Zero Trust transformed organizational security by challenging the traditional assumption that users, devices, and workloads inside the network are inherently trustworthy. Instead, it introduced a straightforward principle: never trust, reliably verify.
This shift modernized security for cloud adoption, remote work, SaaS expansion, and distributed environments. However, AI introduces new risks that emerge after access is granted, revealing the limitations of Zero Trust.
The following sections will examine the specific challenges presented by AI, the areas where Zero Trust falls short, and how next-generation approaches such as Confidential AI seek to address these evolving security concerns.
What Zero Trust Was Built to Solve (and What It Wasn't)
Zero Trust was designed to answer one critical question: who should be allowed in?
This approach resulted in stronger identity controls, device checks, network segmentation, least-privilege access, and continuous authentication. While these protections are essential, Zero Trust is most effective at the point of entry. Once access is granted, the emphasis shifts to what occurs during execution.
This question is increasingly important in the age of AI. Traditional enterprise applications follow structured, predictable workflows. In contrast, AI workloads continuously process prompts, proprietary data, model weights, embeddings, generated outputs, and dynamic context sourced from multiple systems, often across shared GPUs, hybrid infrastructure, or third-party environments.
Even with strong identity controls and access policies, sensitive assets may be exposed during workload execution. Organizations can implement Zero Trust effectively and still experience major AI security gaps.
The Blind Spot Zero Trust Doesn't Cover
Organizations encrypt data at rest, secure it in transit, and enforce access with Zero Trust policies. While this is essential, it does not protect data and models during active use.
During AI workload execution, sensitive data is processed in memory, model weights are loaded, outputs are generated in real time, and internal context may be exposed.
In conventional environments, these assets can be visible to the host system, privileged users, or compromised infrastructure.
This is when value is created and risk is highest.
If your organization uses AI for customer operations, financial workflows, healthcare, internal copilots, or proprietary decision-making, your most sensitive information may be processed within environments not designed to protect it during execution.
This often results in delayed AI rollouts, blocked deployments in sensitive cases, and model owners withholding advanced models. Frequently, the main barrier to AI adoption is not capability, but trust.
Fortanix Confidential AI Extends Zero Trust Into Runtime
The next phase of enterprise security extends Zero Trust rather than replacing it.
Zero Trust verifies who receives access, while Confidential AI verifies where and how workloads run after access is granted. It applies the same "never assume anything is safe" mindset at the execution layer, requiring each workload to prove it operates in a secure, verified environment before interacting with sensitive data or valuable models.
Fortanix Confidential AI leverages confidential computing, centered on hardware-based trusted execution environments (TEEs). TEEs isolate workloads during execution, protecting data in process and securing model weights during inference. Administrators cannot view active workloads. Encryption keys are released only after attestation confirms the environment fulfill security standards.
The attestation process strengthens the connection to Zero Trust principles by introducing cryptographic verification of environment identity prior to releasing sensitive assets, rather than functioning solely as an additional access control layer.
Fortanix Confidential Computing Manager (CCM) carries out composite attestation over both CPU and GPU environments, and Fortanix Data Security Manager (DSM) ensures key release is contingent on attestation throughout the workload lifecycle.
Nevertheless, several significant limitations must be considered. The reliance on specific hardware technologies, such as trusted execution environments, introduces constraints related to hardware supply chains, platform compatibility, and possible firmware or microarchitecture-level exploits.
Additionally, the security of the overall solution depends on the implementation rigor and correctness of attestation protocols; any flaws or vulnerabilities in these protocols can undermine the trust anchor of Confidential AI.
Furthermore, sophisticated attackers may target side-channel leaks or exploit misconfigurations within TEEs, bypassing runtime protections. Consequently, while Confidential AI marks a substantial advancement in runtime security, organizations should critically assess these limitations and integrate Confidential AI as one layer within a broader, defense-in-depth security strategy.
Verification at Runtime Is the Next Security Standard
Security methods evolve as technology advances. Perimeter security shifted to Zero Trust as work moved beyond the network edge. Now, AI is driving another transition, concentrating value in runtime environments.
Organizations that adapt early can accelerate high-value AI use cases and deploy sensitive data with greater confidence. They can also attract providers of advanced models seeking to protect their IP. Those depending on outdated trust models will see AI progress hindered by ongoing risk concerns.
Zero Trust is one of the most notable security advances of the past decade. However, AI has made execution the new critical security boundary, requiring the same mindset that made Zero Trust effective.
Fortanix Confidential AI enables organizations to make this shift by combining attestation, confidential computing, and policy-driven key management to guard sensitive workloads during execution. The next chapter after Zero Trust is not hypothetical; it is already here.


