<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN" "JATS-journalpublishing1-4.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.4" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">jcc</journal-id>
      <journal-title-group>
        <journal-title>Journal of Computer and Communications</journal-title>
      </journal-title-group>
      <issn pub-type="epub">2327-5227</issn>
      <issn pub-type="ppub">2327-5219</issn>
      <publisher>
        <publisher-name>Scientific Research Publishing</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.4236/jcc.2026.142005</article-id>
      <article-id pub-id-type="publisher-id">jcc-149647</article-id>
      <article-categories>
        <subj-group>
          <subject>Article</subject>
        </subj-group>
        <subj-group>
          <subject>Computer Science</subject>
          <subject>Communications</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Ensuring Ethical Governance in Autonomous Agentic Systems: A Zero Trust Approach to Safeguarding Future Technologies</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Atem</surname>
            <given-names>Eyong</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="aff1"><label>1</label> Business and Information Studies, Capitol Technology University, Laurel, USA </aff>
      <author-notes>
        <fn fn-type="conflict" id="fn-conflict">
          <p>The author declares no conflicts of interest regarding the publication of this paper.</p>
        </fn>
      </author-notes>
      <pub-date pub-type="epub">
        <day>10</day>
        <month>02</month>
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="collection">
        <month>02</month>
        <year>2026</year>
      </pub-date>
      <volume>14</volume>
      <issue>02</issue>
      <fpage>83</fpage>
      <lpage>105</lpage>
      <history>
        <date date-type="received">
          <day>26</day>
          <month>01</month>
          <year>2026</year>
        </date>
        <date date-type="accepted">
          <day>11</day>
          <month>02</month>
          <year>2026</year>
        </date>
        <date date-type="published">
          <day>14</day>
          <month>02</month>
          <year>2026</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>© 2026 by the authors and Scientific Research Publishing Inc.</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="open-access">
          <license-p> This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ( <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link> ). </license-p>
        </license>
      </permissions>
      <self-uri content-type="doi" xlink:href="https://doi.org/10.4236/jcc.2026.142005">https://doi.org/10.4236/jcc.2026.142005</self-uri>
      <abstract>
        <p>The rapid advancement of autonomous agentic systems (AAS) has revolutionized critical sectors such as healthcare, finance, defense, and cybersecurity. However, their integration into these domains raises significant ethical and security concerns, mainly when deployed within Zero Trust (ZT) frameworks, which assume no entity should be trusted by default. This paper explores the ethical governance of AAS within ZT frameworks, focusing on accountability, bias mitigation, and privacy protection. We examine the challenges posed by AAS, including decision-making accountability, inherited biases, and data privacy risks, and propose mitigation strategies such as explainable AI (XAI), human oversight, and privacy-preserving technologies. Additionally, we discuss the implementation of ZT principles, including continuous authentication, least privilege access, and network segmentation, and highlight the complexities of integrating AAS into these frameworks. The paper concludes with policy recommendations and future research directions, emphasizing the need for regulatory standards, ethical AI governance, and interdisciplinary collaboration to ensure the responsible deployment of AAS in ZT environments.</p>
      </abstract>
      <kwd-group kwd-group-type="author-generated" xml:lang="en">
        <kwd>Autonomous Agentic Systems</kwd>
        <kwd>Zero Trust Framework</kwd>
        <kwd>Ethical Governance</kwd>
        <kwd>Explainable AI</kwd>
        <kwd>Privacy-Preserving Technologies</kwd>
        <kwd>Accountability Mechanisms</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec1">
      <title>1. Introduction</title>
      <p>The rapid advancement of autonomous agentic systems (AAS) has ushered in a new era of technological innovation, particularly in critical infrastructure and cybersecurity. These systems, which operate with varying degrees of autonomy, are increasingly deployed to manage complex tasks, optimize operations, and enhance security protocols. However, their integration into critical sectors such as energy, healthcare, transportation, and defense has raised profound ethical and security concerns. As organizations increasingly adopt Zero Trust architectures—a security model that assumes no entity, internal or external, should be trusted by default—the need to integrate robust ethical governance frameworks for AAS becomes imperative. This article delves into the ethical considerations of deploying AAS within Zero Trust frameworks, focusing on accountability, bias mitigation, and privacy protection.</p>
      <p>Autonomous agentic systems are characterized by their ability to perform tasks with minimal human intervention, leveraging artificial intelligence (AI), machine learning (ML), and other advanced technologies. In critical infrastructure, AAS are being used to monitor and control power grids, manage water supply systems, and optimize transportation networks. For instance, smart grids employ AAS to balance energy supply and demand in real-time, while autonomous drones are used to inspect pipelines and other infrastructure components. However, the increasing reliance on these systems has exposed vulnerabilities that could be exploited by malicious actors, leading to catastrophic consequences.</p>
    </sec>
    <sec id="sec2">
      <title>2. Understanding Autonomous Agentic Systems</title>
      <p>Autonomous agentic systems (AAS) represent a significant leap in the evolution of artificial intelligence (AI) and machine learning (ML) technologies. These systems are designed to operate with a high degree of autonomy, enabling them to perform complex tasks, make decisions, and adapt to changing environments with minimal human intervention. Their applications span a wide range of sectors, including healthcare, cybersecurity, finance, and defense, where they are increasingly being deployed to enhance efficiency, accuracy, and security.</p>
      <sec id="sec2dot1">
        <title>2.1. Definition and Characteristics</title>
        <p>Autonomous agentic systems are AI-driven entities that exhibit agency, meaning they can perceive their environment, make decisions, and take actions to achieve specific goals without continuous human oversight. These systems are characterized by their ability to learn from data, adapt to new situations, and operate in dynamic and often unpredictable environments. Key characteristics of AAS include:</p>
        <p>1) Autonomy: AAS can perform tasks independently, relying on pre-programmed rules, machine learning models, or reinforcement learning algorithms to guide their behavior. This autonomy allows them to operate in environments where human intervention is impractical or impossible [<xref ref-type="bibr" rid="B1">1</xref>].</p>
        <p>2) Adaptability: These systems are designed to adapt to changing conditions, learning from new data and experiences to improve performance over time. This adaptability is particularly valuable in sectors such as cybersecurity, where threats evolve rapidly [<xref ref-type="bibr" rid="B2">2</xref>].</p>
        <p>3) Decision-Making Capability: AAS are equipped with decision-making algorithms that enable them to evaluate multiple options and choose the most appropriate course of action based on predefined objectives. This capability is critical in applications such as healthcare diagnostics and financial trading [<xref ref-type="bibr" rid="B3">3</xref>].</p>
        <p>4) Interactivity: AAS often interacts with other systems, humans, or their environment. For example, autonomous drones in defense operations interact with ground control systems and other drones to coordinate missions [<xref ref-type="bibr" rid="B4">4</xref>].</p>
        <p>5) Scalability: These systems can be scaled to handle large volumes of data and complex tasks, making them suitable for deployment in critical infrastructure and large-scale industrial operations [<xref ref-type="bibr" rid="B5">5</xref>].</p>
      </sec>
      <sec id="sec2dot2">
        <title>2.2. Applications in Various Sectors</title>
        <p>The versatility of autonomous agentic systems has led to their widespread adoption across multiple sectors. Below, we explore their applications in healthcare, cybersecurity, finance, and defense, highlighting their transformative impact and the challenges associated with their deployment.</p>
        <p>2.2.1. Healthcare</p>
        <p>In healthcare, AAS is revolutionizing diagnostics, treatment, and patient care. These systems leverage AI and ML to analyze medical data, assist in decision-making, and perform complex procedures with precision. Key applications include:</p>
        <p>AI-Driven Diagnostics: AAS are being used to analyze medical images, such as X-rays, MRIs, and CT scans, to detect diseases like cancer, cardiovascular conditions, and neurological disorders. For example, AI algorithms have demonstrated the ability to identify breast cancer in mammograms with accuracy comparable to or exceeding that of human radiologists [<xref ref-type="bibr" rid="B6">6</xref>].Robotic Surgery: Autonomous surgical robots, such as the da Vinci Surgical System, assist surgeons in performing minimally invasive procedures with enhanced precision and control. These systems reduce the risk of human error and improve patient outcomes [<xref ref-type="bibr" rid="B7">7</xref>].Personalized Medicine: AAS analyzes patient data, including genetic information and medical history, to recommend customized treatment plans. This approach has shown promise in managing chronic diseases such as diabetes and cancer [<xref ref-type="bibr" rid="B8">8</xref>].</p>
        <p>2.2.2. Cybersecurity</p>
        <p>In cybersecurity, AAS detect, prevent, and respond to cyber threats in real time. Their ability to process vast amounts of data and identify patterns makes them invaluable in safeguarding digital infrastructure. Key applications include:</p>
        <p>Automated Threat Detection: AAS uses machine learning algorithms to monitor network traffic, identify anomalies, and detect potential cyberattacks. For instance, intrusion detection systems (IDS) powered by AI can identify and mitigate threats such as malware, phishing, and distributed denial-of-service (DDoS) attacks [<xref ref-type="bibr" rid="B9">9</xref>].Incident Response: Autonomous systems can automatically respond to cyber incidents by isolating affected systems, blocking malicious traffic, and initiating recovery protocols. This reduces response times and minimizes the impact of cyberattacks [<xref ref-type="bibr" rid="B10">10</xref>]. AI improves threat detection by using machine learning to analyze data in real-time, identifying patterns and anomalies to catch new threats early. AI also automates incident response, learning from past breaches and adapting to emerging threat.Vulnerability Management: AAS continuously scans systems for vulnerabilities and applies patches or updates to mitigate risks. This proactive approach enhances the resilience of cybersecurity frameworks [<xref ref-type="bibr" rid="B11">11</xref>].</p>
        <p>2.2.3. Finance</p>
        <p>The financial sector has embraced AAS to improve efficiency, reduce risks, and enhance decision-making. These systems are particularly effective in fraud detection, trading, and risk management. Key applications include:</p>
