
Highlights emerging security vulnerabilities related to AI agent adoption that SMBs must prepare for.
Zscaler shares climbed about 4% after the company’s investor day, where leadership reaffirmed both its first-quarter and full-year guidance. The stronger story inside the room came from CEO Jay Chaudhry: businesses are racing to capture AI-driven revenue and efficiency while worrying that the AI agents they deploy create new cybersecurity risks.
Chaudhry expects that tension to drive stronger demand for zero-trust security, the architecture category Zscaler sells, and the market read the message.
AI agents are turning zero-trust security from an enterprise talking point into a mainstream requirement.
What did Zscaler announce at its investor day?
The Bloomberg interview with CEO Jay Chaudhry at the investor day carries the core of it: Zscaler reaffirmed first-quarter and full-year guidance, and shares rose about 4% on the day.
Chaudhry framed the demand side plainly: businesses see AI as a way to boost revenue and efficiency, and they worry that AI agents could create cybersecurity risks.
Zscaler’s own Agentic SecOps launch shows the company building product around exactly that worry, security operations designed for autonomous systems.
The guidance reaffirmation is the footnote; the agent-risk framing is the story.
Do AI agents actually create new security risks?
Per the CEO’s stated view, yes: the same autonomy that makes agents useful makes them dangerous, because an agent acts, connects, and moves data without a human clicking through each step.
The claim is a vendor’s thesis, and the honest read is that it comes from a company that sells zero-trust security. It is also consistent with how the architecture is defined: NIST’s zero-trust standard, SP 800-207, treats every request as untrusted until verified, which applies to software actors the same as people.
No breach statistics or agent incident numbers were cited in the interview, so the risk case rests on the architecture argument, not on published incident data.
The risk claim is directional and vendor-stated, not incident-proven.
How is zero trust different from the old perimeter model?
Legacy security builds a hardened boundary and trusts traffic inside it, which made sense when every worker and every workload sat in one office or one data center.
Zero trust removes the inside: every user, device, and now every agent authenticates and gets only the access it needs, per request, per the NIST definition.
Agents break the perimeter model by design, because they move between systems on their own schedule, holding credentials that were often issued to a human or a service account years ago.
The perimeter assumed human users; agents dissolve that assumption.
What does the zero-trust shift require from a small business?
The practical requirement is an inventory: name every agent, integration, and automation that holds credentials to your systems, because unnamed access cannot be governed.
Zscaler’s AI security documentation describes the pattern vendors are converging on: visibility into AI tool usage, access controls applied per identity, and policies that treat AI actors as first-class users rather than background traffic.
For a small team, the work is not a platform migration, it is a review cycle: quarterly credential audits, least-privilege scopes on every integration, and named owners for each agent.
An agent without a named owner is an access policy nobody wrote.
The front desk tablet at a busy fitness studio holds every member’s card on file, the door code, and the billing portal, and the owner just connected a booking assistant that reads the schedule, cancels no-shows, and emails members on its own. Nobody gave the assistant a user account, because it is software, not staff.
That booking assistant now holds more live access than most employees, and it sits outside every policy the studio wrote for people. The 4% market move prices this pattern at scale: thousands of businesses connecting agents that hold real credentials with no review trail.
Badge it like staff, scope it like a temp, review it quarterly, and the agent risk shrinks to a manageable line item instead of an incident report.
What should you do about AI agent security now?
Stop treating AI agents as passive software and start treating them as privileged users: named, scoped, logged, and reviewed on a schedule.
Run the inventory this week, because the cost is an afternoon and the exposure is unbounded. Restrict each agent to least-privilege access, and cut lateral movement paths so one compromised integration cannot reach your financial systems.
If your security policy still assumes every actor is a person, that document is now out of date, and the gap grows with every agent you connect.
Write the agents into your security policy before an incident writes them in for you.
Zscaler’s investor day is one more entry in the run of AI security signals building since agents went mainstream. You can follow the other AI security signals we have flagged as the policy side catches up with the deployment side.
Source: Bloomberg Tech