Google introduces Beyond Zero for AI enterprise security
Security
Going Beyond Zero: A New Paradigm For Enterprise Security
Jul 27, 2026
x.com
Copy link
Heather Adkins
VP, Security Engineering
Archana Ramamoorthy
Senior Director, Cybersecurity and Data Protection
Share
x.com
Copy link
At Google, we’ve spent decades trying to push the limits of what is possible in security. In 2014, we released the BeyondCorp whitepaper, describing the beginnings of what became a near decade-long push to establish zero trust as the desired model for securing enterprise networks. We’re pleased to reflect on the success of our internal adoption of BeyondCorp and see the benefits that it has brought to our users in keeping them safer. It has also enabled our company as a whole to transition to a more secure way of working without compromising our own agility and ability to innovate. Likewise, it has been wonderful to see the success of other enterprises and the security industry more broadly in adopting zero trust as the standard for what good enterprise security looks like. Security is ultimately a collaborative endeavor, and when good ideas and design patterns are shared with the broader industry we only stand to gain from the many learnings that come back to us.<br>The enterprise landscape is now entering a new era shaped by artificial intelligence, where AI is changing the assumptions around how enterprise security works. AI agents are being deployed globally to increase operational velocity and boost productivity. However, this increased capability also presents new potential risks, as attackers can leverage similar speed to compromise privileged credentials and execute attacks. This creates the need for a new security paradigm that is capable of defending against these new threats.<br>Introducing Beyond Zero<br>Beyond Zero is a new security paradigm designed to address these AI-era challenges with a contextual, risk-based, resource-level authorization model to run at machine-speed, securing both humans and agents without overburdening the user experience. This extends the concepts from zero trust into the authorization layer, ensuring that every single action taken inside an enterprise is authorized.
The Beyond Zero model is built on five core principles:<br>Resource and Action-based security : Authorization decisions are evaluated at the level of individual actions on specific resources, rather than granting broad access to an entire application or tool. This applies uniformly across all access methods, including front-end interfaces, APIs, and the Model Context Protocol (MCP).<br>Blended static and dynamic security: Granular static policies are paired with dynamic controls that apply heightened security measures during high-risk or complex scenarios. This approach introduces dynamic protections without moving to a fully dynamic model, which can be difficult to verify statically.<br>Automatically enriched context: The decision systems can draw on context about the user action, what the user should be working on, what data the user action is trying to interact with, what the user action is attempting to do with the data, and what potential risk mitigations are available. These facts are always available to the decision making infrastructure.<br>Automated in-depth investigation: Risk signals can autonomously trigger security investigations, which can immediately deploy user challenges or containment measures across the access stream.<br>Challenges and containments: Security policies can directly trigger verification challenges or containment protocols, requiring users or agents to provide additional risk telemetry on demand.<br>Early internal prototypes and deployments of Beyond Zero are showing improved access abuse detection, intellectual property protection, as well as allowing us to run our business at pace while abiding by the many regulatory and other specialized control offerings needed by our customers. We will continue to share additional technical details and deployment strategies as our work progresses.<br>Sharing Beyond Zero with the Industry<br>Google is introducing Beyond Zero to the broader security community through a series of technical publications. The first paper, Beyond Zero: Enterprise Security for the AI Era, has been published in ACM Queue. This initial paper outlines the foundational vision for Beyond Zero and details the architecture developed within Alphabet.<br>Subsequent papers will be released over time to share ongoing implementation data and operational insights, following a publication model similar to the original BeyondCorp series.<br>While industry-wide adoption of continuous authorization is in its early stages, peer organizations and industry bodies are beginning to develop comparable frameworks that are described in Beyond Zero. Google remains committed to collaborating with industry partners to refine these techniques and advance collective enterprise...