Trending now
Tariffs Labor Costs Platform Consolidation AI Workforce Automation Data Center Load Interest Rates AI Capex IRA Incentives FDA Approval Pathway Autonomous Systems

Hot Topics · Cross-industry

Zero Trust

Zero trust architecture moving from framework to procurement category.

120 mentions 32 companies New this quarter

AI-generated · informational only · not investment advice · verify before relying.

01 · The lede

Intelligence brief

SeventhBiz Intelligence

Refreshed 8h ago

Zero Trust has shifted from a network access control pattern to an identity and runtime enforcement framework for AI agents, with 120 mentions across 32 companies this quarter versus zero in the prior cycle. The threshold move is explicit: ZS extended its Zero Trust Exchange to cover 'users, workloads, branches, and now agents' (vs. the prior framing of users, devices, and applications), PANW positioned Idira as identity-first enforcement ensuring 'every machine action is authorized, scoped, and fully auditable,' and CRWD operationalized this via Signal's 30 million access decisions per customer without naming zero trust explicitly. S, BOX, and OKTA all launched or expanded agent governance layers — runtime behavioral enforcement, agentic content security, and IL5-authorized identity orchestration respectively — positioning zero trust as the control plane for non-human identities. The DoD's 2027 Zero Trust mandate and federal FedRAMP/IL-level authorizations (QLYS, TENB, PLTR) have crystallized zero trust from optional architecture to compliance requirement in government-facing workloads. The investment implication is direct: zero trust enforcement at the identity and runtime layers for AI agents is no longer a differentiator but a table-stake architectural requirement, and vendors that do not articulate agent-centric zero trust enforcement in their platform narrative (regardless of market cap or existing security product strength) face displacement by vendors positioning zero trust as the primary enforcement layer for agentic workloads.

02 · Language arc

Quarter over quarter

How the language around Zero Trust evolved across recent earnings cycles. Threshold marker flags the inflection point.

  1. 2026-02

    “I don't find any Zscaler customer... they all want to replace SD-WAN for cost reasons and for security reasons”

  2. 2026-03

    “We're moving access from static point in time to real time and redefining Zero Trust. Access should be always on, granular and dynamic.”

  3. 2026-08

    “you're going to have even more agents and you've got to have a proper security model for those agents”

    ← threshold

  4. 2026-09

    “By connecting users, workloads, branches, and now agents directly to the applications they need without placing them on the network”

03 · Companies

Companies engaging with this topic

Tracked companies with an on-record signal on Zero Trust this cycle.

ZS ZS Zscaler Last filed: earnings_call · Sep 3, 2026 “Autonomous AI attacks cross from theoretical to documented enterprise threat” PANW PANW Palo Alto Networks Last filed: earnings_call · Sep 1, 2026 “NGS ARR crosses $9B with nearly $1B added in a single quarter” S S SentinelOne Last filed: 10-Q · Aug 28, 2026 “Emerging solutions cross 50% of total ARR — platform mix tipping point” OKTA OKTA Okta Last filed: 10-Q · Aug 27, 2026 “Identity Repositioned as Enterprise Control Plane, Not Access Tool” CRWD CRWD CrowdStrike Last filed: 10-Q · Aug 27, 2026 “CrowdStrike self-declares as 'AI security infrastructure' — category repositioning” BOX BOX Box Last filed: 10-Q · Aug 26, 2026 “Box transitions from AI-augmented platform to agent-native architecture” NET NET Cloudflare Last filed: 8-K · Aug 13, 2026 “Agentic AI-First: 20% Workforce Cut Crosses Qualitative Threshold” FTNT FTNT Fortinet Last filed: 10-Q · Jul 30, 2026 “Product Revenue Reacceleration Signals Hardware Refresh Cycle in Full Swing” TENB TENB Tenable Last filed: 10-Q · Aug 4, 2026 “Anthropic Named as Federal Supply Chain Risk — Direct Tenable Exposure” QLYS QLYS Qualys Last filed: 8-K · Aug 4, 2026 “Revenue Growth Deceleration: 10% Q1 → 8–9% Q2 Guidance” RPD RPD Rapid7 Last filed: 8-K · Aug 31, 2026 “Retired Army Cyber Command general joins board; military cyber doctrine expertise at the table” AKAM AKAM Akamai Technologies Last filed: 10-Q · Aug 7, 2026 “$1.8B frontier AI customer commitment transforms CIS growth visibility” PLTR PLTR Palantir Last filed: 10-Q · Aug 4, 2026 “U.S. Commercial Segment Crosses into Hypergrowth Regime” DDOG DDOG Datadog Last filed: earnings_call · Aug 6, 2026 “AI-native customer cohort scaling rapidly in size and spend” GTLB GTLB GitLab Last filed: 10-Q · Sep 2, 2026 “Flex launch shifts AI usage from feature to billable consumption dimension” GEN GEN Gen Digital Last filed: 10-Q · Aug 7, 2026 “AI adoption crosses from product narrative to Board-approved workforce restructuring” VRNS VRNS Varonis Systems Last filed: 10-Q · Jul 29, 2026 “Agentic AI Governance Crosses from Emerging to Core Product” MDB MDB MongoDB Last filed: earnings_call · Sep 1, 2026 “Frontier Lab inference workloads move from pilot to production on Atlas” CRM CRM Salesforce Last filed: 8-K · Sep 4, 2026 “Agentforce ARR crosses $1.2B — from pipeline narrative to revenue-scale business” AMGN AMGN Amgen Last filed: 10-Q · Aug 5, 2026 “Meritide Phase III fully enrolled across all six global studies”

