AI shortens the time to exploit and introduces powerful machine identities. Xage limits what each identity can discover, reach, and do at the asset level.

 

Artificial intelligence is changing both sides of cybersecurity. Attackers can use AI to accelerate research, scripting, vulnerability exploitation, and social engineering. At the same time, enterprise AI agents are gaining legitimate access to applications, APIs, data, management systems, and operational workflows.

Asset protection must address both risks. The goals are to preempt attacks by cloaking assets from unauthorized discovery and, if a compromise occurs, prevent an attacker from using a compromised person, device, workload, or AI agent as a foothold to reach critical business systems.

What You Will Learn

  • How AI compresses the time between vulnerability discovery and exploitation.
  • Why AI agents must be governed as privileged machine identities.
  • Which controls reduce asset exposure and contain lateral movement across IT and OT.
  • How Xage creates identity-aware, session-scoped access to critical resources.

AI Compresses the Attack Cycle

AI has not replaced familiar attack methods. It makes many of them faster and easier to scale. Google Threat Intelligence has observed threat actors using generative AI primarily for research, troubleshooting, scripting, and content development.

The 2026 Verizon Data Breach Investigations Report found that vulnerability exploitation became the leading breach entry point, accounting for 31 percent of breaches. Verizon also reported that AI can shrink the time required to exploit known vulnerabilities from months to hours. Third-party involvement reached 48 percent of breaches, widening the number of potential paths to high-value systems.

That pace is difficult to match with patching alone. Operational systems, specialized appliances, legacy applications, and safety-critical assets may not accept endpoint agents, support modern authentication, or tolerate frequent downtime. Organizations therefore need controls that remain effective when prevention or patching falls behind.

Recent incidents show that AI agents can also act beyond their assigned tasks. These cases began during cybersecurity evaluations but resulted in unauthorized access to real third-party systems including:

OpenAI and Hugging Face. OpenAI’s incident report describes how models operating with reduced safeguards bypassed isolation controls and compromised Hugging Face systems in July 2026. An internal research model drove the main intrusion; GPT-5.6 Sol agents also participated. The agents chained vulnerabilities and obtained credentials, illustrating how an evaluation task can escalate into a real intrusion.

Anthropic. The Wall Street Journal reported that Claude models reached the internet and breached three organizations during testing. Anthropic confirmed that the evaluations lacked its standard deployment safeguards. A September follow-up identified a fourth incident, underscoring the difficulty of detecting the full scope of unauthorized agent activity.

Google Gemini. The Wall Street Journal reported that Gemini accessed the internet and hacked three companies during a May cybersecurity evaluation run by Irregular. Google confirmed the incident but disputed characterizing it as model misalignment. The case reinforces the need to enforce boundaries around which external systems an agent can reach.

These were evaluation incidents, not evidence that ordinary chatbot sessions routinely launch attacks. Their relevance to asset protection is concrete: controls must limit what an agent can discover, reach, and do, even when its behavior departs from the intended task.

AI Agents Become Privileged Identities

AI agents can query databases, invoke Model Context Protocol tools, call APIs, change applications, provision infrastructure, and trigger business or operational processes. An agent connected to valuable tools and data functions as a privileged machine identity.

Shared credentials, long-lived API keys, and broad permissions make that identity dangerous. NIST recommends treating agents as distinct entities with their own identifiers, credentials, and entitlements instead of allowing them to impersonate users or inherit unrestricted access. It also warns that agents can act at a speed and scale far beyond human users.

OWASP identifies Identity and Privilege Abuse as a major agentic application risk. Prompt injection or tool misuse becomes much more consequential when an agent has standing access to sensitive data, administrative functions, or operational systems.

Assets Need More Than Boundary Security

Firewalls, network zones, VPNs, and detection technologies remain important. They do not always determine whether a particular identity should perform a specific action on a specific asset at that moment. Broad trust inside an approved zone can still connect malware or a manipulated agent to a high-consequence resource.

The problem is especially visible in OT. Dragos reports that only 30 percent of OT networks have sufficient visibility, 56 percent cannot see below the IT and OT boundary, and 88 percent struggle with detection and response. When defenders cannot observe every step, reducing reachability and containing lateral movement become essential.

What Effective Asset Protection Requires

  • Make the final controller, workload, application, service, API, or data resource the policy target.
  • Treat people, devices, services, workloads, applications, and AI agents as policy subjects.
  • Create the least-privilege path only for the approved task, then remove it at logout, timeout, revocation, or policy change.
  • Enforce policy close to the resource and continue operating at remote, air-gapped, or degraded sites.
  • Connect the initiating identity, target, policy decision, protocol, action, and session in the audit record.

How Xage Protects Assets

Xage  Asset Protection combines the distributed Xage Zero Trust Identity Fabric with Xage Extended Protection, or XEP. The Fabric provides identity, credentials, policy, authorization, brokering, and audit evidence. XEP enforces those decisions close to individual devices, applications, workloads, controllers, groups, and switches.

The protection model works as a four-step sequence: remove unnecessary visibility, broker the approved interaction, verify every action, and contain anything that becomes compromised. Together, these controls narrow broad network access into a specific, temporary identity-to-asset exchange.

