ZscalerZero TrustAI

Zscaler Joined the Hiroshima AI Process. Yes, That Is a Real Thing, and It Actually Matters.

July 28, 2026 · Brian Deitch

Zscaler just joined the Hiroshima AI Process Partners Community.

I know. The name sounds like a documentary you fall asleep to at 11pm and wake up to at 2am convinced you understand geopolitics now. But stick with me, because there is a real story here, and it is not the one the acronym is selling.

Full disclosure before I get going: I work at Zscaler. So read the enthusiasm below as informed, not neutral.

What The Hiroshima AI Process Actually Is

The Hiroshima AI Process, or HAIP if you enjoy pretending every initiative needs a callsign, launched under Japan's 2023 G7 Presidency. The whole point is to move the international conversation on AI forward without it collapsing into either "AI will save us all" or "AI will end civilization by Thursday."

Its Partners Community pulls together organizations that want to do practical work on AI governance and responsible adoption. Zscaler joined the Friends Group Partners' Community, which is the part where you stop nodding along at conferences and actually contribute something.

And here is the part that got my attention. HAIP already has International Guiding Principles and a Code of Conduct for advanced AI systems. Those principles are not vibes. They cover risk assessment, security testing, transparency, incident response, and safeguards against misuse.

Read that list again. Risk assessment. Security testing. Incident response. Least privilege's cooler international cousins.

That is not an ethics panel. That is a security posture wearing a diplomat's suit.

Why A Security Company Belongs In This Room

Most companies show up to AI governance talks with a slide deck and a promise. Zscaler shows up with receipts.

The reason is simple. Every enterprise racing to deploy AI is also quietly signing up for a brand new attack surface. Agents reaching into data. Models making decisions. Employees pasting things into tools nobody in security has ever heard of. AI is not just a productivity story. It is a "who authorized the chatbot to touch the CRM" story.

Zscaler already lives in that mess. The company secures AI so organizations can actually use it, protects the AI initiatives they are building, and uses AI on the defensive side to catch the AI-powered attacks coming the other way. That real-world experience is exactly what a governance body needs, because principles written by people who have never watched an agent go sideways at machine speed tend to age like milk.

Transparency Is A Load-Bearing Wall

The line from the post that actually stuck with me:

"Trust in AI cannot rest on broad assurances alone. It depends on evidence, visibility, and candid reporting."

— Adam Dobell, Head of Government Affairs, APJ, Zscaler

That is the whole thing right there. Everybody says "trust us" about their AI. Almost nobody shows their work.

Zscaler's ThreatLabz team publishes an annual AI Security Report, and the 2026 edition found that AI adoption is opening critical security gaps across global enterprises. The company also put out frontier model research with the greatest security blog title of the year, "When the Scanner Starts Thinking: Learnings from Mythos and GPT 5.5 Cyber Security," which is a structured evaluation of how frontier models actually behave in cybersecurity work. Methodology, capability assessment, real recommendations. Not a hype reel.

On top of that, Zscaler is engaged in Anthropic's Project Glasswing and OpenAI's Trusted Access for Cyber program, which is where you go to actually stress test what these frontier models can and cannot do instead of guessing on a webinar.

And the internal governance piece matters just as much. Sam Curry, Zscaler's Global CISO, has been public about the commitment not to use proprietary customer data or personal information to train AI models, backed by a data containment architecture and anonymized, aggregated signals. In an industry where "we take your privacy seriously" usually means "we already trained on it," that is a real line in the sand.

The Zero Trust Throughline

If you have read anything I write, you know where this lands.

Governance frameworks and zero trust are chasing the same goal from opposite ends. HAIP says assess the risk, test the security, be transparent, respond to incidents, and guard against misuse. Zero trust says verify continuously, enforce least privilege, shrink the blast radius, and never assume one authentication is a lifetime backstage pass.

Same philosophy. One writes it as international principles. The other enforces it in traffic at runtime. AI just made both of them non-optional at the same time.

Bottom Line

A cybersecurity company joining an international AI governance body could easily have been a logo on a website and a paragraph nobody reads. This one is not, because the principles HAIP is built on are the same ones security teams already fight for every day: test it, watch it, contain it, and do not trust it blindly just because it sounds confident.

AI adoption is going to keep sprinting. It is good to see the people who secure it get a seat at the table where the rules are being written, instead of getting handed the rules after everything is already on fire.

Full post: Zscaler Joins the Hiroshima AI Process Partners Community

zscalerai-governancehiroshima-ai-processresponsible-aizero-trust
All postsDiscuss on LinkedIn