The security industry has been adapting to AI faster than any previous technology shift, and Zscaler has been at the forefront of that effort. But the nature of the challenge keeps evolving. Attackers are deploying AI to reason over complex environments and find paths that traditional tooling doesn’t see. Meeting that requires more than faster detection or broader coverage. It requires security that can reason the same way: understanding how an enterprise can be compromised, not just flagging that something looks wrong.That’s why our partnership with OpenAI matters. Through OpenAI’s Daybreak Defense Network, Zscaler built two new capabilities using OpenAI GPT cyber models, and today, I’m excited to showcase what enterprise security can do and what it should look like in an AI-first world.We presented both of these at OpenAI Intelligence at Work: Cyber on September 3, and you can learn more about them below. Innovation Showcase 1: Endpoint AI Security — Attack Chain AnalysisAI agents, assistants, and AI coding IDEs are now part of the standard developer workflow. They’re powerful. They’re also a new and largely unmapped attack surface, one that now extends to local and web MCP servers, locally-run models, and AI running directly inside the browser. Our new Endpoint AI Security Attack Chain Analysis capability, powered by OpenAI GPT cyber models, changes how organizations understand device risk. Instead of surfacing a flat list of misconfigurations and CVEs, it reads the full state of an endpoint — AI agents, coding assistants, IDE and browser extensions, installed software, packages, and system configuration — and reasons over all of it to construct a realistic attack chain.What does that mean in practice? It means the output isn’t, “you have a vulnerable extension.” It’s: here is the path from an initial lure, to code execution under this user’s account, to credential and source code theft, to persistence, to re-entry, and here is what you need to close first.Findings are backed by evidence, and all steps are labelled, confirmed on the host, inferred from state, or flagged for verification. The result is a prioritized remediation roadmap that gives security teams something unique: a defender’s view of their own devices that resembles potential paths of an attacker.This capability runs as an endpoint agent, either independently or as a module within the current Zscaler client running on more than 70M devices, fully controlled and policy-scoped. Zscaler controls the policy-scoped endpoint context submitted for analysis. It simply does something that has historically been very hard to do at scale: performs authorized analysis of potential attack paths so your defenders don’t have to. Innovation Showcase 2: Identity Risk Analysis in the Zscaler AI Access GraphThe other major attack surface that’s grown faster than security teams can manually track is identity, specifically, non-human identities. Service accounts, AI copilots, and agentic workloads now outnumber human users in many enterprise environments. Their permissions sprawl across cloud, SaaS, and on-prem systems in ways that no human team can reason over at speed.Our second integration embeds OpenAI GPT cyber models directly into the AI Access Graph to perform Identity-Permission Risk Analysis at enterprise scale.The AI Access Graph already maps identities across the enterprise (human, service account, and AI agent) to data objects throughout the environment and model endpoints they can reach across Azure, AWS, OCI, and GCP. What OpenAI GPT cyber models add is the reasoning layer: they trace the paths through that graph, identify risky combinations — overprivileged access, toxic permission pairings, excessive inherited scope — and rank them not by a generic severity score but by business impact, blast radius, confidentiality, integrity, and availability of what’s actually reachable.Critically, the graph distinguishes agent and bot behavior from human behavior. That distinction matters for agentic identity governance: you need to know not just what access exists, but who or what is using it, and whether that behavior matches the role and peer baselines you’d expect.Remediation is deliberately decoupled from the model’s reasoning. All remediation actions run through a human-approval workflow. The model surfaces the risk and explains it; humans decide what to do. That’s the right design. What This Means for Our Partnership with OpenAIBoth of these capabilities required a model that could reason about how systems get compromised; not abstractly, but concretely and at the specific context of a customer’s environment. Standard models weren’t up to that task. OpenAI GPT cyber models are purpose-built for this kind of security reasoning, and it’s the foundation that makes both of these innovations possible.Our partnership with OpenAI is about building the AI security infrastructure that enterprises actually need: deep, specific, evidence-grounded, and human-reviewed before anything consequential happens. That’s what we’ve showcased on September 3.The pace of change in this space isn’t slowing down. Neither are we.
