damaging, because it rewrites the rules the data plane operates under. Both must be enumerated; most organisations enforce only a subset of either.
A single compromised CI/CD pipeline or model registry can silently weaken every data-plane control the organisation has deployed — which is exactly why sophisticated attackers target it first. Management-plane traffic is how the AI system gets built, changed, and observed. It originates outside the zone topology — from corporate admin networks, CI/CD platforms, model registries, observability services — and its compromise is often more damaging than a data-plane breach: it doesn't evade the rules, it rewrites them.
Conventional Controls Remain Necessary
AI-specific controls do not replace conventional ones — they sit alongside them. NGFWs continue to enforce zone boundaries for non-AI traffic. WAFs continue to protect web and API layers. Identity- based policy, IPS, TLS inspection, MFA, and SIEM all retain their existing roles. The two sets of controls are additive, not substitutive, and both are required in a Zero Trust architecture that includes AI workloads.
12
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 12
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
Management-Plane Trust Transitions
Transitions fall into two categories. Data-plane transitions carry user and application traffic through the running system. Management-plane transitions are how the system itself is built, changed, and observed — and their compromise is often more damaging, because it rewrites the rules the data plane
operates under. Both must be enumerated; most organisations enforce only a subset of either. A single compromised CI/CD pipeline or model registry can silently weaken every data-plane control
the organisation has deployed — which is exactly why sophisticated attackers target it first. Management-plane
traffic is how the AI system gets built, changed, and observed. It originates outside the zone topology — from
corporate admin networks, CI/CD platforms, model registries, observability services — and its compromise is often
more damaging than a
data-plane breach: it doesn't evade the rules, it rewrites them.
Conventional Controls Remain Necessary AI-specific controls do not replace conventional ones — they sit alongside them. NGFWs continue to enforce zone boundaries for
non-AI traffic. WAFs continue to protect web and API layers. Identity-based policy, IPS, TLS inspection, MFA, and SIEM all retain their
existing roles. The two sets of controls are additive, not substitutive, and both are required in a Zero Trust architecture that
includes AI workloads.
The Case for AI Zero Trust 13
6. Check Point AI Zero Trust Solutions At the component layer, Check Point implements AI Zero Trust through a full-stack portfolio of AI security technologies designed to protect every zone in the enterprise AI ecosystem, from workforce use of GenAI and AI applications to agentic workflows, AI firewalls, and GPU-based AI infrastructure. By mapping Check Point technology to zones we enable organizations to protect AI interactions, govern autonomous behaviour, secure models and data paths, and enforce Zero Trust controls across the entire AI ecosystem.
AI Zero Trust
principle / risk
Check Point
product
Zone /
boundary
What it contributes
Assume breach at
the AI interaction
layer
AI Network Firewall / Web
Application
Firewall
Zone 1 → 2
and Zone 2 →
3
Extends conventional firewall /
WAF enforcement into AI
interactions, with AI-aware
protection for GenAI apps and
APIs.
Govern workforce
use of GenAI
Workforce AI
Security
Zone 1 Visibility and governance of
employee use of AI tools,
copilots, and AI-enabled
applications.
Discover and govern
AI applications and
agents
AI Agent Security
Zones 3 & 4 Unified architecture to discover,
protect, and govern AI across
workforce, applications, and
agents
Micro- segmentation
Check Point Security Mgmt + Illumio microsegmentation
Zones 3 & 4 Prevent lateral movement between and within the micro segments & Kubernetes
Continuously validate
AI systems
AI Red Teaming Zones 3 & 4
(validation)
Continuous adversarial testing
across prompts, reasoning
paths, workflows, tool use, and
agent behaviour.
Segment and protect
private LLM and GPU
environments:
AI Factory
Firewall (AIFF)
Inside Zone 3
(east-west)
Check Point NGFW for AI workloads, running on NVIDIA BlueField DPUs.
Reduce blast radius
across the network
AI Network Firewall & Maestro Hyperscale Firewall
All zone
boundaries
Foundational enforcement layer
for hybrid mesh and enterprise
network Zero Trust
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 13
AI Zero Trust
principle / risk Check Point
product Zone / boundary
What it contributes
Assume breach at the AI interaction
layer
AI Network
Firewall / Web Application Firewall
3
Extends conventional firewall / WAF enforcement into AI interactions, with AI-aware protection for GenAI apps and APIs.
