Apply Zero Trust to AI, not only to people
Verify explicitly, least privilege and assume breach are the same three principles, but they mean something different once a model sits in the chain. Verifying now also covers an agent acting on someone's behalf. Least privilege covers the tools it may call. And assuming breach means this: assume that at some point a model receives an instruction that did not come from you. Anyone applying these three to the human and not to the system has kept the model outside their security model.

