Google proposes Beyond Zero security model for AI-era enterprise access

Google proposes Beyond Zero security model for AI-era enterprise access

Google introduced Beyond Zero, a security model for AI-era enterprises built around contextual, resource-level authorization.

Format News Brief
Read Time 3 min
Category Cyber Security
Updated Jul 28, 2026

Google is using its latest security publication to argue that traditional zero-trust controls need a narrower, faster authorization layer as companies give AI agents more access to corporate systems. In a July 27 post, the company introduced Beyond Zero, a model intended to evaluate individual actions on individual resources instead of treating access to an application as the main security boundary.

The proposal builds on Google's earlier BeyondCorp work, which helped popularize zero trust by moving enterprise security away from assumptions tied to trusted networks. Google says the operating environment has changed again: AI agents can work across tools at high speed, while attackers can also use automation to move faster after stealing credentials or abusing privileged access. That combination, according to Google, requires authorization systems that can keep checking intent, resource sensitivity and risk while work is happening.

What changes

Beyond Zero has five stated principles. The first is resource- and action-based security, meaning a request to read one file, update one record or call one API can be judged separately. Google says that approach should apply consistently across interfaces, APIs and the Model Context Protocol. The second principle blends static policy with dynamic controls, so predictable rules remain auditable while higher-risk situations can trigger stronger checks.

The other principles focus on richer context, automated investigation and containment. Google describes systems that can draw on information about the user, the task, the data involved and available mitigations, then automatically start investigations or require additional verification when risk signals rise. The company says early internal prototypes and deployments have improved detection of access abuse and protection of intellectual property, while still allowing regulated work to continue.

Google is also taking the idea into the public security community. Its first technical paper on Beyond Zero has been published in ACM Queue, and the company says more papers will follow with architectural and operational details. That matters because the model is not a finished product announcement so much as a design direction for enterprises trying to secure human workers and software agents under the same authorization fabric.

The practical question is whether other vendors and standards groups converge on similar continuous authorization patterns. For now, Beyond Zero gives security teams a concrete framing for the AI-agent problem: access decisions may need to be small, contextual and machine-speed, because broad permissions granted at login are becoming a weaker fit for automated enterprise workflows.

Sources

Cover image: D Coetzee, source, licensed under CC0.

Comments (0)

Leave a Comment

Loading comments...