# valente-zalewski-beyond-zero-enterprise-security-ai-era-2026-07-20

## Veille

Research article published in **ACM Queue** (vol. 24, no. 3 — thematic issue "LLMs") on **July 20, 2026**, authored by **Joseph Valente** (Director of Product Management, Alphabet Security) and **Michal Zalewski** (Distinguished Engineer, Alphabet Security strategist — the *lcamtuf* of offensive security). **CC BY 4.0** license, **29,143 downloads** in ten days, **a single bibliographic reference**: the 2014 **BeyondCorp** whitepaper. This is not incidental — the article explicitly positions itself as **BeyondCorp's generic successor** and takes on its function: *"publish the vision so the industry can align to it."* **Thesis**: the **application-boundary model is reaching end of life**. The three assumptions that underpinned BeyondCorp — *accessors are human, actions occur at human speed, the application is the right trust boundary* — are all three obsolete now that AI agents access data at **10 times the rate of humans** and reason over vast unstructured corpora. **Beyond Zero** therefore shifts the trust boundary **from the application to the individual action on the individual resource**, and investigation **from after-the-fact to real-time**. **Four-component architecture forming a loop**: *autonomous governance* (which uses AI to build a living **enterprise world model** — Who / What / How — by explicit analogy with a self-driving car's world model), *event intake* (server, client, and **agent activity** signals: prompts, execution plans, tool invocations), *reasoning engine* (hierarchical AI, **fast** for ABAC at access time and **slow** for inference over a sequence of actions; *allow / deny / challenge* verdict), and *challenge infrastructure* (reversible **challenges** — justification, security key tap, approval, **selfie** — vs. durable **containments**, sometimes lifted only after the security team interviews the employee and their manager). **The central design move is the floor/ceiling split**: **static policies** (the floor, statically verifiable) under a **dynamic reasoning engine** (the ceiling) — an explicit rejection of a *"fully dynamic, hard-to-statically-verify"* model. **The named attack vector**: **ambient authority**, the agent inheriting its human's full, often overprovisioned permissions. **Three reservations noted**: this is a **vision paper, not a war story** — zero production metrics, zero false-positive rate, zero deployment scale, whereas [[uber-engineering-agent-identity-crisis-zero-trust-spire-2026-05-21]] had published a P99 < 40 ms and thousands of agents in production two months earlier; an **internal order-of-magnitude inconsistency** (tens of millions of actions/s in the problem statement vs. thousands of decisions/s in the abstract and conclusion); and a **massive European blind spot** — the described system is also an employee-surveillance apparatus (selfie, client-side signals, baselining against the peer group), without a single line on GDPR, proportionality, or employee representative bodies.

## Titre Article

Beyond Zero: Enterprise security for the AI era

## Date

2026-07-20

## URL

https://spawn-queue.acm.org/doi/10.1145/3819083

## Keywords

Beyond Zero, BeyondCorp, zero trust, zero trust, trust boundary, trust boundary, enterprise security, resource-level authorization, resource-level authorization, action-level access control, ABAC, attribute-based access control, machine speed, machine speed, ambient authority, ambient authority, overprovisioned permissions, AI agents, autonomous agents, agentic identity, user intent, agent intent, intent alignment, prompt injection, enterprise world model, autonomous governance, event intake, reasoning engine, challenge infrastructure, challenges, containments, selfie check, security key, justification, approval, floor ceiling, static policies, dynamic policies, static verifiability, preprocessing, latency budget, hot cache, DLP, data loss prevention, SecOps, real-time investigation, activity window, activity window, exfiltration, insider risk, curious contractor, rogue agent, SalesGenie, self-defending enterprise, security as an immune system, NIST agent security, agentic standards, agent introspection, chain-of-thought, request annotations, PDP PEP, SaaS, Alphabet Security, Google, Michal Zalewski, lcamtuf, Joseph Valente, ACM Queue

## Authors

**Joseph Valente** — Director of Product Management, en charge des efforts de sécurité entreprise au sein d'**Alphabet Security** ; son périmètre couvre l'ensemble des business units d'Alphabet (Google Ads, DeepMind, YouTube, Devices, Cloud). Précédemment à l'origine de ce qui est devenu le **Sovereign Cloud de Google** (l'offre de compute souverain de Google Cloud) — détail notable pour un lectorat européen. Avant Google : cofondateur de Pathify et Ebla, passage par Bain & Company.