[#item_full_content] The security industry has been adapting to AI faster than any previous technology shift, and Zscaler has been at the forefront of that effort. But the nature of the challenge keeps evolving. Attackers are deploying AI to reason over complex environments and find paths that traditional tooling doesn’t see. Meeting that requires more than faster detection or broader coverage. It requires security that can reason the same way: understanding how an enterprise can be compromised, not just flagging that something looks wrong.That’s why our partnership with OpenAI matters. Through OpenAI’s Daybreak Defense Network, Zscaler built two new capabilities using OpenAI GPT cyber models, and today, I’m excited to showcase what enterprise security can do and what it should look like in an AI-first world.We presented both of these at OpenAI Intelligence at Work: Cyber on September 3, and you can learn more about them below. Innovation Showcase 1: Endpoint AI Security — Attack Chain AnalysisAI agents, assistants, and AI coding IDEs are now part of the standard developer workflow. They’re powerful. They’re also a new and largely unmapped attack surface, one that now extends to local and web MCP servers, locally-run models, and AI running directly inside the browser. Our new Endpoint AI Security Attack Chain Analysis capability, powered by OpenAI GPT cyber models, changes how organizations understand device risk. Instead of surfacing a flat list of misconfigurations and CVEs, it reads the full state of an endpoint — AI agents, coding assistants, IDE and browser extensions, installed software, packages, and system configuration — and reasons over all of it to construct a realistic attack chain.What does that mean in practice? It means the output isn’t, “you have a vulnerable extension.” It’s: here is the path from an initial lure, to code execution under this user’s account, to credential and source code theft, to persistence, to re-entry, and here is what you need to close first.Findings are backed by evidence, and all steps are labelled, confirmed on the host, inferred from state, or flagged for verification. The result is a prioritized remediation roadmap that gives security teams something unique: a defender’s view of their own devices that resembles potential paths of an attacker.This capability runs as an endpoint agent, either independently or as a module within the current Zscaler client running on more than 70M devices, fully controlled and policy-scoped. Zscaler controls the policy-scoped endpoint context submitted for analysis. It simply does something that has historically been very hard to do at scale: performs authorized analysis of potential attack paths so your defenders don’t have to. Innovation Showcase 2: Identity Risk Analysis in the Zscaler AI Access GraphThe other major attack surface that’s grown faster than security teams can manually track is identity, specifically, non-human identities. Service accounts, AI copilots, and agentic workloads now outnumber human users in many enterprise environments. Their permissions sprawl across cloud, SaaS, and on-prem systems in ways that no human team can reason over at speed.Our second integration embeds OpenAI GPT cyber models directly into the AI Access Graph to perform Identity-Permission Risk Analysis at enterprise scale.The AI Access Graph already maps identities across the enterprise (human, service account, and AI agent) to data objects throughout the environment and model endpoints they can reach across Azure, AWS, OCI, and GCP. What OpenAI GPT cyber models add is the reasoning layer: they trace the paths through that graph, identify risky combinations — overprivileged access, toxic permission pairings, excessive inherited scope — and rank them not by a generic severity score but by business impact, blast radius, confidentiality, integrity, and availability of what’s actually reachable.Critically, the graph distinguishes agent and bot behavior from human behavior. That distinction matters for agentic identity governance: you need to know not just what access exists, but who or what is using it, and whether that behavior matches the role and peer baselines you’d expect.Remediation is deliberately decoupled from the model’s reasoning. All remediation actions run through a human-approval workflow. The model surfaces the risk and explains it; humans decide what to do. That’s the right design. What This Means for Our Partnership with OpenAIBoth of these capabilities required a model that could reason about how systems get compromised; not abstractly, but concretely and at the specific context of a customer’s environment. Standard models weren’t up to that task. OpenAI GPT cyber models are purpose-built for this kind of security reasoning, and it’s the foundation that makes both of these innovations possible.Our partnership with OpenAI is about building the AI security infrastructure that enterprises actually need: deep, specific, evidence-grounded, and human-reviewed before anything consequential happens. That’s what we’ve showcased on September 3.The pace of change in this space isn’t slowing down. Neither are we.