STEP XAGE CONTROL SECURITY EFFECT
1 Hide assets Removes unauthorized discovery and standing visibility.
2 Brokered  access Creates one controlled path to one approved resource.
3 Verify every interaction Applies identity and least privilege to humans, machines, and AI agents.
4 Contain lateral movement Limits east-west reach and reduces the blast radius of compromise.
Diagram

Figure 1. Xage controls interrupt initial access, lateral movement, credential theft, data exfiltration, and malware propagation. Source: Xage Critical Asset Protection white paper, Figure 4.

Step 1: Hide Assets from Unauthorized Identities

The Xage Fabric overlays existing networks from cloud to edge and governs paths, sessions, and credentials using identity, policy, and context. Before authorization, users, devices, workloads, services, and AI agents see no protected resources. After authorization, they see only the specific assets required for the approved task. This reduces the reconnaissance and scanning opportunities attackers depend on to map an environment.

In OT, an engineering laptop can reach an approved HMI without enumerating or connecting directly to every controller behind it. In IT or AI environments, a workload or agent can reach an approved API, MCP tool, or data service without standing reachability to adjacent systems.

Diagram

Figure 2. Identity follows the authorized interaction while downstream assets remain hidden and unreachable unless policy explicitly permits access. Source: Xage Critical Asset Protection white paper, Figure 5.

Step 2: Enforce Secure Brokered Access

For every request, Xage evaluates the identity, target, protocol, endpoint context, policy, and time. The requester never receives direct network access to the protected asset. The Fabric proxies the interaction, creates protocol breaks and inspection points, and can securely traverse multiple hops while maintaining one governed session.

Credentials can be injected just in time so neither a person nor an AI agent sees or stores the downstream secret. XEP then programs only the network flow required to reach the authorized asset. At logout, timeout, revocation, or policy change, Xage removes the session, the temporary path, and any associated privilege. The result is access to one approved target without opening broad network reach or forcing a disruptive redesign.

Diagram

Figure 3. AI agents can interact only with authorized MCP tools, APIs, data sources, and assets, with policy enforced down to the individual tool or action. Source: Xage Critical Asset Protection white paper, Figure 6.

Step 3: Authenticate and Authorize Every Interaction

Human access can use enterprise identity providers, phishing-resistant multifactor authentication, roles, approvals, and time limits. Xage separately verifies the target and authenticates to the downstream resource using a brokered or just-in-time credential. This separates the initiating identity from reusable asset credentials and removes standing privilege from the interaction.

AI agents and other machine identities are governed in the same model. Each agent presents an approved identity, such as an OAuth token or API key, and receives least-privilege authorization for specific tools, APIs, data, and resources. If an agent is compromised, manipulated, or out of policy, Xage can deny the action, revoke the path, isolate the identity, and preserve an action-level audit record. Multiple identity providers and local services also support authentication and authorization at disconnected or degraded sites.

Diagram

Figure 4. Xage independently authenticates human users, AI agents, and machine identities before enforcing policy-based access to approved downstream resources. Source: Xage Critical Asset Protection white paper, Figure 7.

Step 4: Contain Compromise and Lateral Movement

XEP applies identity-based microsegmentation within and between zones, allowing only explicit asset-to-asset communications. It can enforce unidirectional or bidirectional paths, add optional encrypted tunnels, and monitor activity continuously. A compromise that begins on one laptop, service, workload, or AI agent therefore does not automatically become a route to neighboring systems.

Xage V2P Studio can observe assets and traffic flows, help teams translate those flows into policy, and support a staged move from monitoring to enforcement. Local enforcement and distributed policy services continue protecting sites when WAN or cloud connectivity is degraded. By reducing reachable assets and east-west movement, organizations lower blast radius without changing every protected endpoint.

Diagram

Figure 5. XEP creates policy-controlled conduits between zones while enforcing granular authorization between individual assets within each zone. Source: Xage Critical Asset Protection white paper, Figure 8.

What This Looks Like Across the Enterprise

  • OT: An engineer reaches one approved HMI while controllers and other assets remain hidden and inaccessible.
  • Data center: An administrator receives time-limited access to one management system without standing reachability across neighboring infrastructure.
  • AI: An agent calls one approved API or MCP tool without inheriting a user’s full credentials or access to adjacent data sources.
  • Legacy and remote sites: Agentless enforcement and local policy operation protect systems that cannot be frequently patched or continuously connected to the cloud.

Key Takeaways

  • AI increases attack speed while adding AI agents as powerful non-human identities.
  • Patching and perimeter controls cannot remove every path to legacy, high-availability, and mission-critical systems.
  • Effective protection reduces asset visibility, scopes access to one approved interaction, and removes reachability when the task ends.
  • Identity-aware, asset-level enforcement limits what a compromised identity or agent can reach next.
  • Xage applies one policy and enforcement model across IT, OT, data centers, edge, legacy systems, and AI infrastructure.

Start With One High Consequence Interaction

Choose one interaction where compromise could create material safety, operational, financial, or data risk. Identify the initiating identity, final resource, required protocol, approved duration, and evidence needed for audit. Then test authorization, revocation, latency, logging, and enforcement during connectivity loss.

To learn how Xage can protect a high-consequence interaction in your environment, read the new Asset Protection white paper.