        <p>Fraud Detection: AAS analyzes transaction data to identify fraudulent activities, such as credit card fraud and money laundering. Machine learning models can detect unusual patterns and flag suspicious transactions in real time [<xref ref-type="bibr" rid="B12">12</xref>].Algorithmic Trading: Autonomous trading systems use AI algorithms to analyze market data, predict trends, and execute trades at optimal times. These systems operate at high speeds and volumes, enabling them to capitalize on market opportunities [<xref ref-type="bibr" rid="B13">13</xref>]. AI enhances cybersecurity by swiftly analyzing vast amounts of data to detect anomalies and potential threats.Risk Management: AAS assesses financial risks by analyzing market conditions, credit scores, and economic indicators. They provide insights that help organizations make informed decisions and mitigate potential losses [<xref ref-type="bibr" rid="B14">14</xref>].</p>
        <p>2.2.4. Defense</p>
        <p>In defense, AAS are transforming military operations by enhancing situational awareness, precision, and operational efficiency. These systems are deployed in various forms, including autonomous drones, robotic combat units, and surveillance systems. Key applications include:</p>
        <p>Autonomous Drones: Unmanned Aerial Vehicles (UAVs) equipped with AI capabilities are used for reconnaissance, surveillance, and targeted strikes. These drones can operate in hostile environments, reducing the risk to human personnel [<xref ref-type="bibr" rid="B4">4</xref>].Robotic Combat Units: Autonomous ground robots are deployed in combat zones for bomb disposal, reconnaissance, and logistics support. These systems enhance the safety and effectiveness of military operations [<xref ref-type="bibr" rid="B15">15</xref>].Surveillance and Intelligence: AAS analyzes data from satellites, drones, and other sources to provide real-time intelligence and situational awareness. This information is critical for decision-making in military operations [<xref ref-type="bibr" rid="B16">16</xref>] (<xref ref-type="fig" rid="fig1">Figure 1</xref>).</p>
        <fig id="fig1">
          <label>Figure 1</label>
          <graphic xlink:href="https://html.scirp.org/file/1733094-rId15.jpeg?20260214115322" />
        </fig>
        <p>Figure 1. AI-driven threat detection improvements in cybersecurity.</p>
      </sec>
    </sec>
    <sec id="sec3">
      <title>3. Ethical Concerns in Autonomous Systems</title>
      <p>The deployment of autonomous agentic systems (AAS) across critical sectors has brought about significant ethical challenges that must be addressed to ensure responsible use. While offering numerous benefits, these systems also raise concerns related to decision-making accountability, bias and discrimination, and privacy and surveillance. This section details these ethical concerns, highlighting their implications and the need for robust governance frameworks.</p>
      <sec id="sec3dot1">
        <title>3.1. Decision-Making and Accountability</title>
        <p>One of the most pressing ethical concerns surrounding AAS is the issue of accountability in decision-making. Autonomous systems are designed to operate with minimal human intervention, making decisions based on pre-programmed rules, machine learning models, or real-time data analysis. However, determining responsibility becomes a complex legal and ethical challenge when these systems make erroneous or harmful decisions.</p>
        <p>The Problem of Attribution: In traditional systems, human operators are accountable for decisions and actions. However, in AAS, the decision-making process is often opaque, making it difficult to attribute responsibility. For example, if an autonomous vehicle causes an accident, is the manufacturer, the software developer, or the user at fault? This lack of clarity complicates legal proceedings and undermines trust in autonomous systems [<xref ref-type="bibr" rid="B17">17</xref>].Moral Responsibility: AAS operate in environments where their decisions can have significant ethical implications, such as healthcare or defense. For instance, an autonomous medical diagnosis system that makes an incorrect recommendation could harm a patient. Similarly, an autonomous weapon system that mistakenly targets civilians raises profound ethical questions about delegating life-and-death decisions to machines [<xref ref-type="bibr" rid="B18">18</xref>].Regulatory Challenges: Existing legal frameworks are often ill-equipped to address the unique challenges posed by AAS. For example, liability laws typically assume human agency, making applying them to autonomous systems difficult. Developing new regulatory frameworks that clearly define accountability for AAS is essential to ensure their ethical deployment [<xref ref-type="bibr" rid="B19">19</xref>].</p>
        <p>Mitigation Strategies</p>
        <p>Explainable AI (XAI): Developing transparent AI systems that can explain their decision-making processes can help address accountability concerns. Explainable AI allows stakeholders to understand how decisions are made, facilitating accountability and trust [<xref ref-type="bibr" rid="B20">20</xref>].Human Oversight: Incorporating human oversight mechanisms, such as human-in-the-loop (HITL) systems, ensures that critical decisions are reviewed by humans, reducing the risk of harmful outcomes [<xref ref-type="bibr" rid="B21">21</xref>].</p>
      </sec>
      <sec id="sec3dot2">
        <title>3.2. Bias and Discrimination</title>
        <p>Bias in autonomous systems is a significant ethical concern, particularly in law enforcement, finance, and healthcare sectors. Machine learning algorithms underpin many AAS and are trained on large datasets that may contain biases, leading to unfair or discriminatory outcomes.</p>
        <p>Inherited Biases: AAS can perpetuate or amplify biases in their training data. For example, facial recognition systems have been shown to exhibit racial and gender biases, leading to higher error rates for specific demographic groups [<xref ref-type="bibr" rid="B22">22</xref>]. Similarly, predictive policing algorithms may disproportionately target minority communities if trained on biased historical crime data [<xref ref-type="bibr" rid="B23">23</xref>].Impact on Fairness: Bias in AAS can result in the unfair treatment of individuals or groups. In the financial sector, biased algorithms used for credit scoring or loan approvals may deny opportunities to specific populations. In healthcare, biased diagnostic tools may lead to unequal patient treatment based on race, gender, or socioeconomic status [<xref ref-type="bibr" rid="B24">24</xref>].Reinforcement of Stereotypes: AAS that rely on biased data can reinforce harmful stereotypes, perpetuating social inequalities. For instance, hiring algorithms trained on biased data may favor specific demographics over others, exacerbating workplace discrimination [<xref ref-type="bibr" rid="B25">25</xref>].</p>
        <p>Mitigation Strategies</p>
        <p>Bias Detection and Mitigation: Techniques such as fairness-aware machine learning and adversarial debiasing can help identify and mitigate biases in training data and algorithms [<xref ref-type="bibr" rid="B26">26</xref>].Diverse and Representative Data: Ensuring that training datasets are diverse and representative of the population can reduce the risk of biased outcomes [<xref ref-type="bibr" rid="B27">27</xref>].Algorithmic Audits: Regular audits of AAS by independent third parties can help identify and address biases, ensuring compliance with ethical standards [<xref ref-type="bibr" rid="B28">28</xref>].</p>
      </sec>
      <sec id="sec3dot3">
        <title>3.3. Privacy and Surveillance</title>
        <p>The use of AAS in cybersecurity and surveillance contexts raises significant privacy concerns. These systems often collect, process, and store vast amounts of personal data, posing privacy and security risks.</p>
        <p>Data Collection and Usage: AAS in surveillance applications, such as facial recognition systems or smart city technologies, can collect sensitive personal data without individuals’ consent. This raises ethical questions about the extent to which such data collection is justified and how the data is used [<xref ref-type="bibr" rid="B29">29</xref>].Compliance with Privacy Laws: AAS must comply with privacy regulations such as the General Data Protection Regulation (GDPR) in the European Union and the Health Insurance Portability and Accountability Act (HIPAA) in the United States. These laws mandate strict data collection, storage, and usage guidelines, requiring organizations to implement robust data governance frameworks [<xref ref-type="bibr" rid="B30">30</xref>].Surveillance and Civil Liberties: The widespread use of AAS can infringe on civil liberties, such as the right to privacy and freedom of movement. For example, deploying autonomous drones for public surveillance has sparked debates about the balance between security and individual rights [<xref ref-type="bibr" rid="B31">31</xref>].</p>
        <p>Mitigation Strategies</p>
        <p>Privacy by Design: Incorporating privacy considerations into the design and development of AAS can help minimize data collection and ensure compliance with privacy laws [<xref ref-type="bibr" rid="B32">32</xref>].Data Anonymization: Data anonymization and encryption can protect individuals’ privacy while allowing AAS to function effectively [<xref ref-type="bibr" rid="B33">33</xref>].Transparency and Consent: Ensuring transparency in data collection practices and obtaining informed consent from individuals can help build trust and ensure ethical data usage [<xref ref-type="bibr" rid="B34">34</xref>].</p>
      </sec>
    </sec>
    <sec id="sec4">
      <title>4. Zero Trust Frameworks: Principles and Application</title>
      <p>The Zero Trust (ZT) security model has emerged as a critical framework for modern cybersecurity, particularly in an era where traditional perimeter-based defenses are increasingly inadequate. Zero Trust operates on the principle of “never trust, always verify,” requiring continuous authentication and strict access controls to protect networks from both insider and external threats. This section explores the core tenets of Zero Trust, its implementation in cybersecurity, and the challenges and limitations associated with its adoption, particularly in the context of integrating autonomous agentic systems (AAS).</p>
      <sec id="sec4dot1">
        <title>4.1. Implementation in Cybersecurity</title>
        <p>Implementing a zero-trust framework involves a comprehensive approach to cybersecurity, integrating multiple technologies and practices to enforce its core principles. Key components of Zero Trust implementation include:</p>
        <p>Identity Verification: Robust identity and access management (IAM) systems are essential for continuous authentication. Multi-factor authentication (MFA) and biometric verification are commonly used to ensure that only authorized users and devices can access network resources [<xref ref-type="bibr" rid="B35">35</xref>]. Challenge: How do you continuously authenticate an autonomous system, such as a drone or an AI-driven diagnostic tool, when it doesn’t have a traditional “user” identity?Device Security: Zero Trust requires that all devices accessing the network meet strict security standards. This includes ensuring that devices are up-to-date with security patches, have endpoint protection installed, and are free from malware [<xref ref-type="bibr" rid="B36">36</xref>].Least Privilege Access: Access controls are dynamically adjusted based on user roles, device security posture, and contextual factors such as location and time of access. This ensures that users and devices can only access the resources they need at any given time [<xref ref-type="bibr" rid="B37">37</xref>]. How do you enforce least privilege access for AAS without hindering their ability to perform complex tasks? For example, an autonomous trading system may need access to vast amounts of financial data to make decisions, but granting such access could increase the risk of data breaches.Network Segmentation: Micro-segmentation is implemented to isolate critical assets and limit lateral movement within the network. Software-defined networking (SDN) and virtual LANs (VLANs) are often used to create these isolated segments [<xref ref-type="bibr" rid="B38">38</xref>]. The use of software-defined networking (SDN) to dynamically create and manage network segments based on the operational needs of AAS. This would allow for flexible segmentation that adapts to the system’s requirements while maintaining security.Continuous Monitoring and Analytics: Zero Trust frameworks rely on continuous network activity monitoring to detect and respond to potential threats in real time. Security information and event management (SIEM) systems and machine learning algorithms are used to analyze traffic patterns and identify anomalies [<xref ref-type="bibr" rid="B39">39</xref>].</p>
