Zscaler Expert Warns AI Security Stacks Create Shared Blind Spots
Claude Mandy of Zscaler Inc. warns that AI-powered security layers often share training data, creating common cause failures that can defeat entire defense systems.
Claude Mandy, Chief Evangelist at Zscaler Inc., argues that the cybersecurity industry is misapplying the defense in depth framework to AI-powered security stacks. While traditional security relies on independent, deterministic controls to lower failure rates, Mandy asserts that AI controls often share training data. This overlap creates common cause failures and shared blind spots across the security architecture.
Mandy warns that when every layer of a security stack is AI-powered, a single adversarial payload can defeat the entire system because the attacker targets the model class rather than individual products. He notes that agentic architectures exacerbate this risk by creating echo chambers where misclassifications are inherited and reinforced across layers, which often removes human oversight.
To mitigate these risks, Mandy advises chief information security officers to treat AI controls as correlated systems. He recommends that organizations demand documented failure boundaries from vendors and explicitly map human intervention points to ensure oversight remains proactive rather than retrospective.