Attack Surface
The attack surface is the total sum of all potential entry points where an attacker could compromise a system, including network interfaces, APIs, user inputs, and third-party integrations. A larger attack surface increases vulnerability to exploitation.
- Agentic AI expansion: “Agentic AI” (systems that act, not just think) significantly expands the attack surface by enabling agents to interact with APIs, move data, conduct transactions, and create sub-agents agentic-ai.
- Zero Trust implementation: IBM’s Jeff Crume (Distinguished Engineer) advocates for zero-trust principles in AI agent security, requiring strict verification of all agent interactions to mitigate risks from data movement and tool calls zero-trust.
- Zero Trust for AI Agents: Jeff Crume discusses the challenges of securing Agentic AI systems, emphasizing the need for strict verification of all agent interactions, including API calls, tool usage, and data movement IBM Jeff Crume Zero Trust verification.
2026 04 14 Ai zero trust setup IBM channel