**Michal Zalewski** — Distinguished Engineer chez Google, **pilote la stratégie d'Alphabet Security**. Figure historique de la sécurité offensive (connu sous le pseudonyme **lcamtuf**), auteur de *Silence on the Wire* et *The Tangled Web* ; l'article mentionne *The Secret Life of Circuits* et son Substack. Ancien **CISO de Snap**, après plus d'une décennie à Google où il dirigeait l'information security & engineering (>100 ingénieurs), les design reviews et les exercices offensifs.

**Remerciements** (signal de portée interne) : 27 personnes citées chez Alphabet, dont **Heather Adkins** (VP Security Engineering), **Betsy Beyer** et **Rory Ward** (co-auteurs du BeyondCorp original), **Eric Grosse**, **Royal Hansen**, **Umesh Shankar**. La présence des auteurs de BeyondCorp valide la **filiation revendiquée**.

## Ton

**Profile**: an **architecture-doctrine** article published in a professional peer-reviewed journal (ACM Queue, whose readership is *practitioner* rather than academic). Register: **hyperscaler vision paper** — neither a war story, nor a specification, nor marketing, but a **category-framing document**. Target audience: CISOs, security architects, SaaS vendors, standards bodies.

**Style**: a **problem → solution → architecture → scenarios → call to industry → conclusion** structure, the canonical form of an infrastructure whitepaper. Three markers:

1. **Demolition by assumption**, rather than by fact. The article does not say "BeyondCorp failed" — it **enumerates the three assumptions** that underpinned it and shows that none still holds. An effective rhetorical figure: it frames the obsolescence as structural rather than conjunctural, and therefore not fixable by a patch.
2. **The comparison table as argumentative core** (table 1, eight rows, BeyondCorp → Beyond Zero). Each row carries its own justification in plain language. It is the document within the document — the part that will be screenshotted and recirculated.
3. **The scenario as proof**. Three vignettes (*the curious contractor*, *the suddenly foolish administrator*, *the "rogue" agent*) do the work that the figures do not. The second is a small masterpiece of human detail: a system administrator who, in another window, asks **elementary questions about their own system's architecture** — *"information that would be obvious to anyone experienced at the company."* The compromise signal is not technical, it is **cognitive**.

**Marker phrases**: *"from human-speed security to high-frequency, AI-mediated defense,"* *"augments BeyondCorp's foundational identity with a 'brain,'"* *"static policies (the floor) … a dynamic reasoning engine (the ceiling),"* *"the access bubble … dynamically flexes to be bigger or smaller,"* *"geometric shock,"* *"a self-defending enterprise,"* *"security as an immune system,"* *"unlike the blunt 'access denied' of the past."*

**Epistemic stance**: **explicitly forward-looking**. *"This article marks a milestone in Google's own effort to transition to the Beyond Zero model as well as a vision for where the industry needs to move."* The authors do not claim to have shipped anything — they announce a trajectory and call on the industry. **Honest about its status**, which will not stop the text from being read and cited as though it described a system already in production.

