Adversaries, AI, and Zero Trust: Architecting the Future of Exposed-Surface Defense
Download resourcesAbout this session
Guillaume Ferland, a former Bell Canada chief architect now a solutions engineer at Cloudflare, argues attackers have gained a tenfold speed advantage: frontier model access and stolen API keys are now common underground currency, zero-day-to-exploitation windows have collapsed to hours, and attackers write their own tools as fast as any in-house developer. He walks through Cloudflare's internal transformation as a case study: about 95-98 percent of its code is now AI-assisted, developers write 'skills' that constrain what agents may do, and practices are codified in a machine-readable 'codex' (pure JSON, not prose) that CI pipelines enforce, flagging non-mandatory rules and blocking mandatory ones. He argues Zero Trust foundations only need extending for agents, not rebuilding: one access model per application, assume workarounds get found and abused, separate identity from the device an agent runs on, and treat AI gateways as ordinary inspection proxies. Recommendations include isolating AI use per user context, reducing exposed surface with reverse tunnels and authenticating proxies, and empowering internal AI champions rather than centralizing control. A Q&A covers per-agent OAuth identity and how the codex decides which actions need human approval.
As artificial intelligence rapidly reshapes the cybersecurity landscape, organizations face a double-edged threat matrix—ranging from enhanced adversarial capabilities and automated mass exploitation to the internal privacy and security risks of unsanctioned employee AI adoption. In this session, Cloudflare examines how security leaders can navigate these emerging vectors by architecting a forward-looking target state grounded in Zero Trust principles. Attendees will gain actionable insights into neutralizing AI-driven threats, establishing robust governance around model usage, and defining a secure, modern target state architecture that completely eliminates internet-exposed surfaces for critical assets.
Key takeaways
- Assume attackers already have full access to frontier AI models through stolen or fraudulent accounts; do not plan defenses on the premise that vendor guardrails keep capable models out of criminal hands.
- Codify internal engineering standards in a machine-readable format (JSON, not prose) so CI pipelines can automatically flag or block AI-generated code that violates them, rather than relying on tribal knowledge.
- Keep a single, well-documented access model per application and assume any undocumented workaround will eventually be discovered and exploited by an agent you do not control.
- Separate the identity an agent uses from the device or laptop it runs on; treat any agent activity on a personal employee laptop as a security incident rather than normal use.
- Reduce your internet-exposed surface with reverse tunnels and an authenticating reverse proxy in front of employee-facing applications, since exploitation cycles for exposed appliances have dropped from weeks to hours.
Speakers

Guillaume Ferland is an accomplished cybersecurity leader with over 20 years of experience, currently serving as a Solutions Engineer at Cloudflare, where he helps enterprises implement Zero Trust architectures and secure cloud applications. Prior… Read moreRead less
Guillaume Ferland is an accomplished cybersecurity leader with over 20 years of experience, currently serving as a Solutions Engineer at Cloudflare, where he helps enterprises implement Zero Trust architectures and secure cloud applications. Prior to Cloudflare, he spent over a decade at Bell Canada, most recently as a Distinguished Member of Technology, where he led security architecture for critical national infrastructure, including 5G and 911 services. His career is defined by a deep expertise across many fields in Cybersecurity, including application security and SSDLC, infrastructure and cloud security, IAM, as well as SOC. Guillaume is a recognized industry thought leader, frequently contributing to global forums like IEEE and engaging with the AI developer community. He effectively bridges the gap between complex technical security requirements and strategic business outcomes.

