Go back

What's Already in the Room: Google's New "Beyond Zero" Framework

Google's Beyond Zero framework strengthens AI-era security, but Material Security's analysis reveals a critical gap: the sensitive data already accumulated in enterprise environments before any breach occurs.

Industry Insights
August 11, 2026
3m read
3m read
3m listen
3m watch
3m watch
What's Already in the Room: Google's New "Beyond Zero" FrameworkWhat's Already in the Room: Google's New "Beyond Zero" Framework
speakers
speakers
speakers
authors
Belem Regalado
Material Research Team
participants
No items found.
share

Google's Beyond Zero framework strengthens AI-era security, but Material Security's analysis reveals a critical gap: the sensitive data already accumulated in enterprise environments before any breach occurs.

Last month, Google published Going Beyond Zero, an evolution of the zero trust framework for the AI era. Instead of just verifying who is connecting, it authorizes every individual action taken by every user and every agent, at machine speed, with context enriched at the point of decision. It is the right architecture for a world where AI agents operate on behalf of users and attackers move faster than any human response can match.

We think Google is right. And we want to add something to the picture.

The part 'assume breach' tends to skip

In February, we wrote that the 'assume breach' mindset tends to stop at the point of authentication. Security teams apply rigorous skepticism to every login and session token. Then, once a user authenticates into Google Workspace, the posture quietly shifts from 'assume breach' to 'assume safety.' Files accumulate. Emails persist. OAuth tokens are granted. None of that gets the same scrutiny as the login itself.

Beyond Zero extends authorization deeper, to the action level, closing a real gap. But there is another dimension it cannot address on its own: the question of what is already there.

What we found before any breach occurred

We did a systematic analysis of a Google Workspace environment using Material Security's data export, covering Drive, email, and OAuth connections. Every number below comes from that environment, in its normal operating state, before any attacker arrived.

In Drive: more than 83,000 files containing sensitive data across five categories, passwords embedded in documents, financial reports, payroll data, Social Security numbers, and source code. These files were not created by attackers. They were created by employees doing their jobs. The content accumulated because work accumulates. Every month in the data window, users shared more files publicly than they restricted.

The most striking single finding: an OpenAI-connected integration had downloaded a compensation spreadsheet 632,730 times across 15 employee accounts. The download counts follow exact multiples, the signature of a synchronized polling loop. The integration was doing exactly what it was designed to do. Nobody told it not to.

More concerning were apps that could not be identified at all. One has been running since September 2025 and has read sensitive files 87 million times, accessing compensation data, bank account entries, and multi-year financial planning models. Every day.

The email environment told the same story. Finance team inboxes contained 45,550 emails with bank routing numbers, 18,824 invoices, and 4,702 SWIFT codes, not because of any breach, but because that is what finance teams receive. Alongside that: 1,875 emails flagged with Business Email Compromise indicators. Attackers have already found these accounts. The inboxes they are probing contain exactly what they need.

Two questions, not one

Beyond Zero answers: how do we control what agents and users can do going forward, fast enough to match machine-speed threats?

The second question is: what does an attacker actually inherit the day they get in?

These are not the same question. Authorization controls govern what can happen at the gate. Blast radius awareness tells you what is behind it. The industry has always been better at building gates than taking inventory. Beyond Zero advances the gate significantly. What our investigation shows is what the inventory looks like when nobody has taken it.

The data we found was not created by a breach. It was created by three years of normal enterprise operations. It was there before any attacker arrived, and it would still be there after any authorization framework was implemented. Beyond Zero will make future access decisions better. Knowing what is already in the environment is what makes those decisions meaningful. You cannot protect what you have not measured.

Frequently Asked Questions

Find answers to common questions and get the details you need.

No items found.

Related posts

Our blog is your destination for expert insights, practical tips, and the latest news in technology. Stay informed with our regular updates and in-depth articles. Join the conversation and enhance your understanding of the tech landscape.

blog post

What's Already in the Room: Google's New "Beyond Zero" Framework

Google's Beyond Zero framework strengthens AI-era security, but Material Security's analysis reveals a critical gap: the sensitive data already accumulated in enterprise environments before any breach occurs.

Belem Regalado
3
m read
Read post
Podcast

What's Already in the Room: Google's New "Beyond Zero" Framework

Google's Beyond Zero framework strengthens AI-era security, but Material Security's analysis reveals a critical gap: the sensitive data already accumulated in enterprise environments before any breach occurs.

3
m listen
Listen to episode
Video

What's Already in the Room: Google's New "Beyond Zero" Framework

Google's Beyond Zero framework strengthens AI-era security, but Material Security's analysis reveals a critical gap: the sensitive data already accumulated in enterprise environments before any breach occurs.

3
m watch
Watch video
Downloads

What's Already in the Room: Google's New "Beyond Zero" Framework

Google's Beyond Zero framework strengthens AI-era security, but Material Security's analysis reveals a critical gap: the sensitive data already accumulated in enterprise environments before any breach occurs.

3
m listen
Watch video
Webinar

What's Already in the Room: Google's New "Beyond Zero" Framework

Google's Beyond Zero framework strengthens AI-era security, but Material Security's analysis reveals a critical gap: the sensitive data already accumulated in enterprise environments before any breach occurs.

3
m listen
Listen episode
blog post

Map Sensitive File Sharing in Drive and Simplify Customization in Material

Discover Material's latest updates: visualize sensitive file sharing in Google Drive, search files with AI-powered prompts, and customize threat detection faster to strengthen your workspace security.

Kate Hutchinson
5
m read
Read post
Podcast

Map Sensitive File Sharing in Drive and Simplify Customization in Material

Discover Material's latest updates: visualize sensitive file sharing in Google Drive, search files with AI-powered prompts, and customize threat detection faster to strengthen your workspace security.

5
m listen
Listen to episode
Video

Map Sensitive File Sharing in Drive and Simplify Customization in Material

Discover Material's latest updates: visualize sensitive file sharing in Google Drive, search files with AI-powered prompts, and customize threat detection faster to strengthen your workspace security.

5
m watch
Watch video
Downloads

Map Sensitive File Sharing in Drive and Simplify Customization in Material

Discover Material's latest updates: visualize sensitive file sharing in Google Drive, search files with AI-powered prompts, and customize threat detection faster to strengthen your workspace security.

5
m listen
Watch video
Webinar

Map Sensitive File Sharing in Drive and Simplify Customization in Material

Discover Material's latest updates: visualize sensitive file sharing in Google Drive, search files with AI-powered prompts, and customize threat detection faster to strengthen your workspace security.

5
m listen
Listen episode
blog post

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

Melissa Leigh Gore
7
m read
Read post
Podcast

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

7
m listen
Listen to episode
Video

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

7
m watch
Watch video
Downloads

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

7
m listen
Watch video
Webinar

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

7
m listen
Listen episode
blog post

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

Material Research Team
5
m read
Read post
Podcast

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

5
m listen
Listen to episode
Video

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

5
m watch
Watch video
Downloads

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

5
m listen
Watch video
Webinar

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

5
m listen
Listen episode
Privacy Preference Center

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.

New