## Pense-betes

- **Date / source**: **July 20, 2026**, **ACM Queue** vol. 24 no. 3, CC BY 4.0, authored by **Joseph Valente** (Alphabet Security) and **Michal Zalewski**. A single bibliographic reference: the 2014 **BeyondCorp** whitepaper.
- **Key framing**: the application boundary is reaching end of life. Classic zero trust shifted trust from the network to identity and device, but kept the **application as the unit of authorization** — too coarse a unit once the accessor can reason over an entire corpus in seconds. The new proposed unit is **the individual action on the individual resource**, regardless of the access path (front-end, API, MCP). ### The three BeyondCorp assumptions the article abandons 1. Accessors are **human**. 2. Actions occur **at human speed**. 3. The **application** is the right trust boundary. Each falls for a different reason: this is not a patch, it is a model change. ### The four components, in loop order | # | Component | Content | |---|-----------|---------| | 1 | **Autonomous governance** | uses AI to build a living **enterprise world model** — **Who** (function, role, seniority, controlling human for an agent), **What** (semantic understanding of data sensitivity), **How** (assignments, usage and sharing patterns). Fed by HR and project-management data warehouses. Explicit analogy with a self-driving car's world model | | 2 | **Event intake** | server signals (proxies, APIs, productivity apps), client signals (browser state, local file access, process activity, DLP), and **agent activity** (prompts, execution plans, tool invocations). Hot cache for access-time evaluation, long-term store for slow inference | | 3 | **Reasoning engine** | hierarchical AI, distributed across server/endpoints. **Fast**: granular ABAC, blocks at access time. **Slow**: complex anomalies (a user accessing 500% more files than their peer group). *Allow / deny / challenge* verdict, and **decisions themselves become attributes** reused downstream | | 4 | **Challenge infrastructure** | reversible **challenges** (justification, security key tap, manager approval, **selfie**) vs. durable **containments**, sometimes lifted only after the employee and their manager are interviewed | ### The design move: floor / ceiling **Static** policies = the floor (security and compliance baseline, **statically verifiable**); **dynamic** reasoning engine = the ceiling. Explicit justification: this allows for dynamic behavior *"without shifting to a fully dynamic, hard-to-statically-verify model."* The entire security decision is not handed to the model. Same architectural figure as the constraint ring in [[sfeir-code-review-anneau-contraintes-2026-07-30]]. ### The named attack vector *"The exploitation of ambient authority, where an agent is granted the full, often overprovisioned permissions of its human user."* This is the mechanism by which a prompt injection becomes an exfiltration: the agent does not need to escalate privileges, it already has too many. The proposed countermeasure is not a filter on the prompt but an **intent-consistency check** — *"User Intent + Agent Intent can be interpreted and checked to ensure alignment,"* and *"The human actor must confirm that the access the agent is attempting is intended by the human."* ### The SalesGenie example, usable as-is An internal agent authorized to read sales reports queries a strategic planning document. | Model | Verdict | Reason | |---|---|---| | BeyondCorp | **ALLOW** | valid certificate, authorized machine, both identities can read sales reports | | Beyond Zero | **CHALLENGE then CONTAIN** | the human who issued the prompt only works on Northeast accounts, the data is top-tier (insider-trading risk), policy requires a valid work assignment | Three-stage intervention: intent confirmation by the human, approval request to the owning team, containment. *"In the vast majority of cases, the decision to contain will be autonomous."* ### The architecture's real bet *"Inference tasks must be front-loaded"*: access-time latency budgets rule out on-the-fly reasoning, so almost everything must be precomputed. The quality of access control then becomes **exactly equal to the quality of the HR and project-management data**. The "work assignment" attribute that decides access in the SalesGenie example presupposes a level of data hygiene few organizations reach. The first point to raise in any transposition workshop. ### Reservations
- **Vision paper, not a war story**: no production metrics, no false-positive rate, no deployment scale, no latency figures — whereas [[uber-engineering-agent-identity-crisis-zero-trust-spire-2026-05-21]] had published a P99 < 40 ms and thousands of agents in production two months earlier.
- **Internal order-of-magnitude inconsistency**: the problem statement speaks of *"tens of millions of concurrent machine-driven actions per second,"* while the abstract and conclusion speak of *"thousands of decisions per second"* — a four-order-of-magnitude gap. Do not cite both figures without flagging it.
- **Unsourced figures**: *"AI agents access data at 10 times the rate of humans,"* a central claim, unsourced.
- **False-positive cost not quantified**: the article claims that only *"a tiny percentage"* of containments would escalate to human review, without data. Yet containing an innocent employee costs a security interview with their manager; at scale, that rate is what decides whether the model is deployable.
- **The circularity is not examined**: the system defending against AI-driven attacks is itself an AI reasoning engine. No mention of attacks **against** the reasoning engine — poisoning of the HR data feeding the world model, injection into semantically analyzed documents, slow manipulation of its own behavioral baseline. ### The European blind spot The described system is also an employee-surveillance apparatus: a selfie to prove one is at their machine, client-side signals, behavioral baselining against the peer group, and derivation from HR data of what the employee **should** be doing. Not a word on GDPR, proportionality, informing employee representative bodies, or the fact that a containment revoked after interviewing the employee and their manager carries labor-law implications. This is the first transposition obstacle, and it is absent from the text. ### The call to the industry, useful as a reading grid for upcoming offerings 1. **Open architectures** — standardized APIs for agent introspection, a standard means of analyzing chain-of-thought and tool usage in real time. 2. **Agentic identity standards** — annotations making every action attributable to an agent + a controlling user + a task. 3. **Externalized decision frameworks** — making a policy-evaluation point operated by the customer organization a *first-class citizen* of every SaaS product. The politically heaviest ask: it requires vendors to accept that a third party decides access within their own product. NIST has launched an effort on agent security. ### Positioning read BeyondCorp (2014) was not a product but a publication that created a category — ZTNA/SASE, which became a market within a decade. Beyond Zero replays the same move: publish early, under CC BY, in a practitioner journal, with a call for standardization. Read it as a market-structuring document as much as an architecture. Published the day before Anthropic's write-up on its secure SDLC — [[clinton-anthropic-secure-ai-native-sdlc-2026-07-21]]: Anthropic secures code production by agents, Google secures agents' access to data. **Disambiguation**: this article's *enterprise world model* (a living representation of the organization serving authorization) has no relation to Google DeepMind's generative *world models*, even though both come from Google. Same phrase, distinct objects — do not merge them in the graph.

