Zero Networks has announced Least Agency Enforcement, a new capability that applies the Open Worldwide Application Security Project’s (OWASP) principle of ‘least agency’ to help organizations safely deploy AI agents.
As organizations grant AI agents the ability to access enterprise systems, invoke privileged tools, and make decisions with minimal human oversight, they must also define and enforce appropriate levels of autonomy. The ‘least agency’ principle in the OWASP Top 10 for Agentic Applications 2026 recommends constraining an agent’s autonomy, tool access, and decision-making authority to reduce the impact of prompt injection, privilege abuse, and compromised AI agents.
Using identity-based micro-segmentation, policy automation, and just-in-time MFA for privileged access, Zero Networks says that Least Agency Enforcement restricts AI agents to communicating only with explicitly authorised systems and accessing only approved resources, while requiring human approval before they perform sensitive administrative actions. The company says that the capability applies least agency controls across cloud, on-premises, Kubernetes, IoT/OT, and hybrid environments.
Zero Networks says that Least Agency Enforcement can:
- Limit AI agents to the systems and services required for their assigned task
- Prevent lateral movement between applications, infrastructure, and administrative systems
- Require just-in-time MFA before AI agents access privileged ports or sensitive infrastructure
- Automatically generate and enforce least-privilege communication policies without manual rule creation
- Contain compromised, manipulated, or over-permissioned AI agents before they can affect critical business systems
Least Agency Enforcement builds upon Zero Networks’ AI Security platform.