      </sec>
      <sec id="sec4dot2">
        <title>4.2. Case Study: Google’s AI for Breast Cancer Screening</title>
        <p>4.2.1. Background &amp; Significance</p>
        <p>Breast cancer is one of the leading causes of cancer-related deaths globally. Early detection significantly improves survival rates, yet traditional mammogram analysis has limitations, including false positives and false negatives.</p>
        <p>4.2.2. AI Model Development</p>
        <p>Google Health developed a deep learning model trained on 76,000 mammograms from the UK and 15,000 from the US.To validate generalizability, the AI model was tested on independent datasets with over 25,000 UK and 3,000 US mammograms.</p>
        <p>4.2.3. Key Findings</p>
        <p>Reduced False Positives by 5.7% (US) and 1.2% (UK) → Fewer unnecessary biopsies.Reduced False Negatives by 9.4% (US) and 2.7% (UK) → Fewer missed cancer diagnoses.Outperformed Radiologists: In retrospective analysis, the AI model detected cancer more accurately than experienced radiologists.Consistency: Unlike human experts, whose performance can vary due to fatigue or cognitive biases, AI provided uniform interpretations.</p>
        <p>4.2.4. Ethical Governance Challenges in AI Diagnostics</p>
        <p>Despite the success, several ethical concerns and governance challenges arise:</p>
        <p><bold>1) Transparency &amp; Explainability</bold></p>
        <p>The AI system’s decision-making process is not always interpretable.Black-box models limit clinicians’ ability to understand and trust AI-generated diagnoses.Ethical Governance Insight: Implement Explainable AI (XAI) techniques such as saliency maps to visualize which areas in a mammogram influenced the AI’s prediction.</p>
        <p><bold>2) Bias &amp; Generalizability</bold></p>
        <p>The training dataset was predominantly from Western populations.AI models may underperform on underrepresented ethnic groups due to biased training data.Ethical Governance Insight: Regulatory frameworks should mandate diverse, representative datasets for training AI in medical applications.</p>
        <p><bold>3) Accountability in Misdiagnosis</bold></p>
        <p>If an AI incorrectly classifies a tumor as benign, who is responsible? The developer, the hospital, or the physician?Ethical Governance Insight: A structured audit log tracking AI-generated diagnoses and clinician overrides can enhance accountability.</p>
        <p><bold>4) Privacy &amp; Data Protection</bold></p>
        <p>AI models require access to large datasets, raising concerns about patient data privacy and potential misuse.Ethical Governance Insight: Implement Privacy-Preserving Machine Learning (PPML) techniques, such as federated learning, to train AI models without direct access to patient data (<bold>Table 1</bold>).</p>
        <p>Table 1. Practical takeaways for ethical AI governance.</p>
        <table-wrap id="tbl1">
          <label>Table 1</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Issue</bold>
                </td>
                <td>
                  <bold>Challenge</bold>
                </td>
                <td>
                  <bold>Ethical Governance Strategy</bold>
                </td>
              </tr>
              <tr>
                <td>
                  <bold>Explainability</bold>
                </td>
                <td>AI decisions are hard to interpret.</td>
                <td>
                  Require
                  <bold>XAI techniques</bold>
                  for transparency.
                </td>
              </tr>
              <tr>
                <td>
                  <bold>Bias</bold>
                </td>
                <td>AI may underperform on certain demographics.</td>
                <td>
                  Mandate
                  <bold>diverse training datasets</bold>
                  .
                </td>
              </tr>
              <tr>
                <td>
                  <bold>Accountability</bold>
                </td>
                <td>Unclear responsibility for AI errors.</td>
                <td>
                  Develop
                  <bold>audit logs</bold>
                  and human oversight.
                </td>
              </tr>
              <tr>
                <td>
                  <bold>Privacy</bold>
                </td>
                <td>AI requires sensitive health data.</td>
                <td>
                  Use
                  <bold>federated learning</bold>
                  for data protection.
                </td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec id="sec4dot3">
        <title>4.3. Case Study: Google’s BeyondCorp</title>
        <p>Google introduced BeyondCorp as an alternative to traditional perimeter-based security models after a sophisticated cyberattack in 2009 (Operation Aurora). BeyondCorp enforces Zero-Trust principles, ensuring access control based on continuous authentication, device trustworthiness, and dynamic risk evaluation.</p>
        <p>4.3.1. How AI Is Integrated into BeyondCorp</p>
        <p>AI-Driven Continuous AuthenticationAI models assess user and device behavior in real-time, detecting anomalies that might indicate compromised credentials or insider threats.AI can trigger additional authentication steps if a user logs in from an unusual location or at an odd time.Automated Risk Scoring &amp; Adaptive AccessAI analyzes risk signals such as login patterns, endpoint security posture, and network requests to adjust access levels dynamically.Employees are only granted the minimum access required (Principle of Least Privilege).Self-Healing Endpoint SecurityGoogle’s AI-driven Endpoint Verification system ensures all devices connecting to internal applications are compliant with security policies.Devices found vulnerable (e.g., outdated software, malware infection) are automatically quarantined until they meet compliance requirements.</p>
        <p>4.3.2. Ethical Considerations in AI-Driven BeyondCorp</p>
        <p>Transparency &amp; Explainability → Google ensures audit logs and explainability mechanisms are in place to justify AI-driven access control decisions.Privacy Protection → AI-driven authentication minimizes data collection, ensuring compliance with privacy laws like GDPR and CCPA.Bias Mitigation → AI models are regularly audited to avoid discriminatory access control decisions that might disproportionately affect certain employees.</p>
        <p>Google’s BeyondCorp initiative is a prominent example of Zero Trust implementation. BeyondCorp shifts access controls from the network perimeter to individual users and devices, ensuring access is granted based on identity and device security rather than network location. This approach has significantly enhanced Google’s security posture, reducing the risk of insider threats and external attacks [<xref ref-type="bibr" rid="B40">40</xref>].</p>
      </sec>
      <sec id="sec4dot4">
        <title>4.4. Challenges and Limitations</title>
        <p>While Zero Trust offers significant security benefits, its implementation is challenging. These challenges are further compounded when autonomous agentic systems (AAS) are integrated into Zero Trust frameworks.</p>
        <p>1) Infrastructure Investment: Implementing Zero Trust requires significant investment in new technologies, such as IAM systems, endpoint protection, and network segmentation tools. Organizations must also invest in training and reconfiguring their IT infrastructure, which can be costly and time-consuming [<xref ref-type="bibr" rid="B35">35</xref>].</p>
        <p>2) System Efficiency: The continuous authentication and monitoring required by Zero Trust can introduce latency and reduce system efficiency. This is particularly problematic in environments where real-time performance is critical, such as financial trading or healthcare [<xref ref-type="bibr" rid="B36">36</xref>].</p>
        <p>3) Complexity of Integration: Integrating AAS into Zero Trust frameworks introduces additional complexities. Autonomous systems often operate with minimal human intervention, making applying traditional authentication and access control mechanisms difficult. For example, how does one verify the identity of an autonomous drone or ensure that an AI-driven diagnostic tool complies with least privilege principles [<xref ref-type="bibr" rid="B38">38</xref>].</p>
        <p>4) Trust Verification: AAS rely on machine learning models that may be opaque or difficult to interpret, raising questions about how to verify their trustworthiness. Ensuring these systems comply with Zero Trust principles requires new approaches to explainability and transparency [<xref ref-type="bibr" rid="B20">20</xref>].</p>
        <p>5) Scalability: Zero Trust frameworks must be scalable to accommodate the growing number of devices and users in modern networks. This is particularly challenging in large organizations or those with distributed workforces, where maintaining consistent security policies across all endpoints can be difficult [<xref ref-type="bibr" rid="B37">37</xref>].</p>
      </sec>
      <sec id="sec4dot5">
        <title>4.5. Mitigation Strategies</title>
        <p>Phased Implementation: Organizations can adopt a phased approach to Zero Trust implementation, starting with critical assets and gradually expanding to the entire network. This reduces the initial investment and allows for iterative improvements [<xref ref-type="bibr" rid="B35">35</xref>].Automation and AI: Leveraging automation and AI can help manage the complexity of Zero Trust frameworks. For example, AI-driven analytics can enhance continuous monitoring, while automation can streamline access control and policy enforcement [<xref ref-type="bibr" rid="B36">36</xref>].Collaboration with Vendors: Partnering with technology vendors and cybersecurity experts can help organizations overcome implementation challenges and ensure compliance with Zero Trust principles [<xref ref-type="bibr" rid="B38">38</xref>].</p>
      </sec>
    </sec>
    <sec id="sec5">
      <title>5. Microsoft’s Zero Trust Deployment: AI-Powered Least Privilege Access</title>
      <sec id="sec5dot1">
        <title>5.1. Background</title>
        <p>Microsoft has been a leading advocate of Zero Trust security across its enterprise and cloud services. The company applies AI-powered security solutions to manage device security, user authentication, and network access controls [<xref ref-type="bibr" rid="B41">41</xref>].</p>
      </sec>
      <sec id="sec5dot2">
        <title>5.2. How AI Is Integrated into Microsoft’s Zero Trust Framework</title>
        <p>AI-Driven Least Privilege EnforcementMicrosoft uses Azure Active Directory Conditional Access Policies to grant user access dynamically based on AI-evaluated risk.Example: AI detects unusual login activity (e.g., logging in from a high-risk country) and enforces additional security checks.Automated Threat Detection with Microsoft DefenderAI models analyze billions of security signals daily to detect anomalous network behavior, insider threats, and malware intrusions.Microsoft Defender for Endpoint uses AI to predict and prevent advanced cyberattacks in real-time [<xref ref-type="bibr" rid="B41">41</xref>].AI-Powered Compliance MonitoringMicrosoft Compliance Manager uses AI to track regulatory compliance across industries, ensuring that security policies align with standards like NIST, ISO/IEC 27001, and GDPR.AI can automate remediation, reducing compliance gaps without manual intervention (<bold>Table 2</bold>).</p>
        <p>Table 2. Comparison of Google and Microsoft’s AI-driven zero trust approaches.</p>
        <table-wrap id="tbl2">
          <label>Table 2</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Feature</bold>
                </td>
                <td>
                  <bold>Google BeyondCorp</bold>
                </td>
                <td>
                  <bold>Microsoft Zero Trust</bold>
                  <bold>Deployment</bold>
                </td>
              </tr>
              <tr>
                <td>
                  <bold>Authentication</bold>
                </td>
                <td>AI-driven continuous authentication</td>
                <td>AI-powered adaptive conditional access</td>