## RésuméDe400mots

Published in **ACM Queue** on July 20, 2026 by **Joseph Valente** and **Michal Zalewski** (Alphabet Security), this article positions itself as **successor to the 2014 BeyondCorp whitepaper** — its sole reference — and takes on its function: publishing a vision for the industry to align to.

**The diagnosis.** The application-boundary model is reaching end of life. The three assumptions that underpinned BeyondCorp — *accessors are human, actions occur at human speed, the application is the right trust boundary* — all three collapse once AI agents access data at **10 times the rate of humans**. Added to this are a *"geometric shock"* in the volume and sensitivity of data, attackers who have weaponized AI (on-demand rewriting of malicious code, newfound patience on surfaces previously deemed low-value), and a vector specific to agentic systems: **ambient authority**, the agent inheriting its human's full, often overprovisioned permissions.

**The model.** Beyond Zero shifts the trust boundary **from the application to the individual action on the individual resource**, and investigation **from after-the-fact to real-time**. The central design move is a **floor/ceiling** split: **static** policies guarantee a **statically verifiable** baseline, on top of which a **dynamic reasoning engine** applies friction — explicitly to avoid a fully dynamic, unverifiable model.

**The architecture**, in four components forming a loop: *autonomous governance* uses AI to build a living **enterprise world model** (Who / What / How), fed by HR and project data warehouses, by analogy with a self-driving car's *world model*; *event intake* ingests server, client, and **agent** signals (prompts, plans, tool invocations); the *reasoning engine*, hierarchical AI, decides fast at access time (ABAC) and slowly in the background (anomalies such as "500% more files than one's peer group"), rendering an *allow / deny / challenge* verdict that itself becomes a reusable attribute; *challenge infrastructure* distinguishes reversible **challenges** (justification, security key, approval, selfie) from durable **containments**, sometimes lifted only after the employee and their manager are interviewed.