Govern workforce use of GenAI
Workforce AI
Security Zone 1 Visibility and governance of
employee use of AI tools, copilots, and AI-enabled applications.
Discover and govern AI applications and agents
AI Agent Security
Zones 3 & 4 Unified architecture to discover, protect, and govern AI across workforce, applications, and agents
Micro-segmentation Check Point
Security Mgmt + Illumio
microsegmentation
Zones 3 & 4 Prevent lateral movement between and within the
micro segments & Kubernetes
Continuously validate
AI systems
AI Red Teaming Zones 3 & 4
(validation) Continuous adversarial testing across prompts, reasoning paths, workflows, tool use, and agent behaviour.
Segment and protect private LLM and GPU environments:
AI Factory Firewall (AIFF)
Inside Zone 3
(east-west) Check Point NGFW for AI
workloads, running on NVIDIA BlueField DPUs.
Reduce blast radius across the network
AI Network Firewall & Maestro
Hyperscale Firewall
All zone boundaries
Foundational enforcement layer for hybrid mesh and enterprise network Zero Trust
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
6. Check Point AI Zero Trust Solutions
At the component layer, Check Point implements AI Zero Trust through a full-stack portfolio of AI
security technologies designed to protect every zone in the enterprise AI ecosystem, from workforce
use of GenAI and AI applications to agentic workflows, AI firewalls, and GPU-based AI infrastructure. By mapping Check Point technology to zones we enable organizations to protect
AI interactions, govern autonomous behaviour, secure models and data paths, and enforce Zero Trust
controls across the entire AI ecosystem.
The Case for AI Zero Trust
Architectural Summary: Five trust zones, each with dedicated Check Point controls
Zone 1:
Users & Perimeter
Zone 2:
Applications & Frontend
Zone 3:
AI Orchestration & Models
Zone 4:
AI Agents
Zone 5:
Tools, Data & Core Systems
AI Network Firewall AI Network Firewall AI Network Firewall Prompt defense AI Factory Firewall/BlueField
Workforce AI security Secure LLM Gateway AI Red Teaming AI Red Teaming Maestro Hyperscale
ZTNA / SASE WAF / API security ThreatCloud AI ThreatCloud AI Check Point + Illumio
Identity access control
Never trust
user / agent
Inspect
all traffic
Least
privilege
Never trust
prompts / output
Assume
breach
14
AI Zero Trust | Architectural Summary
Five trust zones, each with dedicated Check Point security controls.
From Left to Right: users (and machines) enter through ZTNA, cross the AI Network Firewall, reaching agents governed by agentic security, and then reach LLMs defended by prompt defense. AI compute workload runs on GPU clusters inside the AI Data Center ("AI Factory"). The AI data center is protected by AI Factory Firewalls along with multiple overlapping AI security layers including AI runtime inspection from beginning to end. One platform, with every boundary enforced.
Two control points carry most of this load.
AI Network Firewall: extends the traditional NGFW with AI-aware inspection and segmentation, including prompt- injection detection and policy enforcement between users, agents, models, and sensitive enterprise systems.
Secure LLM Gateway: the dedicated control point for AI and model interactions, covering secure LLM routing, prompt defense, content and policy inspection, and governance over how AI applications and agents connect to internal and external models.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 14
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
AI Zero Trust | Architectural Summary
Five trust zones, each with dedicated Check Point security controls.
From Left to Right: users (and machines) enter through ZTNA, cross the AI Network Firewall, reaching
agents governed by agentic security, and then reach LLMs defended by prompt defense. AI compute
workload runs on GPU clusters inside the AI Data Center ("AI Factory"). The AI data center is protected by AI Factory Firewalls along with multiple overlapping AI security layers including AI runtime inspection from beginning to end. One platform, with every boundary enforced.
Architectural Summary: Five trust zones, each with dedicated Check Point controls
AI Network Firewall
Secure LLM Gateway
WAF / API security
Zone 2:
Applications & Frontend
AI Network Firewall
AI Red Teaming
ThreatCloud AI
Zone 3:
AI Orchestration & Models
Prompt defense
AI Red Teaming
ThreatCloud AI
Zone 4:
AI Agents
AI Factory Firewall/BlueField
Maestro Hyperscale
Check Point + Illumio
Zone 5:
Tools, Data & Core Systems
AI Network Firewall
Workforce AI security
ZTNA / SASE
Identity access control
Zone 1:
Users & Perimeter
Never trust user / agent
Inspect all traffic
Least
privilege Never trust
prompts / output Assume
breach
Two control points carry most of this load.
