
Google has published Beyond Zero, a research-backed successor to BeyondCorp that extends zero-trust security into the age of autonomous AI agents. The company describes it as a “security model for the AI era,” shifting authorization from broad application access to individual resources and actions, with machine-speed decisions designed to work for both people and agents.
Google’s Beyond Zero reframes enterprise trust
In the paper, Google argues that the assumptions behind BeyondCorp are no longer enough. BeyondCorp, first outlined in 2014, helped popularize the idea of replacing network-perimeter security with a zero-trust approach for enterprise access. Beyond Zero takes that idea further by treating each action as a distinct authorization event, rather than assuming that a user or system session can be trusted once access is granted.
That shift matters because the enterprise environment has changed. Google says AI agents are now being deployed globally to increase operational velocity and improve productivity, and those agents do not behave like traditional human users. According to the paper, access control now needs to account for autonomous actors that can operate at scale, move quickly, and initiate actions without the same patterns of timing or intent that security teams have historically expected from employees.
From applications to individual actions
Beyond Zero moves the decision point from the application level to the level of individual resources and actions. In practice, that means access decisions can be made with contextual and risk-based controls that continuously evaluate each action, whether it is initiated by a person or an AI agent.
Google says the model combines static authorization policies with dynamic controls for higher-risk scenarios. It also relies on automatically enriched context about users, actions, data, and risk signals, plus automated investigation when those signals indicate something unusual. In some cases, the model can apply challenges or containment measures that require additional verification or telemetry from users and AI agents before an action is allowed to proceed.
The five principles behind the model
Google says Beyond Zero is built on five principles. Those principles are intended to guide how enterprises think about authorization when humans and AI agents share the same systems and data.
- Authorization at the level of individual actions and resources across interfaces and APIs.
- A mix of static policies and dynamic controls for scenarios with greater risk.
- Automatically enriched context about users, actions, data, and risks.
- Automated investigation triggered by risk signals.
- Challenges or containment measures that can require extra verification or telemetry from users and AI agents.
Google presents these principles as a response to a world where authorization can no longer be treated as a one-time gate at the application boundary. Instead, the company is pushing for “continuous authorization” at a much finer level, so enterprises can enforce policy at machine speed.
What Google says changed since BeyondCorp
The paper is framed as an evolution rather than a rejection of Google’s earlier security work. Joseph Valente, formerly director of product management at Google, and Michal Zalewski, a distinguished security researcher and formerly at Google, write that the core assumptions behind BeyondCorp have broken down.
The assumptions underpinning BeyondCorp — that accessors are human, that actions occur at human speed, and that applications are the correct boundary for trust—are no longer sufficient.
That statement captures the central idea of Beyond Zero. Security models built around people logging into apps no longer fully fit environments where software agents can perform repeated actions continuously, potentially across many systems, with little or no human intervention.
Google frames the challenge as one of scale as much as technology. In a LinkedIn post, Valente wrote that continuous authorization of every action at scale “seemed like overkill at first,” but the world changed as organizations grew from thousands of workers to hundreds of thousands, and then to millions of agents.
Beyond Zero is one of those areas where Google had built something internally that was well ahead of anyone else for a long time. Doing continuous authorization of every action at scale seemed like overkill at first. But then thousands of workers became hundreds of thousands of workers. Hundreds of thousands of workers were joined by millions of agents. And so on…
Industry reaction is cautious
While Google positions Beyond Zero as a new paradigm for enterprise security, the early reaction has been mixed. On LinkedIn and in related commentary, the concept has been welcomed as a serious attempt to update security architecture for AI-driven systems, but several practitioners have questioned whether most organizations can realistically adopt it in the near term.
Kane Narraway, security manager at Canva, was supportive of the direction but skeptical about practical rollout. In his piece “Beyond Zero: For The Rest Of Us,” he wrote that the paper is aspirational and that Google says the deployment is internal-only, not all components are built, and more papers are coming. He also cautioned that ordinary enterprises should not assume they can mirror Google’s internal model directly.
It’s worth being clear about what this paper is and isn’t though. It’s aspirational. Google says deployments are internal-only, the components aren’t all built, and more papers are coming. This is the same playbook as 2014: publish the vision, describe the architecture at a high level, and encourage the industry to build towards it collaboratively (…) You aren’t Google and don’t try to be.
On Hacker News, discussion has been largely skeptical so far. One commenter argued that zero trust is deterministic while AI is non-deterministic, making AI-driven authorization a poor fit for access control. Another concern raised by practitioners is that access control is usually treated as a hard security boundary, while probabilistic decisions are harder to predict, test, and audit.
Zero trust is deterministic. AI is non-deterministic. Non-deterministic access controls are a terrible idea.
Why enterprise teams may struggle to adopt it quickly
Google’s model may be compelling in theory, but the practical barriers are significant. SaaS vendors would need to expose authorization at the action level, and the broader standards ecosystem would have to mature before the approach can become common outside a small number of large platforms.
Google also acknowledges that smaller security teams face difficult trade-offs around false positives, intent detection, auditing, and cost. Those are not minor operational details. They are the kinds of issues that determine whether a security model can actually be deployed in production, especially when every action may need to be continuously evaluated.
Firas Durri summed up one response from practitioners by arguing that the path to AI-agent readiness involves increasing software auditability and reversibility. That view reflects a broader concern: if organizations are going to let autonomous agents act in business systems, they need better records of what happened and a reliable way to roll back or contain mistakes.
What Google has not said yet
Google is not presenting Beyond Zero as a finished product. Instead, it describes the work as ongoing and says it plans to publish more detail on implementation and operational considerations. At the same time, the company has not published specific deadlines for those follow-up materials.
That leaves enterprise leaders with a familiar mix of ambition and uncertainty. The paper sketches a security model that is designed for a world of humans and agents acting together, but many of the hardest questions remain open: how to tune policy, how to limit false alarms, how to audit AI decisions, and how to keep the system usable for everyday operations.
For now, Beyond Zero is best understood as Google’s attempt to define the next step beyond zero trust. BeyondCorp focused on trust without a network perimeter. Beyond Zero focuses on trust when the “user” may be an AI agent, the “session” may be continuous, and the pace of action may be far faster than a human security workflow can handle.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 5, 2026 at 10:22 pm
1 views