              </tr>
              <tr>
                <td>
                  <bold>Threat</bold>
                  <bold>Detection</bold>
                </td>
                <td>AI-based anomaly detection in access requests</td>
                <td>AI-powered Defender detects advanced cyber threats</td>
              </tr>
              <tr>
                <td>
                  <bold>Device</bold>
                  <bold>Security</bold>
                </td>
                <td>AI-driven endpoint verification</td>
                <td>AI-enforced device compliance policies</td>
              </tr>
              <tr>
                <td>
                  <bold>Least Privilege</bold>
                </td>
                <td>Dynamic role-based access using AI</td>
                <td>AI-managed conditional least privilege access</td>
              </tr>
              <tr>
                <td>
                  <bold>Compliance</bold>
                  <bold>Monitoring</bold>
                </td>
                <td>Audit logs ensure transparency</td>
                <td>AI automates compliance with global regulations</td>
              </tr>
              <tr>
                <td>
                  <bold>Privacy</bold>
                  <bold>Protection</bold>
                </td>
                <td>AI minimizes personal data collection</td>
                <td>AI models trained on anonymized datasets</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
    </sec>
    <sec id="sec6">
      <title>6. Intersection of Ethical Governance and Zero Trust in Autonomous Systems</title>
      <p>Integrating autonomous agentic systems (AAS) into Zero Trust (ZT) frameworks presents unique challenges at the intersection of ethical governance and cybersecurity. As AAS becomes increasingly prevalent in critical sectors, ensuring accountability, transparency, and privacy within these systems is paramount. This section explores how ethical governance principles can be embedded into Zero Trust frameworks to address these challenges, focusing on accountability, transparency, and privacy protection.</p>
      <sec id="sec6dot1">
        <title>6.1. Ensuring Accountability in Autonomous Agents</title>
        <p>Accountability is a cornerstone of ethical governance, particularly in autonomously operating systems. In the context of AAS, accountability ensures that decisions and actions can be traced back to their source, whether human or machine, and that appropriate measures are in place to address errors or misconduct.</p>
        <p>Audit Trails and Logging: Embedding audit trails within AAS is essential for tracking decision-making processes. These logs record the system’s actions, including data inputs, algorithmic decisions, and outputs. For example, an autonomous diagnostic system in healthcare should maintain detailed logs of patient data, diagnostic criteria, and treatment recommendations to ensure accountability in case of errors [<xref ref-type="bibr" rid="B17">17</xref>].Regulatory Compliance: Accountability mechanisms must align with regulatory requirements, such as the General Data Protection Regulation (GDPR) in the EU or the Health Insurance Portability and Accountability Act (HIPAA) in the US. These regulations mandate that organizations implement measures to ensure transparency and accountability in automated decision-making processes [<xref ref-type="bibr" rid="B30">30</xref>].Human Oversight: Incorporating human-in-the-loop (HITL) systems ensures that humans review critical decisions made by AAS. This not only enhances accountability but also provides a safeguard against unintended consequences. For instance, human oversight can intervene in autonomous vehicles when the system’s decision-making is uncertain or risky [<xref ref-type="bibr" rid="B21">21</xref>].</p>
        <p>Mitigation Strategies:</p>
        <p>Blockchain for Immutable Logs: Blockchain technology can create immutable audit trails, ensuring that logs cannot be tampered with and providing a transparent record of system actions [<xref ref-type="bibr" rid="B42">42</xref>].Accountability Frameworks: Developing standardized accountability frameworks for AAS can help organizations ensure compliance with ethical and regulatory standards [<xref ref-type="bibr" rid="B19">19</xref>].</p>
      </sec>
      <sec id="sec6dot2">
        <title>6.2. Transparency and Explainability in AI Decision-Making</title>
        <p>Transparency and explainability are critical for building trust in AAS, particularly in high-stakes applications such as healthcare, finance, and defense. Explainable AI (XAI) ensures that the decision-making processes of autonomous systems are understandable to stakeholders, including users, regulators, and affected individuals.</p>
        <p>Explainable AI (XAI): XAI techniques, such as decision trees, rule-based systems, and model-agnostic methods, provide insights into how AAS arrive at their decisions. For example, in financial services, explainable algorithms can help regulators understand why a loan application was denied, ensuring compliance with anti-discrimination laws [<xref ref-type="bibr" rid="B20">20</xref>].Stakeholder Trust: Transparency in AAS fosters trust among users and stakeholders. In healthcare, for instance, patients are more likely to trust AI-driven diagnostic tools if they understand how recommendations are made [<xref ref-type="bibr" rid="B8">8</xref>].Ethical Guidelines: Ethical frameworks, such as the EU’s Ethics Guidelines for Trustworthy AI, emphasize the importance of transparency and explainability in AI systems. These guidelines recommend that AI decisions be explainable to users and that systems provide transparent information about their capabilities and limitations [<xref ref-type="bibr" rid="B43">43</xref>].</p>
        <p>Mitigation Strategies:</p>
        <p>Model Interpretability: Using interpretable machine learning models, such as linear regression or decision trees, can enhance transparency in AAS [<xref ref-type="bibr" rid="B44">44</xref>].User-friendly explanations: User-friendly explanations, such as visualizations or natural language summaries, can make AI decisions more accessible to non-technical stakeholders [<xref ref-type="bibr" rid="B45">45</xref>].</p>
      </sec>
      <sec id="sec6dot3">
        <title>6.3. Privacy and Data Protection within Zero Trust Frameworks</title>
        <p>Zero Trust frameworks enhance data security by enforcing strict access controls and continuous monitoring. However, integrating AAS into these frameworks requires balancing security with privacy protection, ensuring that sensitive data is handled ethically and complies with regulations.</p>
        <p>Data Minimization: Zero Trust principles align with data minimization, a key tenet of privacy regulations such as GDPR. By limiting data collection and access to what is strictly necessary, organizations can reduce the risk of privacy breaches [<xref ref-type="bibr" rid="B30">30</xref>].Encryption and Anonymization: Encrypting data at rest and in transit, as well as anonymizing sensitive information, ensures that even if data is accessed, it cannot be easily exploited. For example, patient data can be anonymized in healthcare before training AI models, protecting individual privacy [<xref ref-type="bibr" rid="B33">33</xref>].Access Control and Least Privilege: Zero Trust’s principle of least privilege ensures that AAS only access the data necessary for their tasks. This reduces the risk of unauthorized access and data breaches. For instance, an autonomous financial trading system should only have access to the data required for its trading algorithms, not the entire customer database [<xref ref-type="bibr" rid="B35">35</xref>].Ethical Data Governance: Ethical governance frameworks should ensure that AAS complies with privacy regulations while maintaining operational efficiency. This includes implementing data protection impact assessments (DPIAs) and ensuring that data usage is transparent and consensual [<xref ref-type="bibr" rid="B32">32</xref>].</p>
        <p>Mitigation Strategies:</p>
        <p>Privacy by Design: Incorporating privacy considerations into the design and development of AAS ensures that data protection is a core component of the system [<xref ref-type="bibr" rid="B32">32</xref>].Regular Audits: Regular audits of data access and usage within Zero Trust frameworks help identify and address potential privacy risks [<xref ref-type="bibr" rid="B28">28</xref>].</p>
        <p>Ethical Considerations in AI-Driven Zero Trust</p>
        <p>Fairness &amp; Non-Discrimination → AI models undergo bias testing to prevent unfair enforcement of access controls (e.g., discriminatory blocking of specific users or locations).Accountability &amp; Explainability → Microsoft ensures that AI-driven security decisions are transparent, allowing security teams to audit and override when necessary.Data Security &amp; Privacy → AI models are trained on anonymized, aggregated data, ensuring privacy is not compromised while detecting security threats.</p>
      </sec>
    </sec>
    <sec id="sec7">
      <title>7. Policy Recommendations and Future Directions</title>
      <p>Integrating autonomous agentic systems (AAS) into Zero Trust (ZT) frameworks requires a proactive approach to policymaking, ethical governance, and research. As these systems become more pervasive in critical sectors, it is essential to establish regulatory standards, adopt best practices for ethical AI governance, and identify future research directions to address emerging challenges. This section outlines policy recommendations and future directions to ensure the responsible deployment of AAS within ZT environments.</p>
      <sec id="sec7dot1">
        <title>7.1. Regulatory Standards and Compliance</title>
        <p>To ensure the ethical and secure deployment of AAS in Zero Trust frameworks, governments, and industry bodies must establish robust regulatory standards and compliance mechanisms. These frameworks should address cybersecurity and ethical considerations, ensuring AAS operates transparently, accountably, and in alignment with societal values.</p>
        <p>AI Ethics Guidelines: Regulatory frameworks should incorporate AI ethics guidelines, such as those proposed by the European Commission’s High-Level Expert Group on AI. These guidelines emphasize principles such as fairness, transparency, accountability, and human oversight, which are critical for the ethical deployment of AAS [<xref ref-type="bibr" rid="B43">43</xref>].Cybersecurity Compliance: AAS operating within ZT frameworks must comply with cybersecurity standards, such as the NIST Cybersecurity Framework and ISO/IEC 27001. These standards provide guidelines for implementing Zero Trust principles, including continuous authentication, least privilege access, and micro-segmentation [<xref ref-type="bibr" rid="B36">36</xref>][<xref ref-type="bibr" rid="B46">46</xref>].Data Protection Regulations: AAS must adhere to data protection regulations, such as the General Data Protection Regulation (GDPR) in the EU and the California Consumer Privacy Act (CCPA) in the US. These regulations mandate strict data collection, storage, and usage controls, ensuring that AAS handles sensitive information responsibly [<xref ref-type="bibr" rid="B30">30</xref>].Cross-Border Collaboration: Given the global nature of cybersecurity threats, international collaboration is essential to harmonize regulatory standards and ensure consistent enforcement. Organizations such as the United Nations and the OECD can play a key role in facilitating cross-border cooperation on AI and cybersecurity governance [<xref ref-type="bibr" rid="B19">19</xref>].</p>
        <p>7.1.1. Critical Assessment of Existing Regulatory Frameworks</p>
        <p><bold>1) General Data Protection Regulation (GDPR)</bold></p>
        <p>Strengths: GDPR is one of the most comprehensive data protection frameworks, emphasizing transparency, accountability, and user consent. It requires organizations to implement measures such as data minimization, encryption, and privacy by design.Limitations for AAS and ZT:GDPR focuses primarily on human data subjects and does not explicitly address the challenges posed by autonomous systems. For example, how can consent be obtained from an autonomous drone, or how can transparency be ensured in AI-driven decision-making?The regulation’s right to explanation (Article 22) is challenging to apply to complex AI models, especially in real-time AAS applications like autonomous vehicles or financial trading systems.</p>
