Trust in the Age of AI: Why Zero Trust Must Apply to Information
Here’s an uncomfortable truth: for many organizations, the deception is already live. Employees are being fooled every day. So are customers, investors, and board members. We’re not talking about the distant threat of deepfakes in some future dominated by science fiction. We’re talking about right now. A fake chief executive appears on a video call, a cloned voice calmly authorizes a money transfer, a perfectly worded fraudulent email slips past the usual checks and convinces someone to act. These tactics aren’t entirely new—con artists have always impersonated authority. But artificial intelligence has changed the game. It has made these attacks cheaper to produce, harder to detect, and far more convincing inside the everyday flow of business. A deepfake that once required Hollywood-level resources can now be generated in minutes. A phishing email that used to be riddled with typos now reads like it was written by the CEO’s own assistant. And because these weapons are so effective, they aren’t being used sparingly. They’re being woven into the ordinary routines of work, waiting for the moment when someone clicks, replies, or transfers money. This is why the principle of Zero Trust—long a cornerstone of cybersecurity—must now be applied to information itself. In cybersecurity, Zero Trust begins with a simple assumption: no user, device, application, or request should be trusted by default. Every action must be verified. In an age of AI-generated misinformation, that same mindset must apply to the content moving through our organizations. We can no longer assume that a video is real because we can see it, or that a message is genuine because it landed in our inbox. The very concept of trust has been destabilized, and the default setting of belief has become a vulnerability.
The consequences of this shift go far beyond an occasional embarrassing tweet or a confused employee. There is a new trust crisis unfolding, and it has three familiar but increasingly dangerous faces. First, there is misinformation: false content that spreads without deliberate intent. It has always existed, but AI accelerates it, from realistic but entirely fabricated news articles to doctored screenshots taken out of context and shared widely. Second, there is disinformation: content created specifically to deceive. This used to be labor-intensive and expensive. Now generative AI can produce a relentless flow of fake reviews, fake social proof, fabricated press releases, and synthetic audio in seconds, at a scale no human workforce could ever match. Third, and perhaps most dangerous of all, is malinformation: true information stripped of context and weaponized. A single real email, selectively edited and released at an awkward moment, can do more damage than a hundred outright lies, precisely because it contains enough truth to be believed. A competitor, a criminal group, or an activist campaign no longer needs to breach a network to cause serious harm. All they have to do is shape what people see and believe about an organization. They can manipulate employees by feeding them false internal announcements. They can mislead customers by circulating fake product videos. They can pressure investors with fabricated financial documents. The speed from confusion to commercial damage is terrifyingly fast: a stock decision made on the strength of a fake headline, a partnership withdrawn because of a decontextualized executive video, a customer exodus triggered by a convincing but fraudulent data breach notice. What makes this so difficult for businesses is that it mirrors a struggle we are all facing as individuals. In an environment saturated with AI-generated content, the survival habits we need—pause before reacting, question the source, verify before acting—are the very habits organizations must build into their operations. But a poster campaign won’t solve it. The instinct to trust has become a vulnerability, and fixing that requires a structural response, not just an awareness drive.
This is where Zero Trust emerges as the way forward. Traditionally, Zero Trust was about access and privilege. It made sure the right people had access to the right applications, and nothing more. But in an AI-driven information environment, the principle needs to evolve. It is no longer enough to ask, “Who is requesting access?” We also have to ask, “What information is being used? What action is about to be taken? Can the intent behind that action be trusted?” In practice, this means going beyond authentication and asking questions about authenticity. Is this information verified? Is this image real or AI-generated? Has this content been edited, and if so, by whom? Has it been separated from its original context? Zero Trust provides a framework for answering those questions. It forces organizations to verify before acting, limit exposure wherever possible, and reduce the risk that false, manipulated, or decontextualized information will flow unchecked through the business. The direction is being set by standards bodies like the Coalition for Content Provenance and Authenticity (C2PA), which are working toward a future where provenance and integrity are embedded in digital content itself. Just as a padlock icon in a browser tells you a connection is secure, future content could carry its own digital proof of where it came from and whether it has been altered. In that world, trust no longer has to be searched for; it travels with the information. Every piece of content becomes a signal in a continuous trust decision. This is the natural evolution of Zero Trust: from securing access to securing meaning, from verifying identity to verifying reality.
