Organisations should apply Zero Trust consistently across both legacy and modern systems. The principle should remain the same: never trust by default, always verify users, devices, applications, and access requests.
For legacy infrastructure, this may require stronger identity controls segmentation, and a gradual approach to modernising security controls. For AI-driven systems, organisations also need to consider who can access the systems, what data they can use, and how those systems are monitored.
The goal is not to replace everything at once, but to apply consistent security principles across the entire environment while adapting controls to the risks of each system.