The Erosion of Cybersecurity Zero-Trust Principles Through Generative AI: A Survey on the Challenges and Future Directions
Generative artificial intelligence (AI) and persistent empirical gaps are reshaping the cyber threat landscape faster than Zero-Trust Architecture (ZTA) research can respond. We reviewed 10 recent ZTA surveys and 136 primary studies (2022–2024) and found that 98% provided only partial or no real-world validation, leaving several core controls largely untested. Our critique, therefore, proceeds on two axes: first, mainstream ZTA research is empirically under-powered and operationally unproven; second, generative-…
Expeditionary mobile operations center (EMOC) by Gonzalez, Jose. Public domain
In a peer-reviewed survey published October 15, 2025, researchers analyzed 10 recent Zero-Trust Architecture surveys and 136 primary studies from 2022-2024 and found most controls lacked real-world validation. They argue generative AI attacks exploit those gaps and propose a seven-stage Cyber Fraud Kill Chain that maps synthetic identities, context manipulation, and adversarial telemetry to NIST SP 800-207 components.
The findings matter because they suggest current Zero-Trust principles of verify explicitly and assume breach are being undermined at scale, with compliance regimes unable to audit AI-mutable content. The authors contend incremental extensions are insufficient and call for a generative-AI-aware redesign, but the survey itself does not test countermeasures, leaving effectiveness and implementation feasibility unresolved.
- Review covered 10 recent ZTA surveys and 136 primary studies from 2022-2024.
- 98% of reviewed studies provided only partial or no real-world validation of core Zero-Trust controls.
- Authors propose Cyber Fraud Kill Chain with seven stages: target identification, preparation, engagement, deception, execution, monetization, and cover-up.
- CFKC maps generative techniques to NIST SP 800-207 components and cites synthetic identities and adversarial telemetry as erosion mechanisms.
Generative AI enables fraud attacks that erode Zero-Trust Architecture by using synthetic identities and context manipulation to increase false-negative rates, extend dwell time, bypass policies, and evade audit trails.
The rundown
The authors conducted a survey of 10 ZTA surveys and 136 primary studies published between 2022 and 2024, concluding mainstream ZTA research is empirically under-powered and operationally unproven.
To expose compounding risk, they introduced the Cyber Fraud Kill Chain, linking generative techniques to specific NIST SP 800-207 components and arguing that existing guidance offers no systematic countermeasures for AI-scaled attacks.
Sources
- Peer-reviewedJournal of Cybersecurity and Privacy2025-10-15
How should this claim be treated?
ace
The debate