September 11, 2026
As organisations embrace agentic AI, security is rapidly becoming the defining challenge for businesses struggling to balance the pace of innovation with the urgency of protection.
That tension is becoming more pronounced across Asia Pacific and Japan (APJ), where organisations are rapidly moving beyond experimentation towards autonomous agents capable of accessing applications, interrogating data and acting across business processes.
For channel partners, that changes the nature of the AI opportunity.
Because the conversation is no longer simply about helping businesses deploy AI, rather creating the security, governance and trust required for organisations to deploy AI securely at scale.
“Most enterprise AI systems are being deployed much faster than they can be secured,” outlined Foâd Farrokhnia, Vice President of Partners and Alliances across APJ at Zscaler.
“That’s the bottom line at the moment.”
Farrokhnia addressed the market via Partner Playbook: Securing Agentic AI in APJ, which frames ecosystem growth across three critical pillars – Customer Priorities, Zscaler Value and Partner Opportunities.
Despite AI adoption accelerating across APJ, the security architecture sitting underneath remains built for a different era.
According to ThreatLabz 2026 AI Security Report by Zscaler, AI and ML activity increased 91% year-over-year across an ecosystem of more than 3,400 applications while 53% of business leaders are now deploying AI agents to effectively automate entire business processes.
Such rapid adoption has left many organisations with no clear map of the AI models interacting with their data or the supply chains behind them – scenarios already playing out in mature AI markets such as Australia, India and Japan.
Compounding this challenge, enterprise AI systems are now vulnerable at machine speed. Zscaler experts found most enterprise AI systems could be compromised in just 16 minutes, with critical flaws uncovered in 100% of systems analysed.
“The security models that we’ve had in the past really start to fail in the AI era,” Farrokhnia exposed.
“The firewalls, the VPNs that were built on implicit trust. If you’re inside the network, everything’s good, you’re trusted. When you’re outside, then that’s when we verify. Those things aren’t really going to be doing the job anymore.”
That becomes particularly problematic as organisations move from AI applications that respond to human prompts towards agents capable of independently interacting with applications, cloud environments and corporate data.
“When AI systems are being deployed, they’re being deployed at breakneck speed, and in that situation, assuming trust is probably the most dangerous thing you can do,” Farrokhnia cautioned.
As a consequence, Farrokhnia highlighted that customer priorities across APJ are consolidating around two immediate challenges.
“One is shadow AI and those ungoverned prompts,” he expanded. “Business units deploying unsanctioned models, browser extensions and MCP servers without any IT visibility.”
The second is what happens when autonomous AI begins operating at scale.
“When you think about agentic risk, but then at scale with a lot of speed, organisations are expecting to be managing hundreds, thousands, if not millions, of autonomous AI agents acting independently on business data without really any permission boundaries at the moment,” Farrokhnia continued.
The significance lies in what happens to the attack surface as AI scales.
An organisation moving from dozens of AI use cases towards potentially thousands or millions of autonomous agents is not simply increasing productivity capacity. It is multiplying the number of identities and interactions requiring oversight, while potentially giving those agents access to sensitive applications and business data.
That changes the trust equation.
“To earn enough trust to actually move fast, you have to trust nothing,” Farrokhnia added.
For Farrokhnia, however, that should not translate into security becoming another barrier between organisations and AI adoption. The objective is to secure transformation without constraining it.
“What we want to be is an enabler of the productivity gains that you want to see off the back of these investments in AI and agentic AI,” Farrokhnia continued. “That’s where Zscaler and partners can work together to deliver that as a value outcome for customers.”
The security challenge created by agentic AI is not detached from the business opportunity, however. The faster organisations attempt to extract value from AI, the faster the underlying security requirements develop alongside it.
“As AI accelerates business value, it accelerates the threat vectors at pretty much exactly, if not even faster speed,” Farrokhnia noted.
In response, Zscaler is positioning zero-trust as the architecture capable of reconciling those competing demands.
Built as a cloud-native zero-trust exchange, Zscaler processes more than 400 billion transactions daily – an architecture designed to create the visibility required to address the speed versus security paradox in the age of AI.
“We don’t block AI adoption, we enable it,” Farrokhnia said.
“That’s a great news story for partners because that’s what customers want to hear: how do I actually drive the productivity gains, the ROI on all of this investment?”
That position has underpinned a series of announcements including Zscaler AI Broker, Zscaler Endpoint AI Security and Zscaler AI Access Graph. As businesses adopt agentic workflows through MCP, AI Broker operates as an inline governor sitting between agents and the resources they attempt to access.
“It’s an agent registry, effectively ensuring that every agent only accesses the exact data authorised for its specific task,” Farrokhnia added.
Endpoint AI Security – a product of Zscaler’s recent acquisition of SquareX – extends zero-trust into the browser to address areas including malicious plugins, shadow AI and browser-based AI tools.
Powered by the acquisition of Symmetry Systems, AI Access Graph tackles another part of the problem – understanding the increasingly complex relationship between humans, AI and enterprise data.
“This provides that real-time mapping of relationship and data lineage between human identities, AI models, applications and even multi-cloud data stores,” Farrokhnia said.