        <p><bold>2) NIST Cybersecurity Framework</bold></p>
        <p>Strengths: The NIST framework provides a flexible, risk-based approach to cybersecurity, emphasizing continuous monitoring, incident response, and access control. It aligns well with Zero Trust principles.Limitations for AAS and ZT:The framework does not explicitly address the integration of autonomous systems or the ethical implications of AI-driven decision-making.It lacks detailed guidance on implementing least privilege access for AAS, which often requires broad access to data and systems.</p>
        <p><bold>3) EU Ethics Guidelines for Trustworthy AI</bold></p>
        <p>Strengths: These guidelines emphasize fairness, transparency, and human oversight, which are critical for the ethical deployment of AAS.Limitations for AAS and ZT:The guidelines are non-binding and lack specific technical or regulatory requirements for implementation.They do not address integrating AI ethics with Zero Trust cybersecurity frameworks, leaving a gap in balancing ethical considerations with security requirements [<xref ref-type="bibr" rid="B47">47</xref>] (<bold>Table 3</bold>).</p>
        <p>Table 3. Comparison of Google and Microsoft’s AI-driven zero trust approaches.</p>
        <table-wrap id="tbl3">
          <label>Table 3</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Framework</bold>
                </td>
                <td>
                  <bold>Strengths</bold>
                </td>
                <td>
                  <bold>Limitations for AAS and ZT</bold>
                </td>
                <td>
                  <bold>Proposed Innovations</bold>
                </td>
              </tr>
              <tr>
                <td>
                  <bold>GDPR</bold>
                </td>
                <td>Emphasizes transparency, accountability, and user consent.</td>
                <td>Focuses on human data subjects; difficult to apply to autonomous systems.</td>
                <td>AAS-specific accountability frameworks; dynamic access control policies.</td>
              </tr>
              <tr>
                <td>
                  <bold>NIST</bold>
                  <bold>Cybersecurity</bold>
                </td>
                <td>Flexible, risk-based approach; aligns with Zero Trust principles.</td>
                <td>Lacks guidance on integrating AAS and addressing ethical implications of AI.</td>
                <td>Explainable AI mandates; ethical impact assessments.</td>
              </tr>
              <tr>
                <td>
                  <bold>EU Ethics Guidelines</bold>
                </td>
                <td>Emphasizes fairness, transparency, and human oversight.</td>
                <td>Non-binding; lacks technical or regulatory requirements for implementation.</td>
                <td>Cross-border regulatory harmonization; mandatory EIAs for AAS.</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>7.1.2. Policy Recommendations</p>
        <p>1) Develop AAS-Specific Regulations: Governments and industry bodies should develop regulations specifically tailored to the unique challenges of AAS, including accountability, transparency, and dynamic access control.</p>
        <p>2) Mandate Explainable AI: Regulatory frameworks should require explainable AI techniques in AAS to ensure transparency and accountability.</p>
        <p>3) Conduct Ethical Impact Assessments: Organizations deploying AAS should be required to conduct EIAs to evaluate their systems’ ethical, privacy, and societal implications.</p>
        <p>4) Harmonize International Standards: International organizations should facilitate the development of harmonized regulatory standards for AAS and ZT to address global cybersecurity threats [<xref ref-type="bibr" rid="B19">19</xref>].</p>
      </sec>
      <sec id="sec7dot2">
        <title>7.2. Best Practices for Ethical AI Governance</title>
        <p>Adopting best practices for ethical AI governance is essential to mitigate risks associated with AAS and ensure their responsible deployment within Zero Trust frameworks. These practices should focus on bias detection, continuous monitoring, and transparency.</p>
        <p>Bias Detection Mechanisms: Implementing bias detection and mitigation techniques is critical to ensuring fairness in AAS. Tools such as fairness-aware machine learning and adversarial debiasing can help identify and address biases in training data and algorithms [<xref ref-type="bibr" rid="B24">24</xref>] (<xref ref-type="fig" rid="fig2">Figure 2</xref>).</p>
        <fig id="fig2">
          <label>Figure 2</label>
          <graphic xlink:href="https://html.scirp.org/file/1733094-rId16.jpeg?20260214115330" />
        </fig>
        <p>Figure 2. AI fairness studies and findings.</p>
        <p>Continuous Monitoring and Auditing: AAS should be subject to constant monitoring and auditing to ensure compliance with ethical and cybersecurity standards. This includes tracking system behavior, identifying anomalies, and addressing potential risks in real-time [<xref ref-type="bibr" rid="B28">28</xref>].AI Transparency: Promoting transparency in AAS through open-source standards and explainable AI (XAI) techniques can enhance trust and accountability. For example, organizations can publish model architectures, training data, and decision-making criteria to ensure transparency [<xref ref-type="bibr" rid="B20">20</xref>].Stakeholder Engagement: Engaging stakeholders, including users, regulators, and affected communities, in the development and deployment of AAS ensures that diverse perspectives are considered. This can help identify potential ethical risks and build public trust [<xref ref-type="bibr" rid="B17">17</xref>].</p>
        <p>Best Practices</p>
        <p>Ethical Impact Assessments: Conduct ethical impact assessments (EIAs) to evaluate AAS’s potential risks and benefits before deployment.Human-in-the-Loop Systems: Incorporate human oversight mechanisms to ensure that critical decisions made by AAS are reviewed by humans [<xref ref-type="bibr" rid="B21">21</xref>].</p>
      </sec>
      <sec id="sec7dot3">
        <title>7.3. Future Research Needs</title>
        <p>As AAS and Zero Trust frameworks evolve, further research is needed to address emerging challenges and advance the state of the art in AI ethics and cybersecurity.</p>
        <p>Integrating AI Ethics with Cybersecurity Frameworks: Research is needed to develop integrated frameworks that combine AI ethics principles with zero-trust cybersecurity practices. This includes exploring how ethical considerations, such as fairness and accountability, can be embedded into ZT architectures [<xref ref-type="bibr" rid="B19">19</xref>].Unbiased Machine Learning Models: Developing unbiased machine learning models is critical to ensuring fairness in AAS. This includes researching techniques for bias detection and mitigation and creating diverse and representative training datasets [<xref ref-type="bibr" rid="B24">24</xref>].Enhancing Zero Trust Automation: Automating Zero Trust processes, such as continuous authentication and access control, can improve efficiency and scalability. Research is needed to develop AI-driven tools that enhance ZT automation while maintaining security and compliance [<xref ref-type="bibr" rid="B35">35</xref>].Privacy-Preserving Technologies: Advancements in privacy-preserving technologies, such as federated learning and homomorphic encryption, can enhance data protection in AAS. These technologies enable secure data sharing and analysis without compromising privacy [<xref ref-type="bibr" rid="B48">48</xref>].Ethical and Legal Implications of AAS: Further research is needed to explore the ethical and legal implications of AAS, particularly in high-stakes applications such as healthcare and defense. This includes addressing questions of liability, accountability, and the societal impact of autonomous systems [<xref ref-type="bibr" rid="B18">18</xref>] (<xref ref-type="fig" rid="fig3">Figure 3</xref>).</p>
        <fig id="fig3">
          <label>Figure 3</label>
          <graphic xlink:href="https://html.scirp.org/file/1733094-rId17.jpeg?20260214115330" />
        </fig>
        <p>Figure 3. Performance and ethical impact metrics for AAS.</p>
      </sec>
      <sec id="sec7dot4">
        <title>7.4. Research Priorities</title>
        <p>Interdisciplinary Collaboration: Foster collaboration between AI researchers, cybersecurity experts, ethicists, and policymakers to address complex challenges at the intersection of AI and cybersecurity.Long-Term Impact Studies: Conduct longitudinal studies to assess the long-term impact of AAS on society, including their effects on employment, privacy, and human rights.</p>
      </sec>
    </sec>
    <sec id="sec8">
      <title>8. Conclusion</title>
      <p>Integrating autonomous agentic systems (AAS) into Zero Trust (ZT) frameworks represents a transformative shift in cybersecurity and operational efficiency across critical sectors such as healthcare, finance, defense, and infrastructure. However, this convergence also introduces significant ethical and security challenges that must be addressed to ensure the responsible deployment of these technologies. Throughout this article, we have explored the moral considerations, technical complexities, and governance frameworks necessary to navigate the intersection of AAS and Zero Trust. To ensure ethical deployment, organizations must; Implement explainable AI (XAI) to improve trust and transparency in decision-making. Adopt bias-mitigation strategies and diverse training datasets to ensure fairness. Establish clear accountability frameworks, including audit trails and human oversight. Balance data security with privacy protection using compliance-driven approaches like Privacy-Preserving Machine Learning (PPML). Industry leaders like Google and Microsoft have successfully deployed AI-driven Zero Trust models, demonstrating the potential of AI-powered adaptive security while maintaining ethical compliance. Moving forward, policymakers, AI developers, and cybersecurity experts must collaborate to establish regulatory standards that align innovation with ethical responsibility. Organizations can leverage AAS within Zero Trust frameworks to create a more secure, transparent, and ethically responsible digital future by proactively addressing AI fairness, accountability, and governance.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="B1">
        <label>1.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Russell, S. and Norvig, P. (2020) Artificial Intelligence: A Modern Approach. 4th Edition, Pearson.</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Russell, S.</string-name>
              <string-name>Norvig, P.</string-name>
              <string-name>Edition, P</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Artificial Intelligence: A Modern Approach</article-title>
            <source>4th Edition</source>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B2">
        <label>2.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Goodfellow, I., Bengio, Y. and Courville, A. (2016) Deep Learning. MIT Press.</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Goodfellow, I.</string-name>
              <string-name>Bengio, Y.</string-name>
              <string-name>Courville, A.</string-name>
            </person-group>
            <year>2016</year>
            <article-title>Deep Learning</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B3">
        <label>3.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Wooldridge, M. (2009) An Introduction to Multi-Agent Systems. 2nd Edition, Wiley.</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Wooldridge, M.</string-name>
              <string-name>Edition, W</string-name>
            </person-group>
            <year>2009</year>
            <article-title>An Introduction to Multi-Agent Systems</article-title>
            <source>2nd Edition</source>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B4">
