Spokes.wiki Search About
Blog Posting source ↗ source url updated Mon Jul 27 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

Beyond Zero (Google, 2026-07-27)

Google’s security blog, by Heather Adkins (VP, Security Engineering) and Archana Ramamoorthy (Senior Director, Cybersecurity and Data Protection), proposing Beyond Zero: a risk-based authorization model that extends BeyondCorp-style zero trust to enterprises running autonomous AI agents.

The argument

Agents raise the speed at which work happens, and attackers get the same speedup — the post’s stated motivation is adversaries compromising privileged credentials and executing at machine speed. A model that decides whether this device and user may reach this network was built for a world where a human clicked things at human pace. Beyond Zero’s answer is to move the decision point: authorize individual actions on specific resources, across every access path including APIs and the Model Context Protocol, and to make that decision at machine speed too.

Five principles

  1. Resource- and action-based security.
  2. Blended static and dynamic controls.
  3. Automatically enriched contextual data.
  4. Automated security investigations.
  5. Challenges and containment.

Principle 4 is the one this corpus has already met: soc-fast-slow-thinking makes the same argument from a vendor’s side of the SOC, and for the same reason — the volume of decisions passed human capacity. Principle 5’s challenge step is the interesting one, implying graduated response (re-authenticate, constrain, contain) rather than the binary allow/deny that zero trust inherited.

What’s named, and what isn’t

Named: Chrome Enterprise, Workspace with Gemini, Android, and DeepMind research on agent security. Not named: any number. The post reports “improved access abuse detection” and IP protection from internal prototypes, with no metrics, no breach statistics, no customer examples. It closes by inviting industry collaboration and promising technical papers later.

Tier

T1 for what Beyond Zero is — first-party, from the people building it, and Google has standing here (the 2014 BeyondCorp paper is the reference implementation of the idea it’s extending). The evidence is nil, though: a framework announcement with prototype anecdotes. Treat the five principles as a design position, not a validated result, and re-read this page when the promised technical papers land.

The claim underneath it

“Attackers move at machine speed” is the premise, not a finding — the third source in this spoke to assert AI-accelerated attack velocity without measuring it, after Akrites‘s “minutes rather than weeks” and the SOC piece’s alert-volume argument. See synthesis; the pattern is now worth naming.

zero-trust · defensive-security · soc-fast-slow-thinking · akrites-oss-ai-threats · security-operations-center · synthesis