Zero trust is the security posture in which no network location, no identity, and no prior authentication is treated as inherently trustworthy — every access decision is made fresh, against current context, on the principle of least privilege, with continuous verification rather than perimeter assumption. This article maps the NIST 800-207 components onto AI-specific components: model endpoints, agent runtimes, tool gateways, retrieval indexes, fine-tuning jobs, and model artefacts. It walks through a threat model that names the realistic adversaries, presents a reference architecture diagram that names every enforcement point, and concludes with the operational disciplines (audit, behaviour analytics, key rotation, supply-chain attestation) that distinguish a zero-trust AI system from a conventional AI system with a few extra firewalls.