Related Big Read: Why agentic AI is exposing the limits of zero trust
Related assets: The permission-based attack surface; Control under compression
Legacy systems are ageing while attackers and AI agents are beginning to operate at machine speed. The priority is shifting from perfect trust to survivable trust.
The enterprise is being squeezed by time, and the pressure is coming from several directions.
Legacy systems cannot be modernised quickly enough. Windows 10 reaching end of support on 14 October 2025 was a key indicator, but the deeper problem is familiar: hardware constraints, procurement cycles, budget limits, operational dependency, and large estates that do not move cleanly because a support date has arrived.
On the other side is machine-speed capability. Bruce Schneier’s October 2025 analysis of autonomous AI hacking captured the shift in tempo. AI systems were being used to discover vulnerabilities, automate attack chains, and compress work that used to require skilled human time.
The problem is the mismatch.
Many organisations are still defending against slow systems and slow processes, while the attack economy accelerates.
Why legacy exposure is not just technical debt
Legacy risk is often described too politely.
It is treated as a backlog of updates, a compatibility issue, or a budget inconvenience. Those descriptions are not wrong, but they are not the full picture.
At scale, legacy exposure becomes a standing trust gap. Unsupported or hard-to-upgrade systems remain connected to real users, real data, real operations, and real suppliers. They may be too important to remove quickly and too fragile to trust comfortably.
That matters because predictable weakness attracts automated attacks.
If attackers can search, test, adapt, and exploit faster, then large pools of known legacy exposure become more valuable. The defender may still be negotiating maintenance windows while the attacker is already operating at compute speed.
Why trust in AI agents is accelerating the problem
The edition, Why agentic AI is exposing the limits of zero trust, carried a second signal: trust was moving away from human users and towards tokens, connected apps, service accounts, AI workflows, and delegated access.
That changes the meaning of authentication.
A valid login or token does not prove that the downstream action is safe. An OAuth grant can keep working after the original user interaction is forgotten. An AI workflow can inherit access without inheriting judgment.
The question is no longer only who gained access. It is what authority they now have and how far that authority can travel.
Why perfect remediation is the wrong first step
The natural instinct is to ask for complete remediation: patch everything, replace every unsupported system, rationalise every token, remove every stale integration.
That is right as an ambition.
It is wrong as a first step. Apply the 80/20 rule: address the exposures that create the greatest risk before trying to do everything all at once.
When the estate cannot be fixed quickly enough, leaders need a survivable trust model. That means reducing blast radius before the ideal end state is available. It means segmentation, isolation, shorter-lived credentials, tighter connected-app review, constrained AI authority, and pre-authorised containment paths.
This is not a lower standard.
It is an honest, pragmatic, risk-based approach.
Use this checklist where ageing infrastructure, non-human identity, and AI-enabled workflows overlap. Work through the five areas and record the evidence behind each answer.
High-level checklist: survivable trust
Legacy endpoint reality
Map the systems that cannot be modernised quickly enough and confirm how their exposure is being contained.
Non-human identity exposure
Map the tokens, connected applications, and service accounts that can preserve access after a human interaction has ended.
Machine-speed threat readiness
Plan for discovery and exploitation timelines that may outpace traditional patch and response cycles.
Sanctioned AI at scale
Make the control boundary explicit wherever enterprise AI increases access to sensitive systems or data.
Practical fallbacks
Keep a credible operating path available when legacy exposure cannot be removed immediately.
The executive move
Ask management to identify one place where legacy exposure and non-human authority overlap.
That may be an old endpoint estate, a high-value SaaS integration, an OAuth-heavy business process, a service-account pattern, or an AI workflow using inherited permissions.
Then ask for three proofs:
- How is it segmented?
- How is authority narrowed?
- How is access revoked if behaviour changes?
If those proofs are weak, the organisation is not facing a single issue. Instead it is sitting in the trust gap.