AI Network Firewall: extends the traditional NGFW with AI-aware inspection and segmentation, including prompt-injection detection and policy enforcement between users, agents, models, and sensitive enterprise systems. Secure LLM Gateway: the dedicated control point for AI and model interactions, covering secure LLM routing, prompt defense, content and policy inspection, and governance over how AI applications
and agents connect to internal and external models.
The Case for AI Zero Trust 15
7. Where to Start – A Five-Phase Executive Approach to AI Zero Trust
01 Conduct a risk-based AI security assessment
Start by understanding where AI creates material business and cyber risk. Leadership should direct a structured assessment of AI use cases, agents, models, applications, and supporting infrastructure against recognized frameworks such as OWASP LLM, OWASP Agentic risks, and MITRE ATLAS, to identify the most relevant threats, control gaps, and priority exposures.
Check Point has published the following assets to help you:
Check Point AI Risk Matrix Tool
White Paper | Agentic AI Security: The Enterprise Playbook
AI Data Center & AI Factory Security Blueprint
02 Make the AI estate visible
Once risk has been framed, the next step is to build visibility into where AI already exists or
is planned. This means identifying major AI use cases, model connections, agents, AI-
enabled applications, and critical tool or data dependencies across the enterprise, including
informal or shadow deployments that may sit outside current governance.
03 Define the trust zones
With visibility established, the organization should classify AI components into a clear trust
model. Architecture and security teams should use the five-zone approach to distinguish AI
orchestration, model environments, agents, and MCP or tool access from existing DMZ and
internal zones, creating the policy and segmentation foundation for AI Zero Trust.
04 Prioritize and protect the highest-risk boundaries
Not every boundary carries the same business impact, so leadership should focus first on
the trust transitions that matter most. Priority should be given to the boundaries where
compromise could expose sensitive data, enable autonomous action, or create systemic
operational risk — such as application-to-model, model-to-agent, and agent-to-core-
system interactions — and where AI-specific controls such as AI firewalls, AI secured
gateways, prompt defence, and tool inspection are required.
05 Assign ownership and operational accountability
Finally, AI Zero Trust must be turned into an operating model, not left as an architectural
concept. Security and enterprise architecture teams should define the framework. AI and
application teams should define intended behaviour and acceptable action scope. And
infrastructure and network teams should enforce segmentation and resilience. These
responsibilities must be explicitly assigned before AI workloads scale into production.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
The Case for AI Zero Trust 15
01 Conduct a risk-based AI security assessment
Start by understanding where AI creates material business and cyber risk. Leadership
should direct a structured assessment of AI use cases, agents, models, applications, and
supporting infrastructure against recognized frameworks such as OWASP LLM, OWASP
Agentic risks, and MITRE ATLAS, to identify the most relevant threats, control gaps, and priority exposures.
Check Point has published the following assets to help you:
Check Point AI Risk Matrix Tool
White Paper | Agentic AI Security: The Enterprise Playbook
AI Data Center & AI Factory Security Blueprint
02 Make the AI estate visible
Once risk has been framed, the next step is to build visibility into where AI already exists or
is planned. This means identifying major AI use cases, model connections, agents, AI-
enabled applications, and critical tool or data dependencies across the enterprise, including
informal or shadow deployments that may sit outside current governance.
03 Define the trust zones
With visibility established, the organization should classify AI components into a clear trust
model. Architecture and security teams should use the five-zone approach to distinguish AI
orchestration, model environments, agents, and MCP or tool access from existing DMZ and
internal zones, creating the policy and segmentation foundation for AI Zero Trust.
© 2026 Check Point Software Technologies Ltd. All Rights Reserved
7. Where to Start – A Five-Phase Executive Approach to AI Zero Trust
04 Prioritize and protect the highest-risk boundaries
Not every boundary carries the same business impact, so leadership should focus first on
the trust transitions that matter most. Priority should be given to the boundaries where
compromise could expose sensitive data, enable autonomous action, or create systemic
operational risk — such as application-to-model, model-to-agent, and agent-to-core- system interactions — and where AI-specific controls such as AI firewalls, AI secured
gateways, prompt defence, and tool inspection are required.