**The demonstration** rests on the closing example: the SalesGenie agent queries a strategic document. **BeyondCorp says ALLOW** (valid certificates and identities); **Beyond Zero says CHALLENGE then CONTAIN** (the human who issued the prompt lacks the required work assignment).

**The call to action** covers three standardization efforts — agent introspection, attributable agentic identities, customer-operated decision points within SaaS — with **NIST** having already launched an effort. Conclusion: *"security as an immune system."*

## GrapheDeConnaissance

- Joseph Valente —travaille_chez→ Google (ORGANISATION, 0.97)
- Michal Zalewski —travaille_chez→ Google (ORGANISATION, 0.97)
- Michal Zalewski —dirige→ la stratégie d'Alphabet Security (AFFIRMATION, 0.93)
- Google —publie→ Beyond Zero (CONCEPT, 0.97)
- Beyond Zero —remplace→ BeyondCorp (CONCEPT, 0.93)
- Beyond Zero —est_basé_sur→ BeyondCorp (CONCEPT, 0.95)
- Valente et Zalewski —affirme_que→ le modèle de frontière applicative arrive en fin de vie face aux agents autonomes (AFFIRMATION, 0.95)
- Beyond Zero —affine→ la frontière de confiance, de l'application vers l'action individuelle sur la ressource (AFFIRMATION, 0.95)
- agents IA —mesure→ un accès aux données à 10 fois le rythme des humains (MESURE, 0.8)
- ambient authority —permet→ l'exploitation d'un agent héritant des permissions surprovisionnées de son humain (AFFIRMATION, 0.93)
- politiques statiques —permet→ une base de sécurité vérifiable statiquement (le plancher) sous le raisonnement dynamique (le plafond) (AFFIRMATION, 0.95)
- Valente et Zalewski —s_oppose_à→ un modèle de sécurité entièrement dynamique, difficile à vérifier statiquement (AFFIRMATION, 0.92)
- Beyond Zero —utilise→ enterprise world model (CONCEPT, 0.95)
- enterprise world model —est_basé_sur→ les entrepôts RH et de gestion de projet de l'entreprise (AFFIRMATION, 0.9)
- reasoning engine —permet→ un verdict allow / deny / challenge qui devient lui-même un attribut réutilisable (AFFIRMATION, 0.92)
- alignement intention utilisateur / intention agent —réduit→ les risques d'injection de prompt (AFFIRMATION, 0.9)
- challenges et containments —s_oppose_à→ le blocage binaire « access denied » du modèle hérité (AFFIRMATION, 0.9)
- challenges et containments —s_applique_à→ la révocation durable d'accès, parfois levée après entretien du salarié et de son manager (AFFIRMATION, 0.9)
- préprocessing des attributs —permet→ de tenir le budget de latence à l'accès en front-loadant l'inférence (AFFIRMATION, 0.93)
- Beyond Zero —s_applique_à→ les accès via front-end, API, MCP ou tout autre chemin (AFFIRMATION, 0.9)
- Valente et Zalewski —recommande→ des standards d'identité agentique rendant chaque action attribuable à un agent, un utilisateur contrôlant et une tâche (AFFIRMATION, 0.93)
- Valente et Zalewski —recommande→ faire du point d'évaluation de politique opéré par l'entreprise un first-class citizen de tout produit SaaS (AFFIRMATION, 0.9)
- NIST —publie→ un effort de normalisation sur la sécurité des agents (AFFIRMATION, 0.85)
- Beyond Zero —converge_avec→ la doctrine d'identité agentique de Uber (actor chain, tokens single-hop) (CONCEPT, 0.82)
- Beyond Zero —affirme_que→ la sécurité d'entreprise doit fonctionner comme un système immunitaire s'adaptant au contexte et à l'intention de chaque requête (CITATION, 0.9)
- ACM Queue —publie→ Beyond Zero: Enterprise security for the AI era (DOCUMENT, 0.97)

---
Canonical: https://www.thekb.eu/en/fiches/valente-zalewski-beyond-zero-enterprise-security-ai-era-2026-07-20/
