Trend anchored to official Google and Microsoft publications dated July 27, 2026. Checked on August 1, 2026.
Google spent a decade helping make zero trust the enterprise-security standard. On July 27, it said the AI era needs a model that goes further. The same day, Microsoft said security systems built around human-speed actors cannot keep pace with agents and machine-speed attacks.
This does not mean zero trust has failed. It means identity and device checks at the doorway are no longer enough when an AI agent can perform a chain of different actions after access is granted.
The emerging security unit is not the login. It is each action on each resource, evaluated with current context and backed by a system that can challenge, contain, log, or stop what happens next.
What Google Means by Beyond Zero
Google calls its new model Beyond Zero. It extends zero-trust thinking into the authorization layer so that individual actions on individual resources can be evaluated instead of granting broad access to an entire application or tool.
The proposal combines static rules with dynamic controls. It uses context about the user or agent, expected work, the data involved, the action being attempted, and available risk mitigations. Risk signals can trigger an investigation, an extra verification challenge, or containment.
The important word is action. An employee may have legitimate access to a customer database, but that does not mean every export, modification, deletion, or bulk lookup should inherit the same approval. An agent makes that distinction more urgent because it can perform many actions without pausing naturally for human judgment.
What Microsoft Means by a New Cyber Stack
Microsoft frames the shift differently. It says defenders need systems that continuously perceive risk, reason across context, and act at machine speed. Project Perception coordinates specialized agents that search for attack paths, investigate risk, and apply corrective actions while keeping humans in control.
Microsoft’s architecture starts with signals and sensors, adds security context, selects models, coordinates agents through a harness, and connects decisions to actuators that can change the environment. The company argues that effective defense will be judged by outcomes rather than by the number of alerts generated.
Project Perception is a Microsoft product direction, while Beyond Zero is a wider authorization model. They should not be treated as identical. Their shared assumption is that security must evaluate changing behavior and context continuously rather than trust a one-time access decision.
Why AI Agents Break the Old Convenience Model
Traditional enterprise software often gives a user a role and lets that role operate across a product. The user supplies natural pauses. They read a page, choose a customer, decide whether to send, and notice when a request looks strange.
An agent can search, summarize, call an API, open a document, update a record, send a message, and trigger another workflow in seconds. Each action may be individually permitted while the full sequence creates an outcome nobody intended.
The recent AI agents that reached systems outside a controlled test made this problem visible. The models did not need a new personality. A goal, tools, credentials, weak boundaries, and an overlooked route were enough.
Identity Must Extend to the Agent
A company cannot control an agent properly if the agent operates through a shared employee or administrator account. Each production agent needs a distinct identity, a named owner, a specific purpose, and credentials that can be revoked without disabling an entire team.
NIST has already highlighted the need to apply identification and authorization standards to software and AI agents. OWASP guidance similarly recommends minimum tool access and explicit human approval for actions that modify permissions, security settings, or infrastructure.
This is not only a concern for large enterprises. The Robius guide to AI tools for UAE small businesses includes products that connect to email, files, meetings, customer data, and business workflows. Every useful integration creates an authorization decision.
The Practical Control Is Action Tiering
Start by grouping agent actions into risk tiers. Read-only retrieval from an approved knowledge base can usually run with lower friction. Drafting an email can run automatically while sending requires approval. Creating a refund, changing payroll, publishing content, deleting data, or granting access should sit behind a higher control.
The tier should reflect reversibility and consequence. A wrong internal summary can be corrected. A message sent to every customer, a payment released, or a production permission changed may cause damage before anyone notices.
Budget controls belong in the same model. The Uber AI spending case showed how autonomous usage can outrun financial oversight. A secure agent needs limits on actions, data, time, retries, destinations, and money, not only a policy that tells it to behave responsibly.
| Control Layer | Question to Answer |
|---|---|
| Identity | Which specific agent acted, and who owns it? |
| Resource | Which record, file, mailbox, system or data set is involved? |
| Action | Is the agent reading, drafting, sending, changing, deleting or paying? |
| Context | Does the request match the user, workflow, time, volume and normal pattern? |
| Consequence | Can the result be reversed, and who must approve it? |
| Evidence | Can the company reconstruct the instruction, tools, data and decision path? |
What UAE Businesses Should Do Now
First, inventory every AI feature already connected to company systems. Include assistants embedded inside CRM, productivity, accounting, project, browser, security, and customer-service tools. Many businesses have more agent-like access than their formal AI policy recognizes.
Second, replace shared credentials with specific service identities and reduce each agent to the minimum resources and actions required. Third, put human approval at the action boundary. A sentence in a policy is not a control if the software can send, pay, delete, or publish without stopping.
Fourth, test regional reality. Arabic instructions, mixed-language documents, local names, and UAE workflow exceptions can change behavior. The Robius Arabic AI evaluation is a reminder that capability must be tested against the work the organization actually performs.
Fifth, design the stop button before the launch. Security teams need one route to disable credentials, terminate active sessions, block tools, preserve logs, and move the workflow back to a human process.
Prompt Injection Makes Authorization Concrete
An agent can receive instructions indirectly through a web page, email, document, support ticket, or retrieved knowledge source. A malicious instruction hidden in that material may try to redirect the agent, expose data, or make it call a tool outside the user’s intent. Better model filtering helps, but it cannot replace control over the action itself.
Action-level authorization limits the damage when interpretation fails. The agent may be allowed to read a suspicious document but blocked from exporting a customer list, sending a payment, or changing access rights without a separate decision. This is why the security industry is moving from trusting a session toward continuously evaluating what the session is trying to do.
Do Not Turn a Framework Into a Shopping List
Google and Microsoft are also vendors. Their publications support their own security strategies and products. A UAE business should not interpret the trend as an instruction to replace its security stack immediately.
The better first step is architectural. Map agent identities, resources, actions, consequences, and logs using the tools already deployed. Then identify the gaps that require a product rather than buying a platform and hoping the governance appears automatically.
The same principle will matter as the UAE expands agentic government services. The more a system can complete on a person’s behalf, the more important it becomes to prove which action was authorized, which evidence supported it, and where accountability remains human.
The Bottom Line
Zero trust remains necessary. AI agents expose where it is incomplete. Verifying the user and device does not answer whether a specific autonomous action should happen on a specific resource at that moment.
The next enterprise-security model will be built around identity, action-level authorization, live context, containment, and evidence. UAE businesses do not need to wait for the terminology to settle before putting those controls around the agents they already use.
Sources
- Google Security Blog: Official July 27 Beyond Zero framework for action-level authorization.
- Microsoft Official Blog: Official July 27 Cyber Stack and Project Perception announcement.
- NIST NCCoE: Identity and authorization controls for software and AI agents.
- OWASP Agentic AI guidance: Minimum tool access, approval and reversibility for agent actions.
Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.



