🤖 AI Summary
This study addresses the security, reliability, and compliance challenges associated with AI agent decision-making in zero trust architectures (ZTAs) by proposing an autonomous zero trust execution framework based on a multi-agent collaborative pipeline. This approach pioneers the integration of retrieval-augmented generation (RAG) into the agent reasoning process, combining dynamic policy inference with context-aware routing to realize NIST-compliant ZTA control loops and continuous verification mechanisms. Experimental evaluations demonstrate that the proposed system achieves 95.0% accuracy, 93.9% precision, and 96.3% recall in test environments, effectively validating both the feasibility and superiority of the framework.
📝 Abstract
Agentic AI is emerging as a promising paradigm for automating complex cybersecurity decisions, yet its use in enforcing zero trust introduces significant challenges in safety, reliability, and policy compliance. This paper presents Agentic AI based zero trust architecture (Agentic-ZTA) that operationalizes the NIST SP 800-207 ZTA architecture control loop through coordinated multi- agent decision pipeline. In the proposed framework, policy knowledge is embedded into a retrieval-augmented generation pipeline and retrieved at inference time as top-k relevant policies. Access requests are intercepted by the Policy Enforcement Point (PEP), enriched with contextual metadata. The request context is routed to a policy engine agent which invokes domain-specialized core agents first followed by supporting agents, if further evaluation needed. AI agents reason over access context, policy constraints and determine trust. The retrieved policies are embedded into agent prompt during inference time and agentic trust scores are aggregated and evaluated by a trust-algorithm, producing the final access decision for enforcement under continuous verification. We implement Agentic-ZTA in a testbed and evaluate it on representative access-control use cases scenarios. Our Agentic-ZTA framework achieves 95.0% accuracy, 93.9% precision, and 96.3% recall, and demonstrate the feasibility of enforcing zero trust using AI agents.