05 Assign ownership and operational accountability
Finally, AI Zero Trust must be turned into an operating model, not left as an architectural
concept. Security and enterprise architecture teams should define the framework. AI and
application teams should define intended behaviour and acceptable action scope. And
infrastructure and network teams should enforce segmentation and resilience. These
responsibilities must be explicitly assigned before AI workloads scale into production.
https://airiskmatrix.org/ https://www.checkpoint.com/resources/all-assets-460c/white-paper-agentic-ai-security-the-enterprise-playbook https://engage.checkpoint.com/ai-data-center-ai-factory-security-blueprint https://airiskmatrix.org/ https://www.checkpoint.com/resources/all-assets-460c/white-paper-agentic-ai-security-the-enterprise-playbook https://engage.checkpoint.com/ai-data-center-ai-factory-security-blueprint
The Case for AI Zero Trust
8. Conclusion Anthropic Mythos and other advanced frontier AI models have raised the risk level for all enterprises: AI-driven attacks are becoming faster, cheaper, and harder to contain, while many enterprise AI systems remain highly vulnerable. Meeting the challenges of AI cybersecurity demands adaptation. AI Zero Trust is the required evolution of Zero Trust principles applied to AI systems. It's an effective model for practitioners because it's built on the assumptions that now matter most: assume breach, enforce least privilege, and contain compromise at every boundary.
The priority for leadership is to move quickly, treat AI security as a business resilience issue, and extend AI Zero Trust across the AI estate before gaps in protection result in costly business disruption and loss of trust or confidence.
About Check Point Check Point Software Technologies Ltd. is a global cyber security leader protecting more than 100,000 organizations worldwide. Its mission is to secure enterprises’ AI transformation. Built on a prevention first approach and an open ecosystem architecture, Check Point helps organizations reduce risk, simplify operations, and innovate with confidence. This unified security architecture continuously adapts to evolving threats and expanding AI attack surfaces, protecting hybrid networks, cloud environments, digital workspaces, and AI systems. Structured around four strategic pillars, Hybrid Mesh Network Security, Workspace Security, Exposure Management, and AI Security, Check Point delivers consistent protection and visibility across complex multivendor environments.
Learn More
16
Securing the AI Data Center & AI Factory Contact Us
Worldwide Headquarters
5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599
U.S. Headquarters
100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391
www.checkpoint.com
© 2026 Check Point Software Technologies Ltd. All rights reserved. | Updated v.0 July 28, 2026
The Case for AI Zero Trust 16
8. Conclusion
Anthropic Mythos and other advanced frontier AI models have raised the risk level for all enterprises: AI-driven attacks are becoming faster, cheaper, and harder to contain, while many
enterprise AI systems remain highly vulnerable. Meeting the challenges of AI cybersecurity demands adaptation.
AI Zero Trust is the required evolution of Zero Trust principles applied to AI systems. It's an effective model for practitioners because it's built on the assumptions that now matter most: assume
breach, enforce least privilege, and contain compromise at every boundary.
The priority for leadership is to move quickly, treat AI security as a business resilience issue, and
extend AI Zero Trust across the AI estate before gaps in protection result in costly business disruption and loss of trust or confidence.
About Check Point
Check Point Software Technologies Ltd. is a global cyber security leader protecting more than 100,000
organizations worldwide. Its mission is to secure enterprises’ AI transformation. Built on a prevention
first approach and an open ecosystem architecture, Check Point helps organizations reduce risk,
simplify operations, and innovate with confidence. This unified security architecture continuously adapts to evolving threats and expanding AI attack surfaces, protecting hybrid networks, cloud environments, digital workspaces, and AI systems. Structured around four strategic
pillars, Hybrid Mesh Network Security, Workspace Security, Exposure Management, and AI Security,
Check Point delivers consistent protection and visibility across complex multivendor environments.
Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599
U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391
www.checkpoint.com
© 2026 Check Point Software Technologies Ltd. All rights reserved. | Updated v.0 July 28, 2026
Learn More
Securing the AI Data Center & AI Factory Contact Us
https://engage.checkpoint.com/executive-guide-securing-the-ai-data-center-ai-factory https://pages.checkpoint.com/2026-mar-ww-ai-factory-and-data-center-security.html https://engage.checkpoint.com/executive-guide-securing-the-ai-data-center-ai-factory https://pages.checkpoint.com/2026-mar-ww-ai-factory-and-data-center-security.html