For partners, the value is not only having another collection of security products to take to market. It is the ability to enter customer conversations with a broader architecture around how AI can be secured over time.
“For our APJ partners aligning with Zscaler means I can now walk into a client meeting with a lot of confidence around my ability to actually address not only their current requirements with regards to having a productive AI investment, but also start to roadmap how they can secure their business for the long-term,” Farrokhnia noted.
Project AI-Guardian pushes that concept beyond technology and into the ecosystem.
“It packages an AI practice that our partners can co-create, co-deliver and take to customers based on business outcomes,” Farrokhnia highlighted.
The model spans strategic AI advisory and architectural integration through to AI governance, managed services and non-human identity security. But there is another element Farrokhnia believes needs to change: collaboration.
As AI security continues to cut across data, cloud, identity, infrastructure, security and advisory capabilities, solving that through isolated partner motions becomes increasingly difficult.
“We do tend to shy away from that a little bit,” Farrokhnia acknowledged.
“That collaboration piece sometimes becomes very siloed, and this partner does X and this partner does Y, and we don’t talk to each other. I think right now we really need to drop those walls and really connect and collaborate.”
That ecosystem stretches across global and regional systems integrators, managed service providers (MSPs), technology consultants, hyperscalers and LLM providers. The opportunity, therefore, is not restricted to one type of partner.
For partners, that breadth creates opportunity but also another strategic decision.
The channel has already navigated shifts from hardware to cloud, transactions to services and perimeter security to zero-trust. Securing agentic AI introduces another transformation before many businesses have finished navigating the previous one.
“A lot of partners we speak to right now are going through an evolution,” Farrokhnia acknowledged.
“They may have been a bit more transactional. They may have been doing really well on legacy type solutions. Maybe they got through that and moved to working with us a little bit more on the transformation side, zero-trust transformation.
“Now they’re saying, ‘oh, now it’s another thing, AI. Now, how do I fit into this?’”
Farrokhnia’s answer is simple. This isn’t about chasing every aspect of the AI opportunity, instead understanding exactly where value is created.
“No matter what sort of route to market you take, no matter what partner capability or expertise you bring, be really clear on your point of view and what your specialty is going to be in this conversation,” Farrokhnia advised.
Farrokhnia identified four broad monetisation opportunities for partners: technology integration and AI governance, zero-trust transformation, managed services and the mid-market.
Technology integration and governance responds directly to an enterprise problem that predates AI but is becoming more difficult because of it – fragmented security environments.
“Customers are struggling with fragmented, disconnected security tools,” Farrokhnia said.
“Our partners add tremendous value by integrating user access, cloud data and non-human AI agents into a single cohesive governance model, so that the policies are applied consistently pretty much everywhere.”
Meanwhile, zero-trust transformation offers a different entry point.
Rather than treating AI security as a standalone technology purchase, Farrokhnia sees the AI investment cycle as an opportunity for partners to revisit legacy infrastructure already sitting inside customer environments.
“Partners that we see success with right now, they’re seeing this AI explosion as a means to accelerate firewall and VPN replacement,” he said.
“That’s creating a more secure architecture. It’s allowing for better productivity around investments in AI. It’s also helping with cost reduction and simplification.”
In the context of MSPs, the opportunity extends further into the lifecycle.
For Farrokhnia, potential exists to move beyond one-off transactions and simple allow-and-block controls towards practices incorporating advisory, access control, endpoint visibility, agent governance, red teaming and compliance reporting.
“Really turning that AI risk into a predictable, high-margin sort of managed service is another one,” he added.
But one of the largest addressable opportunities may sit below the enterprise.
“The mid-sized organisations, especially in APJ, face almost exactly the same AI risks and security risks as the big multinationals, but they actually lack the internal security teams to be able to really manage it,” Farrokhnia said.
“They don’t have the resources, and when something happens, a breach happens to a smaller business, it really, really hurts. Really hurts.”
That resource gap potentially creates a natural role for partners capable of turning complex security architecture into something consumable.
“Partners who can come to us and really build and deliver packages, turnkey zero-trust and AI security solutions to this market segment, they’re also seeing some really fantastic opportunity ahead,” Farrokhnia said.
Taken together, those opportunities point towards a broader repositioning of the partner role. Customers may buy AI technology, but making that technology operational, governed and secure requires considerably more than the technology itself.
For partners, that leaves room around the edges – and increasingly at the centre – of the AI investment.
“Pulling these four pillars together, I think our partners become essential transformation advisors,” Farrokhnia said.
“They’re helping clients adopt AI safely while also delivering strong revenue and doing something that’s very profitable for themselves as well.”
Agentic AI will continue to change. So will the threats, architectures and commercial models surrounding it.
Farrokhnia’s message to partners is therefore less about attempting to predict every turn in the market and more about being clear on the value they bring as it evolves.
“The partners that know what their value is and what they can bring in terms of the customer outcome, they figure it out,” he advised.
For an ecosystem accustomed to selling technology transformation, securing agentic AI may ultimately be less about finding an entirely new playbook. It may be about knowing exactly where you belong in it.
Inform your opinion with executive guidance, in-depth analysis and business commentary.