Zero Trust Can't Stop at a Claim. You Need to Prove It.
Zscaler, Thursday, August 20th, 2026
Zscaler argues policies describing intent tell you nothing about behavior, using a bank executive's AI ban as the example.
Zscaler opens with a senior executive at a large international bank in London insisting AI was not a risk because staff were not allowed to use it and policy said so. Zscaler argues that did not close the conversation.
A policy describes what a company intends and says nothing about what people actually do. In a firm full of capable people working against deadlines, the chance that not one of them had quietly opened an AI tool was close to zero.
The executive was describing a control he had asserted rather than one he had verified, which is the gap the post argues zero trust programmes must close with evidence.