        <label>4.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Sharkey, N. (1920) Staying in the Loop: Human Supervisory Control of Weapons. In: <italic>Autonomous Weapons Systems</italic>: <italic>Law</italic>, <italic>Ethics</italic>, <italic>Policy</italic>, Cambridge University Press, 23-38. https://doi.org/10.1017/cbo9781316597873.002 <pub-id pub-id-type="doi">10.1017/cbo9781316597873.002</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1017/cbo9781316597873.002">https://doi.org/10.1017/cbo9781316597873.002</ext-link></mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Sharkey, N.</string-name>
              <string-name>Law, E</string-name>
              <string-name>Policy, C</string-name>
            </person-group>
            <year>1920</year>
            <article-title>Staying in the Loop: Human Supervisory Control of Weapons</article-title>
            <source>In: Autonomous Weapons Systems: Law</source>
            <volume>23</volume>
            <pub-id pub-id-type="doi">10.1017/cbo9781316597873.002</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B5">
        <label>5.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Brynjolfsson, E. and McAfee, A. (2014) The Second Machine Age: Work, Progress, and Prosperity in a Time of Brilliant Technologies. W.W. Norton &amp; Company.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Brynjolfsson, E.</string-name>
              <string-name>McAfee, A.</string-name>
              <string-name>Work, P</string-name>
            </person-group>
            <year>2014</year>
            <article-title>The Second Machine Age: Work, Progress, and Prosperity in a Time of Brilliant Technologies</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B6">
        <label>6.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">McKinney, S.M., Sieniek, M., Godbole, V., Godwin, J., Antropova, N., Ashrafian, H., <italic>et al</italic>. (2020) International Evaluation of an AI System for Breast Cancer Screening. <italic>Nature</italic>, 577, 89-94. https://doi.org/10.1038/s41586-019-1799-6 <pub-id pub-id-type="doi">10.1038/s41586-019-1799-6</pub-id><pub-id pub-id-type="pmid">31894144</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1038/s41586-019-1799-6">https://doi.org/10.1038/s41586-019-1799-6</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>McKinney, S.M.</string-name>
              <string-name>Sieniek, M.</string-name>
              <string-name>Godbole, V.</string-name>
              <string-name>Godwin, J.</string-name>
              <string-name>Antropova, N.</string-name>
              <string-name>Ashrafian, H.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>International Evaluation of an AI System for Breast Cancer Screening</article-title>
            <source>Nature</source>
            <volume>577</volume>
            <pub-id pub-id-type="doi">10.1038/s41586-019-1799-6</pub-id>
            <pub-id pub-id-type="pmid">31894144</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B7">
        <label>7.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Lanfranco, A.R., Castellanos, A.E., Desai, J.P. and Meyers, W.C. (2004) Robotic Surgery: A Current Perspective. <italic>Annals of Surgery</italic>, 239, 14-21. https://doi.org/10.1097/01.sla.0000103020.19595.7d <pub-id pub-id-type="doi">10.1097/01.sla.0000103020.19595.7d</pub-id><pub-id pub-id-type="pmid">14685095</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1097/01.sla.0000103020.19595.7d">https://doi.org/10.1097/01.sla.0000103020.19595.7d</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Lanfranco, A.R.</string-name>
              <string-name>Castellanos, A.E.</string-name>
              <string-name>Desai, J.P.</string-name>
              <string-name>Meyers, W.C.</string-name>
            </person-group>
            <year>2004</year>
            <article-title>Robotic Surgery: A Current Perspective</article-title>
            <source>Annals of Surgery</source>
            <volume>239</volume>
            <pub-id pub-id-type="doi">10.1097/01.sla.0000103020.19595.7d</pub-id>
            <pub-id pub-id-type="pmid">14685095</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B8">
        <label>8.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Topol, E.J. (2019) Deep Medicine: How Artificial Intelligence Can Make Healthcare Human Again. Basic Books.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Topol, E.J.</string-name>
            </person-group>
            <year>2019</year>
            <article-title>Deep Medicine: How Artificial Intelligence Can Make Healthcare Human Again</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B9">
        <label>9.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Sarker, I.H., Kayes, A.S.M. and Watters, P. (2019) Effectiveness Analysis of Machine Learning Classification Models for Predicting Personalized Context-Aware Smartphone Usage. <italic>Journal of Big Data</italic>, 6, Article No. 57. https://doi.org/10.1186/s40537-019-0219-y <pub-id pub-id-type="doi">10.1186/s40537-019-0219-y</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1186/s40537-019-0219-y">https://doi.org/10.1186/s40537-019-0219-y</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Sarker, I.H.</string-name>
              <string-name>Kayes, A.S.M.</string-name>
              <string-name>Watters, P.</string-name>
            </person-group>
            <year>2019</year>
            <article-title>Effectiveness Analysis of Machine Learning Classification Models for Predicting Personalized Context-Aware Smartphone Usage</article-title>
            <source>Journal of Big Data</source>
            <volume>6</volume>
            <elocation-id>No</elocation-id>
            <pub-id pub-id-type="doi">10.1186/s40537-019-0219-y</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B10">
        <label>10.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Kott, A., Ludwig, J. and Lange, M. (2019) Autonomous Cyber Defense: A Review and a Roadmap. <italic>IEEE Security &amp; Privacy</italic>, 17, 76-85.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Kott, A.</string-name>
              <string-name>Ludwig, J.</string-name>
              <string-name>Lange, M.</string-name>
            </person-group>
            <year>2019</year>
            <article-title>Autonomous Cyber Defense: A Review and a Roadmap</article-title>
            <source>IEEE Security &amp; Privacy</source>
            <volume>17</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B11">
        <label>11.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Buczak, A.L. and Guven, E. (2016) A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection. <italic>IEEE Communications Surveys &amp; Tutorials</italic>, 18, 1153-1176. https://doi.org/10.1109/comst.2015.2494502 <pub-id pub-id-type="doi">10.1109/comst.2015.2494502</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/comst.2015.2494502">https://doi.org/10.1109/comst.2015.2494502</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Buczak, A.L.</string-name>
              <string-name>Guven, E.</string-name>
            </person-group>
            <year>2016</year>
            <article-title>A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection</article-title>
            <source>IEEE Communications Surveys &amp; Tutorials</source>
            <volume>18</volume>
            <pub-id pub-id-type="doi">10.1109/comst.2015.2494502</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B12">
        <label>12.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Dal Pozzolo, A., Caelen, O., Le Borgne, Y., Waterschoot, S. and Bontempi, G. (2014) Learned Lessons in Credit Card Fraud Detection from a Practitioner Perspective. <italic>Ex</italic><italic>pert Systems with Applications</italic>, 41, 4915-4928. https://doi.org/10.1016/j.eswa.2014.02.026 <pub-id pub-id-type="doi">10.1016/j.eswa.2014.02.026</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.eswa.2014.02.026">https://doi.org/10.1016/j.eswa.2014.02.026</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Pozzolo, A.</string-name>
              <string-name>Caelen, O.</string-name>
              <string-name>Borgne, Y.</string-name>
              <string-name>Waterschoot, S.</string-name>
              <string-name>Bontempi, G.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>Learned Lessons in Credit Card Fraud Detection from a Practitioner Perspective</article-title>
            <source>Expert Systems with Applications</source>
            <volume>41</volume>
            <pub-id pub-id-type="doi">10.1016/j.eswa.2014.02.026</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B13">
        <label>13.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Treleaven, P., Galas, M. and Lalchand, V. (2013) Algorithmic Trading Review. <italic>Communications of the ACM</italic>, 56, 76-85. https://doi.org/10.1145/2500117 <pub-id pub-id-type="doi">10.1145/2500117</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/2500117">https://doi.org/10.1145/2500117</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Treleaven, P.</string-name>
              <string-name>Galas, M.</string-name>
              <string-name>Lalchand, V.</string-name>
            </person-group>
            <year>2013</year>
            <article-title>Algorithmic Trading Review</article-title>
            <source>Communications of the ACM</source>
            <volume>56</volume>
            <pub-id pub-id-type="doi">10.1145/2500117</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B14">
        <label>14.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Kou, G., Lu, Y., Peng, Y. and Shi, Y. (2014) Evaluation of Classification Algorithms Using MCDM and Rank Correlation. <italic>International Journal of Information Technology &amp; Decision Making</italic>, 13, 407-425. https://arxiv.org/pdf/2304.12408</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Kou, G.</string-name>
              <string-name>Lu, Y.</string-name>
              <string-name>Peng, Y.</string-name>
              <string-name>Shi, Y.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>Evaluation of Classification Algorithms Using MCDM and Rank Correlation</article-title>
            <source>International Journal of Information Technology &amp; Decision Making</source>
            <volume>13</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B15">
        <label>15.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Arkin, R.C. (2009) Governing Lethal Behavior in Autonomous Robots. CRC Press.</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Arkin, R.C.</string-name>
            </person-group>
            <year>2009</year>
            <article-title>Governing Lethal Behavior in Autonomous Robots</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B16">
        <label>16.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Cummings, M.L. (2017) Artificial Intelligence and the Future of Warfare. <italic>International Security</italic>, 41, 7-38.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Cummings, M.L.</string-name>
            </person-group>
            <year>2017</year>
            <article-title>Artificial Intelligence and the Future of Warfare</article-title>
            <source>International Security</source>
            <volume>41</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B17">
        <label>17.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., <italic>et al</italic>. (2018) Ai4people—An Ethical Framework for a Good AI Society: Opportunities, Risks, Principles, and Recommendations. <italic>Minds and Machines</italic>, 28, 689-707. https://doi.org/10.1007/s11023-018-9482-5 <pub-id pub-id-type="doi">10.1007/s11023-018-9482-5</pub-id><pub-id pub-id-type="pmid">30930541</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s11023-018-9482-5">https://doi.org/10.1007/s11023-018-9482-5</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Floridi, L.</string-name>
              <string-name>Cowls, J.</string-name>
              <string-name>Beltrametti, M.</string-name>
              <string-name>Chatila, R.</string-name>
              <string-name>Chazerand, P.</string-name>
              <string-name>Dignum, V.</string-name>
              <string-name>Opportunities, R</string-name>
            </person-group>
            <year>2018</year>
            <article-title>Ai4people—An Ethical Framework for a Good AI Society: Opportunities, Risks, Principles, and Recommendations</article-title>
            <source>Minds and Machines</source>
            <volume>28</volume>
            <pub-id pub-id-type="doi">10.1007/s11023-018-9482-5</pub-id>
            <pub-id pub-id-type="pmid">30930541</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B18">