04 · Risk + structural moves

Structural signal

CyberArk integration into PANW's Idira platform and the OpenID Foundation membership drive by CRWD represent a structural consolidation of identity-layer enforcement as the standard for zero trust. These partnerships reinforce identity-first zero trust as an industry-wide architectural standard rather than a point solution, advantaging vendors with identity governance depth (OKTA, PANW, CRWD, CyberArk) and potentially squeezing pure-play network segmentation vendors (Guardicore, though acquired by Akamai, remains a segmentation-first tool). The FedRAMP/IL-level authorizations clustering (QLYS, TENB, PLTR, OKTA) create a regulatory moat that favors vendors with government compliance infrastructure, disadvantaging smaller or cloud-only security vendors without federal authorization pathways.

Bear case

What invalidates this

The signal could collapse if vendors successfully argue that traditional ML-native sandboxing and model-level safety guardrails supplant zero trust identity and runtime enforcement as the operative control layer for agent containment. Anthropic's May 2026 white paper recommendation of zero trust for AI agents anchors the current posture, but if frontier model providers (OpenAI, Anthropic, xAI) embed sufficient behavioral control within model inference itself, enterprise security teams may deprioritize zero trust infrastructure investment in favor of model-level safety. Additionally, if federal zero trust mandates are delayed or softened by policy reversal (the Trump administration's EO 14306 already introduced 'decentralized flexibility' per MDB's disclosure), the regulatory forcing function dissolves and vendor urgency around zero trust feature completeness drops sharply.

05 · Synthesis

Analyst note

SeventhBiz Intelligence

MSFT's absence from this cycle's zero trust discourse is striking. The company promoted zero trust as a 'strategic initiative for government and regulated customers' in Q2 2026, yet does not appear in Q3 filings or earnings calls with explicit agent-centric zero trust product launches or enforcement framework updates comparable to PANW, OKTA, S, or BOX. Given MSFT's scale in identity (Entra ID, Purview) and its AI agent ambitions (Copilot agents across M365), the silence suggests either a deliberate down-weighting of zero trust branding in favor of Copilot-first messaging, or a lag in translating identity governance into runtime enforcement for agentic workloads — a material competitive gap vs. vendors positioning zero trust as the primary agentic security narrative.

06 · Evidence

Recent mentions

Preview
ZS·CybersecuritySep 3, 2026

“Anthropic published a white paper in late May, encouraging adoption of a Zero Trust architecture for AI agents, emphasizing the importance of treating every agent like an untrusted entity.”

CEO prepared remarks — Zero Trust and AI section

ZS·CybersecuritySep 3, 2026

“By connecting users, workloads, branches, and now agents directly to the applications they need without placing them on the network”

CEO Quote, Press Release

GTLB·Enterprise SaaS & CloudSep 2, 2026

“we, in alignment with our industry, are reinforcing our defensive capabilities in areas such as, but not limited to, behavioral analysis, automated detection response, and zero-trust”

Part II Item 1A — Risk Factors, Security

Unlock Zero Trust

Every company mention and the full by-industry breakdown for this topic, verbatim and source-cited.

27 company mentions 10 industries