Zero Trust Is Easier to Design and Harder to Achieve Than Ever

By Admin19 August 2026

By Raju Vegesna, Chief Evangelist, Zoho

Zero trust has never been simpler to describe: verify every user, device, and request, every time. The tooling behind it has matured into commodity categories. Gartner's 2025 roadmap puts 10% of large enterprises at a mature, measurable zero trust program by the end of 2026, up from under 1% in 2023.

Yet achieving zero trust in practice keeps getting harder. The surface area it has to cover has outgrown the model. Work now spans dozens of SaaS platforms, unmanaged devices, and AI tools employees adopt on their own. One layer has absorbed most of that sprawl: the browser.

The Browser Nobody Secured

Employees spend most of the workday inside a browser tab, moving between email, CRM, and generative AI tools without touching a corporate network. Cloud Security Alliance research found that 80% of organizations have already encountered risky AI agent behavior inside browsers, while only 37% have adjusted their security strategy in response.

Extensions carry much of that risk. LayerX data cited by CSA shows 53% of enterprise-installed extensions can read and change data on every site a user visits. Most employees click through that permission screen without registering what it grants. In January 2026, a fake AI assistant extension called AITOPIA accumulated 900,000 installs before it was caught exploiting exactly this access.

None of this trips a traditional alarm. Sendwin's analysis notes that endpoint tools built for the operating system treat browser memory as a black box. There is no lateral movement to flag, only an authenticated session quietly handing data to a script the user installed voluntarily.

Why This Breaks Zero Trust's Own Logic

Zero trust verifies identity and device posture at the point of access, then largely stops watching. Once a session is authenticated, an extension or OAuth grant inherits the trust the architecture just spent so much effort establishing. OAuth makes this persistent: a token granted to a compromised app survives a password reset. Startup Defense's research cites Salesforce environments breached through overly permissive OAuth defaults as one recent example. Continuous verification, zero trust's core promise, quietly ends at the browser tab.

Extending Zero Trust to Where Work Happens

Enterprise browsers close that gap by applying zero trust principles inside the session itself. Extension use runs through an allowlist instead of an open marketplace. Data loss prevention operates where a user types or pastes, not only where traffic crosses a network boundary. Shadow SaaS and AI usage become visible instead of invisible, and session posture is checked continuously so a stolen token loses value fast.

PeerSpot's 2026 category data shows Island leading enterprise browser mindshare at 27.8%, followed by Chrome Enterprise, Prisma Access Browser, and Edge for Business. The category is projected to grow from $6.3 billion in 2025 to $24.19 billion by 2035, a 14.42% compound annual rate tied directly to zero trust adoption. Gartner's own forecast expects enterprise browsers to sit at the center of most organizations' security strategy by 2027, not function as an optional add-on.

Closing the Gap, Not Adding a Tool 

Zero trust is a discipline of closing the distance between where policy is written and where employees actually work. For a decade, that distance sat at the network edge. Today it sits inside a browser tab, between an authenticated session and whatever extension has quietly attached itself to it. The organizations that treat the browser as part of their zero trust architecture, rather than the layer it forgot to cover, will be the ones whose programs hold up under the next incident.