CSAIChaptersEventsBlog
Join this August 11 webinar to explore practical strategies for managing cloud complexity and AI-driven workloads →

A Zero Trust Approach to AI Asset Inventory

Published 07/31/2026

A Zero Trust Approach to AI Asset Inventory
Written by Jayesh Dalmet, Network Security Engineer L4 ( Sr. Security Engineer), NetApp.

In a Zero Trust architecture, the foundational rule is simple: "You cannot protect what you cannot see."

Organizations are rapidly adopting Artificial Intelligence, leading to a sprawling ecosystem of Large Language Models (LLMs), internal machine learning models, third-party APIs, training datasets, and vector databases. This rapid expansion creates two major security blind spots:

  1. Lack of Visibility: IT and Security teams often do not know what AI assets exist, where they are hosted, or what data they process.
  2. Implicit Trust: Applications and users are frequently given broad access to AI models and datasets once inside the network, violating modern security principles and risking massive data exfiltration or prompt injection attacks.

To secure this new frontier, having an accurate AI Asset Inventory has become an absolute necessity.

 

Why AI Asset Inventory is Crucial for Zero Trust

1. Enabling Granular Policies (The End of "Broad Access"): Zero Trust moves away from network-wide perimeters (e.g., "If you are on the VPN, you are trusted") to micro-perimeters. To write these granular, least-privileged policies, security teams must know exactly what assets exist. If an internal LLM or a vector database isn't in the inventory, you cannot build a Zero Trust to protect it.

2. Combating "Shadow AI": Developers and business units are spinning up AI tools at lightning speed—connecting to external APIs, downloading open-source models, or deploying local instances. This "Shadow AI" bypasses traditional security checks. An automated AI inventory discovers these hidden assets so they can be brought under the Zero Trust umbrella before they leak sensitive corporate data.

3. Context-Aware Access Based on Risk: In Zero Trust, access decisions are based on context. To grant access, the system needs to know the risk level of the asset being requested. Is it a model trained on public marketing data (lower risk), or an LLM fine-tuned on highly confidential HR records (high risk)? An AI asset inventory catalogs the model's data lineage and sensitivity, allowing the Zero Trust engine to demand stricter verification—like MFA or device compliance—for high-risk assets.

4. Vulnerability and Lifecycle Management: Zero Trust requires continuous verification of an asset's security posture. AI assets are complex software pipelines comprising models, weights, training data, and dependencies. If a new vulnerability is discovered in a specific AI library, an accurate inventory allows security teams to instantly locate the affected models and temporarily revoke access until they are patched.

5. Managing Machine-to-Machine (M2M) Trust: In modern applications, humans aren't the only ones querying AI; other microservices and autonomous AI agents are doing it too. Zero Trust demands that these machine identities be verified. An AI inventory maps out the complex web of which applications are authorized to communicate with specific AI models, enabling strict M2M identity verification.

 

 

How to Discover AI Assets in a Zero Trust Environment

When an organization has already implemented a Zero Trust (ZT) architecture, discovering AI assets requires a modern approach. In a traditional network, you might use IP scanners or packet sniffers. In a Zero Trust world, lateral movement is blocked, and traffic is heavily encrypted.

Therefore, you cannot rely on traditional network scanning. Instead, you must query the Zero Trust control plane and trust brokers. Here is how to build your AI inventory by leveraging existing ZT infrastructure:

  • Tap into the Service Mesh (Internal M2M AI): In a mature ZT environment, microservices communicate through a Service Mesh using sidecar proxies. Because every single API call between services is authenticated and logged by the mesh, you can easily identify internal traffic routing to newly spun-up AI endpoints or vector databases.
  • Query Identity and Access Management (IAM): Zero Trust is identity centric. Look at your machine identity providers to search for workloads requesting secrets, API keys, or OAuth tokens related to AI services. Similarly, check your Identity Provider (like Okta or Microsoft Entra ID) for human SSO integrations with AI SaaS platforms.
  • Analyze Zero Trust Network Access (ZTNA) / Secure Service Edge (SSE): Your ZTNA and SSE platforms act as the gateway for all user traffic, replacing traditional VPNs. Because these platforms inspect traffic, they can report exactly who is accessing external AI APIs and from what compliant device.
  • Leverage Cloud Workload Protection & Device Posture Checks: Zero Trust requires verifying the security posture of an endpoint before granting access. Use your Cloud Workload Protection Platforms (CWPP) or Endpoint Detection and Response (EDR) agents to query the software inventory of your servers and employee laptops. Look for running processes associated with local AI development

 

The "Zero Trust Advantage"

The beauty of discovering AI assets within a Zero Trust environment is the depth of the data. When you query these ZT systems, you don't just get a static list of IP addresses. You get a highly contextualized inventory: you know the asset, the exact identity of who or what is using it, the policy governing it, and the security posture of the device accessing it.

By merging AI asset inventory with Zero Trust principles, organizations can safely accelerate their AI adoption without compromising their security posture.


About the Author

Jayesh Dalmet is a CISSP-certified cybersecurity and IT infrastructure leader with 20+ years of experience driving enterprise security strategy, global cyber posture, digital transformation, and high-performing engineering teams.

Share this content on your favorite social network today!

Unlock Cloud Security Insights

Unlock Cloud Security Insights

Choose the CSA newsletters that match your interests:

Subscribe to our newsletter for the latest expert trends and updates