When the “User” Is an by Nutan NavsariwalaWhen the “User” Is an by Nutan Navsariwala

When the “User” Is an

Nutan Navsariwala

Nutan Navsariwala

When the “User” Is an AI Agent: A Zero Trust Case Study This independent research case study looks at what changes when an AI agent moves beyond answering questions and starts taking actions through tools, APIs, workflows and enterprise systems.
Using public cyber-threat reporting and Zero Trust principles, the report examines why AI agents need to be treated as a new type of non-human identity, with limited, traceable and revocable access.
The research focuses on practical questions security leaders need to ask:
What is the agent’s identity? What can it access? What can it change? How is its activity monitored? And who can stop it when something goes wrong?
The case study covers AI-agent identity, least-privilege access, segmentation, continuous verification, monitoring, access revocation and human control.
It also demonstrates my approach to cybersecurity research: finding and checking sources, connecting emerging threats with established security principles, turning technical issues into clear analysis, and presenting the findings in a way that business and security leaders can understand.
This sample is intended for security teams, CISOs, risk leaders and technology executives looking for clear, evidence-based research on AI security, Zero Trust, identity and access management, and emerging cyber risk.
Like this project

Posted Sep 25, 2026

When the “User” Is an AI Agent: A Zero Trust Case Study This independent research case study looks at what changes when an AI agent moves beyond answering qu...