Home / Current Issue / Paper 1712964
AI-Driven Governance and Zero Trust Automation for Continuous Cloud Compliance and Secure Access
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity, AI and Governance
DOI: https://doi.org/10.64388/IREV6I9-1712964
Abstract
The expansion of cloud-native infrastructures, hybrid architectures, and distributed digital ecosystems has intensified the need for continuous security verification, rapid threat detection, and policy-driven governance. Conventional perimeter-based trust models have proven inadequate for protecting agile, API-driven, multi-cloud environments where identities, workloads, and data flows shift dynamically. Zero Trust Architecture (ZTA), as formalized by NIST (2020), has emerged as a strategic response to these challenges, emphasizing continuous authentication, least-privilege access, and context-aware policy enforcement. At the same time, advances in artificial intelligence (AI) have enabled more adaptive, predictive, and automated governance mechanisms that support cloud compliance and security decision-making at scale. In this paper, an integrated AI-Driven Governance and Zero Trust Automation (AIG-ZTA framework is designed to deliver continuous cloud compliance and secure access across hybrid and multi-cloud environments. The framework combines Zero Trust principles with machine learning?based behavioural analytics, automated policy orchestration, and dynamic risk scoring. Through architectural modeling, empirical evaluation, and multi-cloud simulation, the study demonstrates how AI-driven governance enhances identity assurance, reduces policy drift, and accelerates compliance verification. Results show that organizations adopting AIG-ZTA can achieve more resilient cloud security postures, improved real-time access decisions, and scalable, auditable compliance management. The paper concludes by highlighting future research directions, including autonomous ZTA systems, AI-driven compliance reasoning, and the fusion of generative models with continuous authorization pipelines.
Keywords
AI-Driven Governance, Automated Policy Orchestration, Multi-Cloud Security Architecture, Zero Trust Architecture
References
[1] Abdel-Basset, M., Hawash, H., Chakraborty, C., Ryan, M., & Elhoseny, M. (2020). Deep learning for cryptanalysis in IoT security: Challenges and opportunities. IEEE Internet of Things Journal, 7(9), 8800–8815.
[2] Chinni, R. (2023). Evaluating adaptive access policies for zero trust architectures in modern cybersecurity environments. 2023 International Conference on Computing Technologies. Data Communication (ICCTDC), 1–10. https://doi.org/10.1109/icctdc64446.2025.11158852
[3] Conti, M., Dehghantanha, A., Franke, K., & Watson, S. (2018). Internet of Things security and forensics: Challenges and opportunities. Future Generation Computer Systems, 78, 544–546.
[4] ENISA. (2020). Guidelines for Securing the Internet of Things. European Union Agency for Cybersecurity.
[5] European Union. (2016). General Data Protection Regulation (GDPR): Regulation (EU) 2016/679.
[6] Geyer, R. C., Klein, T., & Nabi, M. (2017). Differentially private federated learning: A client-level perspective. arXiv preprint arXiv:1712.07557.
[7] Hevner, A., & Chatterjee, S. (2010). Design Research in Information Systems: Theory and Practice. Springer.
[8] Hussain, F., Hussain, R., Hassan, S. A., & Hossain, E. (2020). Machine learning in IoT security: Current solutions and future challenges. IEEE Communications Surveys & Tutorials, 22(3), 1686–1721.
[9] Kairouz, P., McMahan, H. B., et al. (2021). Advances and open problems in federated learning. Foundations and Trends in Machine Learning, 14(1–2), 1–210.
[10] Li, T., Sahu, A. K., Talwalkar, A., & Smith, V. (2020). Federated learning: Challenges, methods, and future directions. IEEE Signal Processing Magazine, 37(3), 50–60.
[11] Mangla, M. (2023). AI-Driven zero trust architecture: A scalable framework for threat detection and adaptive access control. International Journal Science and Technology, 2(3), 117–124. https://doi.org/10.56127/ijst.v2i3.2274.
[12] Manne, T. A. K. (2025). Implementing zero trust architecture in multi-cloud environments. International Journal of Computing and Engineering, 7(3), 74–82. https://doi.org/10.47941/ijce.2753
[13] McMahan, H. B., Moore, E., Ramage, D., & Hampson, S. (2017). Communication-efficient learning of deep networks from decentralized data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS) (pp. 1273–1282).
[14] National Institute of Standards and Technology. (2020). NIST Special Publication 800-207: Zero Trust Architecture. U.S. Department of Commerce.
[15] Oladosu, S.A., Ige, A.B., Ike, C.C., Adepoju, P.A., Amoo, O.O., & Afolabi, A.I. (2022). Next-generation network security: Conceptualizing a Unified, AI-Powered Security Architecture for Cloud-Native and On-Premises Environments. International Journal of Science and Technology Research Archive, 3(2), 270–280. https://doi.org/10.53771/ijstra.2022.3.2.0143.
[16] Papernot, N., Abadi, M., Erlingsson, Ú., Goodfellow, I., & Talwar, K. (2017). Semi-supervised knowledge transfer for deep learning from private training data. In International Conference on Learning Representations (ICLR).
[17] Zhang, C., Xie, Y., Bai, H., Yu, B., Li, W., & Gao, Y. (2020). A survey on federated learning. ACM Computing Surveys, 54(1), 1–36.
How to cite this paper
@article{1712964,
author = {Nathaniel Adeniyi Akande, Olatunde Ayomide Olasehan, Jeremiah Folorunso Oluwagbotemi, Cynthia Udoka Duruemeruo, Sopuluchukwu Ani},
title = {AI-Driven Governance and Zero Trust Automation for Continuous Cloud Compliance and Secure Access},
journal = {Iconic Research And Engineering Journals},
year = {2023},
volume = {6},
number = {9},
pages = {545-559},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1712964.pdf},
abstract = {The expansion of cloud-native infrastructures, hybrid architectures, and distributed digital ecosystems has intensified the need for continuous security verification, rapid threat detection, and policy-driven governance. Conventional perimeter-based trust models have proven inadequate for protecting agile, API-driven, multi-cloud environments where identities, workloads, and data flows shift dynamically. Zero Trust Architecture (ZTA), as formalized by NIST (2020), has emerged as a strategic response to these challenges, emphasizing continuous authentication, least-privilege access, and context-aware policy enforcement. At the same time, advances in artificial intelligence (AI) have enabled more adaptive, predictive, and automated governance mechanisms that support cloud compliance and security decision-making at scale. In this paper, an integrated AI-Driven Governance and Zero Trust Automation (AIG-ZTA framework is designed to deliver continuous cloud compliance and secure access across hybrid and multi-cloud environments. The framework combines Zero Trust principles with machine learning?based behavioural analytics, automated policy orchestration, and dynamic risk scoring. Through architectural modeling, empirical evaluation, and multi-cloud simulation, the study demonstrates how AI-driven governance enhances identity assurance, reduces policy drift, and accelerates compliance verification. Results show that organizations adopting AIG-ZTA can achieve more resilient cloud security postures, improved real-time access decisions, and scalable, auditable compliance management. The paper concludes by highlighting future research directions, including autonomous ZTA systems, AI-driven compliance reasoning, and the fusion of generative models with continuous authorization pipelines.},
keywords = {AI-Driven Governance, Automated Policy Orchestration, Multi-Cloud Security Architecture, Zero Trust Architecture},
month = {March},
doi = {https://doi.org/10.64388/IREV6I9-1712964}
}