One of the most surprising turn of events during my 40-year career in information technology was the meteoric rise of “Zero Trust”. I have spent decades building trust—both with customers and within their information landscapes. Yet, the industry bought into a hype cycle that security is highest when trust is completely removed.
The document that birthed this trend was published in 2010 by John Kindervag for Forrester, operating on the premise that the traditional “Trust but Verify” model was fundamentally broken. But by removing the very concept of trust, we accidentally stripped away our ability to govern the next generation of computing: autonomous AI agents.
The Flaw in the Zero Trust Paradigm
In 2011, Kindervag explained that as a network engineer, he didn’t care where data was located and trusted everything without verification. His “new” concept was simply network segmentation—using architecture to isolate data. The reality is that many organizations were already segmenting networks and verifying traffic long before 2011.
In 2019, I presented at a Palo Alto Networks event in Dublin. Representing Okta, I demonstrated how identity can verify users within a Next-Gen Firewall. Okta’s core value was that you could trust the service and the cryptographic tokens it issued, provided you verified them using exchanged metadata.
At the same event, Kindervag had a presentaion about Zero Trust. At the gathering concluding the event, I asked him how a firewall operates without trust, Kindervag described it as “reliance” rather than trust. This suggested to me that “Zero Trust” had become an ideological concept divorced from human-relatable trust.
Google’s “Beyond Corp”, Same Purpose but a Relatable Name
One of the most known projects implementing some of the ideas in the report was Google’s BeyondCorp, which I believe was initiated in 2014. Maybe Google would say that this was initiated without reading the report, but the principles listed in this image are very similar, without mentioning “zero trust”. BeyondCorp also signals the purpose of the project in a way that also reflect the idea of “extended enterprise” or “modernize IT”. Google made it clear that the title of the project was a trade mark, and have since then introduced services and products under that trade mark. Three simple principles makes it simple and secure, without removing trust.

Lessons from the Evolution of Trust Models
Digital trust historically split into two paths in the mid-1990s:
- Public Key Infrastructure (PKI): Corporate-driven and hierarchical, facing scaling issues, and raising questions on who to trust and why.
- Web of Trust (WoT): Decentralized peer-verification, exemplified by PGP and modern LinkedIn, fostering responsibility through social connection.
The Crisis of the AI Agent
As noted in a 1994 paper by Stephen Marsh, we need trust models for autonomous systems. Today, AI agents are “breaking free” because we rely on mathematical models that can transport trust but not build it. Current initiatives, like those in the EU, often focus on ZKP (Zero Knowledge Proofs) while ignoring the necessity of responsibility and consequences.
Conclusion: Setting the Path for Human Trust
Since AI agents cannot evaluate trust, and traditional human anchors are weakening, a new framework is necessary. We must develop a decentralized “Human Trust” model that mirrors the peer-to-peer accountability found on platforms like LinkedIn. By using the fundamentals of PKI with trusted certificates to share trust we can get a hybrid model that is cryptographically secured, but relatable to humans. This approach emphasizes accountability over, or in conjunction with, just the mathematical verification of trust.


Leave a Reply