But the urgency is even greater because of what is coming next: the agentic era. AI agents are beginning to enter the workplace, and they will increasingly operate like another person working alongside us. They will read documents, interpret data, make decisions, and take action. They will attend meetings, answer emails, write code, and manage workflows. The similarity to human colleagues, however, ends at the surface. These non-human identities move at machine speed, acting in milliseconds across thousands of tasks. Human-speed verification has no hope of keeping up. That means AI agents must be governed through a Zero Trust model from the very beginning. An agent should not be trusted simply because it sits inside the enterprise, has been approved by a user, or is connected to corporate systems. Its identity, permissions, behavior, and outputs all need to be continuously validated, every time, with the same rigor applied to a stranger walking into a data center. And the principle of least privilege must extend beyond access to information and function. An agent should get only the minimum access, only the minimum data, and only the minimum capability required for its specific task. But this creates a trust challenge that identity management alone cannot solve. Businesses will need to know whether they are dealing with a human or a machine at any given moment. They will need to know whether an agent is behaving responsibly, whether its actions reflect the organization’s values, and whether it is operating within agreed boundaries. In other words, organizations will need to adopt what might be called an operating constitution—a set of rules and principles that every agent is continuously measured against. And because this has to happen in real time, at machine speed, it will take AI itself to audit, flag, and govern these systems. We will need smart, automated oversight to keep the chain of trust intact.
The organizations that thrive in this new environment will be those that treat trust as something to be engineered, not assumed. This is a profound shift for leaders who have spent their careers building cultures of trust, open communication, and empowerment. It can feel counterintuitive to question everything and verify constantly. But the choice is not between trust and distrust; it is between conscious, verified trust and blind, dangerous trust. Misinformation, disinformation, and malinformation are not merely PR problems. They are security problems, resilience problems, and leadership problems. And AI is making them harder to ignore by the day. Leaders must therefore build the same discipline around authenticity that they have always applied to access. That means verifying content before it is acted upon, questioning the intent behind every significant piece of information, and limiting AI systems to what they actually need to do rather than giving them free rein. It means redesigning workflows so that critical decisions are never made on the basis of a single unverified input. It means ensuring that the people in your organization feel empowered to pause and ask, “Is this real?” without being embarrassed or pressured. It means recognizing that this is not simply an IT issue. It belongs on the board agenda, in risk registers, in compliance frameworks, and in every conversation about digital transformation. If an organization can be destabilized by a targeted disinformation campaign, then trust is not just a value—it is a critical business asset that must be actively protected and continuously maintained. And that protection must extend to the very systems we build and deploy, including the AI agents we hire, because every tool introduced into the organization carries its own trust risk.
The good news is that we already have the framework we need. Zero Trust is not a new concept; it has been protecting our networks and applications for years. What needs to change is the way we apply it. We must broaden its scope beyond access and into information, intent, behavior, and action. This means embedding verification into every link of the business chain: from the CEO’s voice on a conference call to the PDF attachment in a supplier’s email, from the video message on the corporate website to the AI agent automatically filing expense reports. It means accepting that trust is no longer the default setting in today’s operating environment. Instead, trust is a decision—a decision that must be made continuously, at machine speed, across every piece of information, every actor, and every action. It will be uncomfortable at first. None of us want to live in a world where we have to verify everything. But the reality is that we already live in a world where a well-aimed piece of synthetic media can topple a reputation or drain a bank account. The old ways of knowing—seeing is believing, hearing is relying—are no longer enough. We need new ways, and they are beginning to emerge: provenance standards, AI-driven verification, Zero Trust architecture applied to content, and a culture of healthy skepticism balanced with the need to act efficiently. The leaders who get this right will not only protect their organizations from harm; they will create a new kind of trust, one that is stronger because it is earned in the face of uncertainty. That is the challenge of this moment. It is also the opportunity. The organizations that engineer trust into everything they do—information, intelligence, and action—will be the ones able to navigate the age of AI with confidence. The rest will be at the mercy of whatever a deepfake says next.