        <label>18.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Sparrow, R. (2016) Robots and Respect: Assessing the Case against Autonomous Weapon Systems. <italic>Ethics &amp; International Affairs</italic>, 30, 93-116. https://doi.org/10.1017/s0892679415000647 <pub-id pub-id-type="doi">10.1017/s0892679415000647</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1017/s0892679415000647">https://doi.org/10.1017/s0892679415000647</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Sparrow, R.</string-name>
            </person-group>
            <year>2016</year>
            <article-title>Robots and Respect: Assessing the Case against Autonomous Weapon Systems</article-title>
            <source>Ethics &amp; International Affairs</source>
            <volume>30</volume>
            <pub-id pub-id-type="doi">10.1017/s0892679415000647</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B19">
        <label>19.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Cath, C. (2018) Governing Artificial Intelligence: Ethical, Legal and Technical Opportunities and Challenges. <italic>Philosophical Transactions of the Royal Society A</italic>: <italic>Mathematical</italic>, <italic>Physical and Engineering Sciences</italic>, 376, Article ID: 20180080. https://doi.org/10.1098/rsta.2018.0080 <pub-id pub-id-type="doi">10.1098/rsta.2018.0080</pub-id><pub-id pub-id-type="pmid">30322996</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1098/rsta.2018.0080">https://doi.org/10.1098/rsta.2018.0080</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Cath, C.</string-name>
              <string-name>Ethical, L</string-name>
              <string-name>Mathematical, P</string-name>
            </person-group>
            <year>2018</year>
            <article-title>Governing Artificial Intelligence: Ethical, Legal and Technical Opportunities and Challenges</article-title>
            <source>Philosophical Transactions of the Royal Society A: Mathematical</source>
            <volume>376</volume>
            <fpage>201800</fpage>
            <elocation-id>ID</elocation-id>
            <pub-id pub-id-type="doi">10.1098/rsta.2018.0080</pub-id>
            <pub-id pub-id-type="pmid">30322996</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B20">
        <label>20.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Gunning, D., Stefik, M., Choi, J., Miller, T., Stumpf, S. and Yang, G. (2019) XAI—Explainable Artificial Intelligence. <italic>Science Robotics</italic>, 4, eaay7120. https://doi.org/10.1126/scirobotics.aay7120 <pub-id pub-id-type="doi">10.1126/scirobotics.aay7120</pub-id><pub-id pub-id-type="pmid">33137719</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1126/scirobotics.aay7120">https://doi.org/10.1126/scirobotics.aay7120</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Gunning, D.</string-name>
              <string-name>Stefik, M.</string-name>
              <string-name>Choi, J.</string-name>
              <string-name>Miller, T.</string-name>
              <string-name>Stumpf, S.</string-name>
              <string-name>Yang, G.</string-name>
            </person-group>
            <year>2019</year>
            <article-title>XAI—Explainable Artificial Intelligence</article-title>
            <source>Science Robotics</source>
            <volume>4</volume>
            <pub-id pub-id-type="doi">10.1126/scirobotics.aay7120</pub-id>
            <pub-id pub-id-type="pmid">33137719</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B21">
        <label>21.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Amodei, D., Olah, C., Steinhardt, J., Christiano, P., Schulman, J. and Mané, D. (2016) Concrete Problems in AI Safety.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Amodei, D.</string-name>
              <string-name>Olah, C.</string-name>
              <string-name>Steinhardt, J.</string-name>
              <string-name>Christiano, P.</string-name>
              <string-name>Schulman, J.</string-name>
            </person-group>
            <year>2016</year>
            <article-title>Concrete Problems in AI Safety</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B22">
        <label>22.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Buolamwini, J. and Gebru, T. (2018) Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification. <italic>Proceedings of the</italic>1 <italic>st Conference on Fairness</italic>, <italic>Accountability and Transparency</italic>, New York, 23-24 February 2018, 81-91.</mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Buolamwini, J.</string-name>
              <string-name>Gebru, T.</string-name>
              <string-name>Fairness, A</string-name>
              <string-name>Transparency, N</string-name>
            </person-group>
            <year>2018</year>
            <article-title>Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification</article-title>
            <source>Proceedings of the 1st Conference on Fairness</source>
            <volume>23</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B23">
        <label>23.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">O’Neil, C. (2016) Weapons of Math Destruction: How Big Data Increases Inequality and Threatens Democracy. Crown Publishing Group.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Neil, C.</string-name>
            </person-group>
            <year>2016</year>
            <article-title>Weapons of Math Destruction: How Big Data Increases Inequality and Threatens Democracy</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B24">
        <label>24.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Mehrabi, N., Morstatter, F., Saxena, N., Lerman, K. and Galstyan, A. (2021) A Survey on Bias and Fairness in Machine Learning. <italic>ACM Computing Surveys</italic>, 54, 1-35. https://doi.org/10.1145/3457607 <pub-id pub-id-type="doi">10.1145/3457607</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3457607">https://doi.org/10.1145/3457607</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Mehrabi, N.</string-name>
              <string-name>Morstatter, F.</string-name>
              <string-name>Saxena, N.</string-name>
              <string-name>Lerman, K.</string-name>
              <string-name>Galstyan, A.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>A Survey on Bias and Fairness in Machine Learning</article-title>
            <source>ACM Computing Surveys</source>
            <volume>54</volume>
            <pub-id pub-id-type="doi">10.1145/3457607</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B25">
        <label>25.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Raghavan, M., Barocas, S., Kleinberg, J. and Levy, K. (2020) Mitigating Bias in Algorithmic Hiring: Evaluating Claims and Practices. <italic>Proceedings of the</italic>2020 <italic>Conference on Fairness</italic>, <italic>Accountability</italic>, <italic>and Transparency</italic>, Barcelona, 27-30 January 2020, 469-481. https://doi.org/10.1145/3351095.3372828 <pub-id pub-id-type="doi">10.1145/3351095.3372828</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3351095.3372828">https://doi.org/10.1145/3351095.3372828</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Raghavan, M.</string-name>
              <string-name>Barocas, S.</string-name>
              <string-name>Kleinberg, J.</string-name>
              <string-name>Levy, K.</string-name>
              <string-name>Fairness, A</string-name>
              <string-name>Transparency, B</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Mitigating Bias in Algorithmic Hiring: Evaluating Claims and Practices</article-title>
            <source>Proceedings of the 2020 Conference on Fairness</source>
            <volume>27</volume>
            <pub-id pub-id-type="doi">10.1145/3351095.3372828</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B26">
        <label>26.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Zemel, R., Wu, Y., Swersky, K., Pitassi, T. and Dwork, C. (2013) Learning Fair Representations. <italic>Proceedings of the</italic>30 <italic>th International Conference on Machine Learning</italic>, Atlanta, 16-21 June 2013, 325-333.</mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Zemel, R.</string-name>
              <string-name>Wu, Y.</string-name>
              <string-name>Swersky, K.</string-name>
              <string-name>Pitassi, T.</string-name>
              <string-name>Dwork, C.</string-name>
              <string-name>Learning, A</string-name>
            </person-group>
            <year>2013</year>
            <article-title>Learning Fair Representations</article-title>
            <source>Proceedings of the 30th International Conference on Machine Learning</source>
            <volume>16</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B27">
        <label>27.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Gebru, T., Morgenstern, J., Vecchione, B., Vaughan, J.W., Wallach, H., Daumé III, H. and Crawford, K. (2018) Datasheets for Datasets. <italic>Proceedings of the</italic>5 <italic>th Workshop on Fairness</italic>, <italic>Accountability</italic>, <italic>and Transparency in Machine Learning</italic>, New York, 23-24 February 2018, 17 p. https://www.microsoft.com/en-us/research/wp-content/uploads/2019/01/1803.09010.pdf</mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Gebru, T.</string-name>
              <string-name>Morgenstern, J.</string-name>
              <string-name>Vecchione, B.</string-name>
              <string-name>Vaughan, J.W.</string-name>
              <string-name>Wallach, H.</string-name>
              <string-name>III, H.</string-name>
              <string-name>Crawford, K.</string-name>
              <string-name>Fairness, A</string-name>
              <string-name>Learning, N</string-name>
            </person-group>
            <year>2018</year>
            <article-title>Datasheets for Datasets</article-title>
            <source>Proceedings of the 5th Workshop on Fairness</source>
            <volume>23</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B28">
        <label>28.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Raji, I.D., Smart, A., White, R.N., Mitchell, M., Gebru, T., Hutchinson, B., <italic>et al</italic>. (2020). Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing. <italic>Proceedings of the</italic>2020 <italic>Conference on Fairness</italic>, <italic>Accountability</italic>, <italic>and Transparency</italic>, Barcelona, 27-30 January 2020, 33-44. https://doi.org/10.1145/3351095.3372873 <pub-id pub-id-type="doi">10.1145/3351095.3372873</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3351095.3372873">https://doi.org/10.1145/3351095.3372873</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Raji, I.D.</string-name>
              <string-name>Smart, A.</string-name>
              <string-name>White, R.N.</string-name>
              <string-name>Mitchell, M.</string-name>
              <string-name>Gebru, T.</string-name>
              <string-name>Hutchinson, B.</string-name>
              <string-name>Fairness, A</string-name>
              <string-name>Transparency, B</string-name>
            </person-group>
            <year>2020</year>
            <pub-id pub-id-type="doi">10.1145/3351095.3372873</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B29">
        <label>29.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Zimmer, M. (2010) “But the Data Is Already Public”: On the Ethics of Research in Facebook. <italic>Ethics and Information Technology</italic>, 12, 313-325. https://doi.org/10.1007/s10676-010-9227-5 <pub-id pub-id-type="doi">10.1007/s10676-010-9227-5</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s10676-010-9227-5">https://doi.org/10.1007/s10676-010-9227-5</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Zimmer, M.</string-name>
            </person-group>
            <year>2010</year>
            <article-title>“But the Data Is Already Public”: On the Ethics of Research in Facebook</article-title>
            <source>Ethics and Information Technology</source>
            <volume>12</volume>
            <pub-id pub-id-type="doi">10.1007/s10676-010-9227-5</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B30">
        <label>30.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Voigt, P. and Von dem Bussche, A. (2017) The EU General Data Protection Regulation (GDPR): A Practical Guide. Springer.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Voigt, P.</string-name>
