Enterprises are rapidly adopting agentic AI to improve efficiency and automate increasingly complex tasks. But many of these AI agents are operating across network environments that were not designed for autonomous systems moving dynamically between applications and infrastructure.
In this Fed Gov Today Cyber Insights interview, Lou Eichenbaum, Federal CTO at ColorTokens, explains why over-permissioned AI agents can create new cybersecurity and operational risks. An AI agent performing a specific task should not automatically be able to discover or access unrelated systems simply because the network permits it.
Lou discusses why enterprises should apply foundational Zero Trust principles, including strong identity, asset discovery, least privilege, and microsegmentation, to AI environments. Instead of relying solely on models to behave as intended, organizations need technical guardrails that define what AI agents can reach and help keep them within their authorized environments.
He also examines the limitations of static, hardware-based segmentation for agentic AI and why more granular, software-based controls can help organizations restrict unnecessary access at the individual asset level.
Watch the interview to hear Lou’s perspective on building an infrastructure foundation that enables AI adoption while maintaining stronger control over how AI agents interact with enterprise systems.
Recorded at the Billington Cybersecurity Summit 2026.
Francis Rose: Lou Eichenbaum is the Federal CTO at ColorTokens. Great to see you again. Thanks for joining me. A lot of agencies are trying to use frontier AI models on top of legacy infrastructure. What are the cyber challenges for doing something like that, Lou?
Lou E.: Yeah, there’s a lot of pressure in federal government, for federal agencies to adopt these models, to increase efficiencies, reduce costs as quickly as they can.
Lou E.: The problem is these traditional network architectures, they weren’t built for agentic AI. Traditional hardware-based segmentation, for example, routers, switches, they weren’t built for AI agents that have to move dynamically through multiple systems to do their jobs. So what is happening is, we are creating great risk within these environments because we are over-permissioning our AI agents.
Lou E.: We’re giving them too many permissions at the identity level. Too many permissions at the asset level, where an AI agent, maybe their job is just to perform a function on an HR server, but for some reason, they can still see, they still have access to the finance server. In AI, we’ve seen it happen. I mean, AI, it learns new behaviors, and it just, it may decide one day, “You know what?
Lou E.: I think I wanna go pen test the finance server.” We are not putting effective guardrails in place to prevent that, and I think it is because of our traditional network architectures. We need to think differently about these things, focus more at the asset level to ensure these AI agents cannot jump out of the sandbox, can’t jump out.
Lou E.: If they’re doing HR stuff, they can’t jump out of the sandbox and start performing functions on the finance server.
Francis Rose: A lot of organizations are coming to me and talking about their digital modernization, digital transformation, whatever term they wanna use to describe what they’re doing.
Francis Rose: What are the fundamentals that those agencies should think about to make sure when they do make these changes, they’re laying the groundwork correctly?
Lou E.: Yeah, and I’m gonna use a term that’s no longer in favor, but I still believe in it. It’s called Zero Trust.
Lou E.: It’s the principles. I know Zero Trust’s turned into this compliance effort about, “Oh, check the box.”
Lou E.: “Let’s put these…” Go back to the principles of thinking about your underlying architecture inside your environments. How can I ensure that, whether it’s an adversary or an AI rogue agent, it can only access the resources it needs inside its network, as opposed to we’re still focusing on the perimeter and thinking,
Lou E.: “Oh, if we protect the perimeter, we’re okay.” These AI agents, they’re our agents, they’re inside our networks. We need to make sure they perform properly. We’re not gonna be able to train them to do that. I think that’s a fallacy. A lot of people are like, “Well, if I train my AI model, it’ll learn not to do that.”
Lou E.: That’s like teaching a kid, a three-year-old, not to go up the steps, you know? That’s why you put fences. So a lot of people are talking about AI governance and guardrails, but a lot of people aren’t talking about how to do it. And for me, hey, I’m an old-school cybersecurity guy. There’s some underlying sound principles, again, Zero Trust principles, things like strong identity, microsegmentation, discovery, asset discovery, just basic things that we’re not doing that I think could help improve and prevent these AI models from going rogue and doing things we don’t want them to do.
Francis Rose: You put your finger on something that I think is interesting, because I have detected the same thing that you have. That folks are a little more standoffish towards Zero Trust than they have been. But if it comes around full circle, at the very beginning of that conversation, the Pentagon especially, when they rolled out their Zero Trust, I mean, that’s been five years or so now, I think.
Francis Rose: There were five main pillars.
Lou E.: That’s right.
Francis Rose: And pretty much everybody agreed at the time, those five things make a lot of sense for protecting something from a cyber perspective. It’s kind of back to the basics, it sounds like.
Lou E.: That’s all it is. And like I said, Zero Trust is something I did a lot of work on at the Department of the Interior, as you know.
Lou E.: Yes. I believe in it. But it became this big thing to do.
Lou E.: As opposed to, hey, what are the outcomes we want to achieve by implementing Zero Trust principles? It just became this thing where, well, for the identity pillar I need to have multi-factor authentication, right?
Lou E.: Well, why? What are you trying to achieve by implementing that? Understanding what are the outcomes you’re trying to achieve. And we just missed some of the important underlying principles. So instead, like I said, we checked the box. We implemented these technologies, and we said, “Hey, we got Zero Trust.”
Lou E.: And that’s not really what Zero Trust is about.
Francis Rose: If we take that idea of focusing on outcomes and shift it back to where we were at the beginning of this conversation, which is infrastructure that’s required for secure AI use and governance, what does that look like in your view, Lou?
Lou E.: Well, again, I think it’s moving away from, for years our network people, we love our routers, we love our switches, we love our firewalls, these hardware-based technologies. Traditionally, they have challenges.
Lou E.: Number one, their static nature is challenging for AI agents. Number two, they’re not granular enough, because they protect a segment, but not necessarily an asset. I think we need to focus more on software-based networking capabilities, and that’s, I don’t know why that hasn’t taken off yet.
Lou E.: We’ve been talking about it for years, but we have to do it. With AI, we just have to do it because these network technologies, they’re just, they’re just not robust enough to really support what we need. And like I said, I fear we’re creating a bit of a ticking time bomb here with these AI agents because we’re, like I said, we’re over-permissioning them inside our network and we expect to train them to do the right thing.
Lou E.: We know they’re gonna do something bad. We know they’re gonna probably learn a bad behavior. They’re gonna think it’s a good behavior, but they’re gonna learn a bad behavior that could impact operations.
Francis Rose: Lou, it’s great to talk to you as always.
Lou E.: Always great talking to you, Frank.