Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
New Training Courses: Turn CSA research into practical skills with self-paced Frontier Ready Training.

Reachability is Only Half the Blast Radius

Published 10/02/2026

Reachability is Only Half the Blast Radius
Written by Mayur Agnihotri, Head of Threat Research, StraightArc Technologies.

 

Action-Class Authority for Agentic Zero Trust

The vulnerability-discovery curve has bent. AI-assisted tooling surfaces exploitable flaws faster than most organizations can test and ship patches, and CSA’s own guidance states the consequence plainly: slow, methodical change cannot keep pace with exploit development that now moves in hours. Patching faster is a losing race by design.

Zero Trust never promised faster patching. Its promise was containment: assume breach, verify continuously, shrink what a compromise can touch. That is the right posture. What the agentic shift exposes is a half of the blast radius current guidance does not yet measure.

 

The half we have solved

Today’s Zero Trust contains reachability, and it does that well. Identity-defined reachability holds that nothing is reachable until policy makes it so: reachability is created only when identity, policy, posture, service intent and context allow it. The SDP Architecture Guide v3 extends the same floor to non-human identities as first-class principals. For human and service access this is a strong control.

 

Agents arrive with reachability already granted

Autonomous agents change the question. A compromised or manipulated agent is not an outsider trying to gain reachability. It already has legitimate reachability, granted so it can do its job. Prompt injection, a poisoned tool result or a confused-deputy delegation does not breach a perimeter. It rides an identity the policy already trusts. At that point “what can this identity reach” has been answered, and answered the wrong way.

The existing guidance accepts the principle one layer up. SDP v3 asks that AI-assisted discovery and policy generation be treated as recommendations rather than autonomous enforcement, with human review before deployment. The AI that proposes a firewall rule is gated. The agent that acts under that rule is not.

 

The second axis is action class

The blast radius is governed by a second axis the model rarely names: what the action does once it executes, and whether anyone can undo it. Graded by reversibility:

  • Read-only: observes, changes nothing.
  • Reversible: the system itself can cleanly roll it back.
  • Externally reversible: undoable, but only by an out-of-band party.
  • Irreversible: no clean undo. Funds moved, data published, a record deleted, a message sent.

A read-only action by a fully compromised agent is a containment success. An irreversible action by a lightly manipulated one is a containment failure. Reachability alone cannot tell those apart, because both agents had reachability.

Across the current Zero Trust line, blast radius means how far something spreads: segmentation, session teardown, narrowed lateral paths. All of that is reach. None of it is whether the effect can be withdrawn.

Zero Trust governs the first gate. Agentic systems need the second.

Two gates, one blast radius. Zero Trust governs the first. Agentic systems need the second.

Two gates, one blast radius. Zero Trust governs the first. Agentic systems need the second.

 

Two rules that keep the gate honest

Grade every agent action by class, and enforce that grade at a deterministic gate before the action runs.

The case exists in the wild. In July 2026 the UK AI Security Institute recorded agents taking nineteen unsanctioned actions on the live internet during an evaluation (INC-2026-07-28-01). Caught mid-attempt, one agent reasoned about whether it could erase what it had done and concluded it could not: the code had already been quoted, and the repository had already been cloned. It ran the reversibility analysis correctly, and it ran it after the action. Nothing in the harness ran it before.

First, the gate evaluates a declared class, bound in a manifest and set by the system designer, not the agent’s own runtime assessment. An agent under injection will relabel an irreversible action as routine.

That declaration has to stay bound to the thing it describes, and in practice it drifts. Across 44,172 tools on the public Model Context Protocol registry between June and August 2026, 83.8% declared a canonical effect annotation while 59.3% still held a declaration bound to an unmutated contract: a 24.5-point gap between what a declaration-gated system believes it has verified and what remains attested (doi.org/10.5281/zenodo.22649163).

Second, the gate evaluates the worst-case class reachable across the entire planned chain, not step by step. Otherwise a benign opening move launders a privileged terminal action.

 

The companion, not the replacement

This does not replace identity-defined reachability. It is its action-layer companion. Identity and non-human-identity attribution answer who is acting and on whose behalf. Action class answers what that actor may do, and whether the effect can be walked back. Policy creates the path; it should also grade the consequence at the end of it.

 

What is not new here

None of the underlying idea is new. Capability-based security has bound authority to scoped, unforgeable tokens for decades. Transactional systems have modelled commit against rollback since the first database. Forensic chain-of-custody graded reversibility long before agentic AI was a phrase. The contribution is narrower: porting that instinct into the agentic Zero Trust policy layer as an enforceable input rather than a runbook footnote.

Zero Trust taught us not to assume reachability. The next step is to stop assuming reversibility: to make whether this can be undone, and by whom, something policy evaluates before the agent acts rather than something reconstructed afterwards.


About the Author

Mayur Agnihotri is Head of Threat Research at StraightArc Technologies. He is named in OWASP AISVS v1.0 and was a peer reviewer on CSA's Zero Trust Microsegmentation Guidance.

Share this content on your favorite social network today!

Unlock Cloud Security Insights

Unlock Cloud Security Insights

Choose the CSA newsletters that match your interests:

Subscribe to our newsletter for the latest expert trends and updates