AI News Feed
Market watch
Cybersecurity

Zero Trust mindset urged to counter AI-driven misinformation, disinformation and malinformation

TechRadar reports that businesses must apply Zero Trust principles to information flows to counter AI-generated misinformation, disinformation and malinformation, treating them as structural risks.

The warning comes from a CISO in Residence at Zscaler, who argues that employees, customers, investors and boards are already being deceived by deepfakes, cloned voices, fraudulent emails and other AI-enabled tactics. These tactics are not new, but AI has made them more convincing within the ordinary flow of business, the report says.

Organizations now need to treat misinformation, disinformation and malinformation as business risks. Misinformation is false content that spreads without deliberate intent. Disinformation is constructed specifically to deceive and can now be manufactured at scale. Malinformation, true information stripped of context and weaponized, is described as the most insidious of the three. A competitor, criminal group or activist campaign can cause damage without breaching a network, simply by shaping what people see and believe.

The article says this mirrors an individual struggle: in an environment saturated with AI-generated content, people need to pause, question sources and verify before acting. Organizations must build the same habits into their operations. The instinct to trust has become a vulnerability, and addressing it requires a structural response, not just awareness campaigns.

Under an evolved Zero Trust model, businesses must not only ask who is requesting access, but also question what information is being used, what action is being taken and whether the intent behind the action can be trusted. Verification goes beyond authentication to ask whether an image is real, whether content has been edited, and whether information is verified. Zero Trust forces organizations to verify before acting and limit exposure to false or manipulated information.

Standards bodies such as the Coalition for Content Provenance and Authenticity (C2PA) point toward a future where provenance and integrity are embedded in digital content itself, similar to a padlock in a browser indicating a secure connection. In that future, trust travels with the information, and every piece of content becomes a signal in a continuous trust decision, the report explains.

The need to trust intent becomes more pressing as AI agents enter the workplace. These agents operate like another person, reading documents, interpreting data, making decisions and acting, but at machine speed. Human-speed verification cannot keep up. Therefore, AI agents must be governed through a Zero Trust model from the outset. An agent should not be trusted just because it sits inside the enterprise, has been approved by a user, or is connected to corporate systems. Its identity, permissions, behavior and outputs need continuous validation, and it should be governed by least privilege.