Agentic AI Risk for Security Leaders
Agent deployments combine autonomy, tool access, delegation and persistent state. Existing general AI frameworks remain relevant, and dedicated agent guidance is available. The practical task is to translate that guidance into accountable owners, enforceable policies and evidence for your deployment.
Governance & Risk · security-leaders The Numbers
These are vendor-sponsored survey findings, not a census of enterprises. Attribute the population and methodology when presenting them. The Fortinet result measures perceived board awareness, not a measured test of directors’ knowledge.
Eight Frameworks
What each covers for agents — and where each stops.
| Framework | Agent Coverage | Status |
|---|---|---|
| NIST AI 600-1 | Cross-cutting GenAI risks relevant to agents; not an agent-specific implementation guide | Published Jul 2024 |
| NIST CAISI Agent Standards | Agent standards and interoperability work; track identity and security-related workstreams separately | Initiative; consult dated outputs |
| Google SAIF 2.0 / CoSAI | Agent risk map added | Available |
| EU AI Act Article 15 | Requirements for high-risk systems; applicability depends on category and role | Phased: Annex III rules Dec 2, 2027; regulated-product high-risk rules Aug 2, 2028. See current Commission timeline. |
| ISO/IEC 42001 | AI management-system requirements applicable to agent deployments; not a technical test suite | Certifiable now |
| CSA AI Controls Matrix | 243 control objectives in AICM v1; identify the version used in your control mapping | Available + recent agent work |
| OpenAI Governance Practices | 7 practices purpose-built for agents | Governance practices; adapt to operational controls |
| Singapore MGF Agentic AI | Agent-focused governance organized around four dimensions | Published Jan 2026, voluntary |
Timeline checked September 18, 2026 against the European Commission enforcement overview. Article 15 concerns high-risk systems; classify the system and applicable role before selecting an obligation or deadline. For agent accountability, memory and MCP guidance, see IMDA sections 2.2 and 2.3.
Six Questions for Your Deployment
When Agent A delegates through Agent B to Tool C, preserve the authority and scope of the originating request. IMDA’s framework addresses human accountability and multi-agent responsibilities. Your implementation must assign owners and produce evidence of the authorization decision at each hop.
The Saviynt/Cybersecurity Insiders survey reports 71% of respondents saying AI tools access core systems and 16% reporting effective governance. Translate the relevant framework into identities, task scopes, tool onboarding, review and revocation. Check whether the implementation enforces those decisions. Survey source.
Memory poisoning is covered in agent-security guidance, including OWASP’s Agentic Top 10 and IMDA’s discussion of agent risks. Define who may write memory, how provenance is retained, what is shared across users and how malicious state is removed. Persistence depends on retrieval and execution behavior.
Compare observable behavior with task and permission expectations. Framework guidance on monitoring still needs a concrete implementation, thresholds, owners and an escalation procedure. Test benign changes and attacks before relying on the monitor.
IMDA discusses MCP-layer controls such as trusted-server selection and sandboxing. Use protocol security guidance to implement endpoint authentication, scoped authorization, trustworthy onboarding and data-flow restrictions. Test actual behavior rather than treating a framework mapping as evidence that a server is safe.
Agents need identifiable principals and scoped permissions. Existing IAM concepts remain useful; delegation, short-lived task authority and rapid autonomous action add operational requirements. Record the caller and delegated scope instead of granting a shared, unrestricted service identity.
What to Do Now
Which agents exist, what tools they access, what permissions they have, whether they delegate to other agents. If you don't know this, you can't govern it.
Remove auto-approve from sensitive operations. Scope tool permissions to the minimum required. This is Kill Chain Stage 4 — often a useful starting point, with priority determined by the deployment’s threat model.
Assess and bound risks upfront, make humans meaningfully accountable, implement technical controls, enable end-user responsibility. Use its structure as a starting point and map it to your organization’s existing controls and accountability.
Define the audit events needed for accountability and incident response. Capture identities, tool actions, policy decisions and outcomes; redact sensitive content, restrict access and set retention periods. This is a proposed organizational policy, not a universal requirement created by a vendor blog.
Track published NIST outputs and consultation updates. Separate the agent standards initiative from related identity, authorization and control-overlay projects; do not treat proposals as finalized standards or promise an unsupported completion date.
This is the governance layer of the Agentic AI Kill Chain. For technical controls, see Hook Guardrails, MCP Security, and Red Teaming. For detection, see Behavioral Baselines.
Practitioner content on agentic AI security — threat models, controls, and governance.
This work represents the author's independent research and personal views. It is not related to or endorsed by the author's employer.