              <string-name>Bussche, A.</string-name>
            </person-group>
            <year>2017</year>
            <article-title>The EU General Data Protection Regulation (GDPR): A Practical Guide</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B31">
        <label>31.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Lyon, D. (2018) The Culture of Surveillance: Watching as a Way of Life. Polity Press.</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Lyon, D.</string-name>
            </person-group>
            <year>2018</year>
            <article-title>The Culture of Surveillance: Watching as a Way of Life</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B32">
        <label>32.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Cavoukian, A. (2012) Privacy by Design: The 7 Foundational Principles. Information and Privacy Commissioner of Ontario, Canada.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Cavoukian, A.</string-name>
              <string-name>Ontario, C</string-name>
            </person-group>
            <year>2012</year>
            <article-title>Privacy by Design: The 7 Foundational Principles</article-title>
            <source>Information and Privacy Commissioner of Ontario</source>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B33">
        <label>33.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Narayanan, A. and Shmatikov, V. (2010) Myths and Fallacies of “Personally Identifiable Information”. <italic>Communications of the ACM</italic>, 53, 24-26. https://doi.org/10.1145/1743546.1743558 <pub-id pub-id-type="doi">10.1145/1743546.1743558</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/1743546.1743558">https://doi.org/10.1145/1743546.1743558</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Narayanan, A.</string-name>
              <string-name>Shmatikov, V.</string-name>
            </person-group>
            <year>2010</year>
            <article-title>Myths and Fallacies of “Personally Identifiable Information”</article-title>
            <source>Communications of the ACM</source>
            <volume>53</volume>
            <pub-id pub-id-type="doi">10.1145/1743546.1743558</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B34">
        <label>34.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Acquisti, A., Brandimarte, L. and Loewenstein, G. (2015) Privacy and Human Behavior in the Age of Information. <italic>Science</italic>, 347, 509-514. https://doi.org/10.1126/science.aaa1465 <pub-id pub-id-type="doi">10.1126/science.aaa1465</pub-id><pub-id pub-id-type="pmid">25635091</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1126/science.aaa1465">https://doi.org/10.1126/science.aaa1465</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Acquisti, A.</string-name>
              <string-name>Brandimarte, L.</string-name>
              <string-name>Loewenstein, G.</string-name>
            </person-group>
            <year>2015</year>
            <article-title>Privacy and Human Behavior in the Age of Information</article-title>
            <source>Science</source>
            <volume>347</volume>
            <pub-id pub-id-type="doi">10.1126/science.aaa1465</pub-id>
            <pub-id pub-id-type="pmid">25635091</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B35">
        <label>35.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Rose, S., Borchert, O., Mitchell, S. and Connelly, S. (2020) Zero Trust Architecture. NIST Special Publication 800-207.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Rose, S.</string-name>
              <string-name>Borchert, O.</string-name>
              <string-name>Mitchell, S.</string-name>
              <string-name>Connelly, S.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Zero Trust Architecture</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B36">
        <label>36.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">NIST (2020) Zero Trust Architecture. National Institute of Standards and Technology Special Publication 800-207. https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf</mixed-citation>
          <element-citation publication-type="web">
            <year>2020</year>
            <article-title>Zero Trust Architecture</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B37">
        <label>37.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Cunningham, C. (2018) The Zero Trust eXtended Ecosystem. Forrester Research.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Cunningham, C.</string-name>
            </person-group>
            <year>2018</year>
            <article-title>The Zero Trust eXtended Ecosystem</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B38">
        <label>38.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">TechDemocracy (2024) Zero Trust Framework|Zero Trust Principles|TechDemocracy Blog. TechDemocracy—Leader in Identity Security Solutions—IAM. https://www.techdemocracy.com/resources/zero-trust-framework-79</mixed-citation>
          <element-citation publication-type="web">
            <year>2024</year>
            <article-title>Zero Trust Framework|Zero Trust Principles|TechDemocracy Blog</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B39">
        <label>39.</label>
        <citation-alternatives>
          <mixed-citation publication-type="report">Kindervag, J. (2010) No More Chewy Centers: Introducing the Zero Trust Model of Information Security. Forrester Research. https://www.forrester.com/report/No-More-Chewy-Centers-The-Zero-Trust-Model-Of-Information-Security/RES56682</mixed-citation>
          <element-citation publication-type="report">
            <person-group person-group-type="author">
              <string-name>Kindervag, J.</string-name>
            </person-group>
            <year>2010</year>
            <article-title>No More Chewy Centers: Introducing the Zero Trust Model of Information Security</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B40">
        <label>40.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Ward, R. and Beye, B. (2014) BeyondCorp: A New Approach to Enterprise Security. Google Cloud.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Ward, R.</string-name>
              <string-name>Beye, B.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>BeyondCorp: A New Approach to Enterprise Security</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B41">
        <label>41.</label>
        <mixed-citation publication-type="web">Microsoft (n.d.) Zero Trust Guidance Center. Microsoft Learn: Build Skills That Open Doors in Your Career. https://learn.microsoft.com/en-us/security/zero-trust/</mixed-citation>
      </ref>
      <ref id="B42">
        <label>42.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Yli-Huumo, J., Ko, D., Choi, S., Park, S. and Smolander, K. (2016) Where Is Current Research on Blockchain Technology? A Systematic Review. <italic>PLOS ONE</italic>, 11, e0163477. https://doi.org/10.1371/journal.pone.0163477 <pub-id pub-id-type="doi">10.1371/journal.pone.0163477</pub-id><pub-id pub-id-type="pmid">27695049</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1371/journal.pone.0163477">https://doi.org/10.1371/journal.pone.0163477</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Yli-Huumo, J.</string-name>
              <string-name>Ko, D.</string-name>
              <string-name>Choi, S.</string-name>
              <string-name>Park, S.</string-name>
              <string-name>Smolander, K.</string-name>
            </person-group>
            <year>2016</year>
            <article-title>Where Is Current Research on Blockchain Technology? A Systematic Review</article-title>
            <source>PLOS ONE</source>
            <volume>11</volume>
            <pub-id pub-id-type="doi">10.1371/journal.pone.0163477</pub-id>
            <pub-id pub-id-type="pmid">27695049</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B43">
        <label>43.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">High-Level Expert Group on AI (2019) Ethics Guidelines for Trustworthy AI. European Commission. https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai</mixed-citation>
          <element-citation publication-type="web">
            <year>2019</year>
            <article-title>Ethics Guidelines for Trustworthy AI</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B44">
        <label>44.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Ribeiro, M.T., Singh, S. and Guestrin, C. (2016) “Why Should I Trust You?” Explaining the Predictions of Any Classifier. <italic>Proceedings of the</italic>22 <italic>nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining</italic>, San Francisco, 13-17 August 2016, 1135-1144. https://doi.org/10.1145/2939672.2939778 <pub-id pub-id-type="doi">10.1145/2939672.2939778</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/2939672.2939778">https://doi.org/10.1145/2939672.2939778</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Ribeiro, M.T.</string-name>
              <string-name>Singh, S.</string-name>
              <string-name>Guestrin, C.</string-name>
              <string-name>Mining, S</string-name>
            </person-group>
            <year>2016</year>
            <article-title>“Why Should I Trust You?” Explaining the Predictions of Any Classifier</article-title>
            <source>Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining</source>
            <volume>13</volume>
            <pub-id pub-id-type="doi">10.1145/2939672.2939778</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B45">
        <label>45.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Lipton, Z.C. (2018) The Mythos of Model Interpretability. <italic>Communications of the ACM</italic>, 61, 36-43. https://doi.org/10.1145/3233231 <pub-id pub-id-type="doi">10.1145/3233231</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3233231">https://doi.org/10.1145/3233231</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Lipton, Z.C.</string-name>
            </person-group>
            <year>2018</year>
            <article-title>The Mythos of Model Interpretability</article-title>
            <source>Communications of the ACM</source>
            <volume>61</volume>
            <pub-id pub-id-type="doi">10.1145/3233231</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B46">
        <label>46.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">ISO/IEC (2013) ISO/IEC 27001:2013 Information Security Management. International Organization for Standardization. https://www.iso.org/standard/88435.html</mixed-citation>
          <element-citation publication-type="journal">
            <year>2013</year>
            <article-title>ISO/IEC 27001:2013 Information Security Management</article-title>
            <fpage>2013</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B47">
        <label>47.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">European Commission (2021) Proposal for a Regulation on a European Approach for Artificial Intelligence. European Commission.</mixed-citation>
          <element-citation publication-type="other">
            <year>2021</year>
            <article-title>Proposal for a Regulation on a European Approach for Artificial Intelligence</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B48">
        <label>48.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Yang, Q., Liu, Y., Chen, T. and Tong, Y. (2019) Federated Machine Learning: Concept and Applications. <italic>ACM Transactions on Intelligent Systems and Technology</italic>, 10, 1-19. https://doi.org/10.1145/3298981 <pub-id pub-id-type="doi">10.1145/3298981</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3298981">https://doi.org/10.1145/3298981</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Yang, Q.</string-name>
              <string-name>Liu, Y.</string-name>
              <string-name>Chen, T.</string-name>
              <string-name>Tong, Y.</string-name>
            </person-group>
            <year>2019</year>
            <article-title>Federated Machine Learning: Concept and Applications</article-title>
            <source>ACM Transactions on Intelligent Systems and Technology</source>
            <volume>10</volume>
            <pub-id pub-id-type="doi">10.1145/3298981</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
    </ref-list>
  </back>
</article>