Beyond Zero: Google Publishes Successor to BeyondCorp

Google has released a whitepaper for 'Beyond Zero,' a successor to its BeyondCorp security model that shifts from network-perimeter security to continuous, risk-based authorization for every action. The model is designed to handle the complexities of modern enterprise environments involving both human workers and AI agents.
Why it matters
As AI agents become more integrated into enterprise workflows, traditional security models are becoming obsolete, necessitating new frameworks for continuous authorization.
InfoQ Homepage News Beyond Zero: Google Publishes Successor to BeyondCorp
Beyond Zero uses contextual and risk-based, resource-level controls to continuously authorize individual actions by both humans and AI agents. The new model is based on five principles: authorization at the level of individual actions and resources across interfaces and APIs; a combination of static policies and dynamic controls for higher-risk scenarios; automatically enriched context about users, actions, data, and risks; automated investigation triggered by risk signals; and challenges or containment measures that can require additional verification or telemetry from users and AI agents.
Joseph Valente , formerly director of product management at Google, and Michal Zalewski , distinguished security researcher and formerly at Google, write in the paper:
The assumptions underpinning BeyondCorp - that accessors are human, that actions occur at human speed, and that applications are the correct boundary for trust - are no longer sufficient.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in