Insight · Security

Agentic AI Security & Controls

Agentic systems change enterprise risk because software can select tools, access data, retain context, and take actions with less direct human intervention. Security must govern what an agent is allowed to know, decide, access, and do.

Executive context

Why this matters

  • An agent may combine model reasoning with identity, memory, tools, data access, delegated authority, and connections to enterprise systems.
  • Traditional application controls remain necessary, but they must be extended to govern instructions, tool selection, action boundaries, evaluation, and human intervention.
  • Leaders need a control model that connects AI-specific risk to existing security, risk, architecture, and operational-resilience responsibilities.

Core content

The operating considerations behind the idea

Identity before autonomy

Every production agent needs an explicit identity and an accountable owner. Access should be granted to that identity—not inherited broadly from a developer, service account, or end user.

  • Unique workload or agent identity
  • Least-privilege authorization
  • Short-lived credentials where practical
  • Separation between development, testing, and production

Bound knowledge and tools

Agent security depends on controlling both the context an agent can retrieve and the tools it can invoke. Data boundaries, retrieval authorization, tool allowlists, and policy enforcement should be designed together.

  • Identity-aware data retrieval
  • Approved tool inventory
  • Explicit input and output boundaries
  • Third-party model and service dependencies

Govern consequential actions

Not every action should be autonomous. Organizations should define which decisions require deterministic checks, human approval, escalation, or prohibition.

  • Risk-based approval thresholds
  • Human authorization for consequential actions
  • Deterministic validation at critical boundaries
  • Containment and kill mechanisms

Observe and evaluate the complete chain

Monitoring must cover more than model output. Useful evidence includes instructions, retrieved context, tool calls, policy decisions, approvals, actions, outcomes, and exceptions.

  • Traceable activity logs
  • Quality and security evaluations
  • Anomaly and misuse detection
  • Incident response and recovery paths

Connect to enterprise controls

Agentic security should extend existing enterprise security practices rather than become an isolated control program. The Studio maps this work to Govern, Identify, Protect, Detect, Respond, and Recover outcomes in the NIST Cybersecurity Framework where appropriate.

  • Governance and risk ownership
  • Architecture and threat modeling
  • Identity, data, and platform controls
  • Assurance, resilience, and continuous improvement

Leadership questions

Questions worth asking before the next decision

  1. 01Which agents can take actions that affect members, employees, money, systems, or regulated decisions?
  2. 02Who owns each agent and accepts residual risk?
  3. 03What information can the agent retrieve, retain, or disclose?
  4. 04Which tools and systems can it invoke, and under whose authority?
  5. 05Where are human approval and deterministic checks required?
  6. 06Can the organization reconstruct, interrupt, and contain an agent's activity?

Practical implications

What leadership and delivery teams should consider

  • Inventory agents as governed enterprise identities and assets.
  • Classify use cases by action authority, data sensitivity, reversibility, and business consequence.
  • Design authorization, observability, evaluation, and containment before production release.
  • Map AI-specific controls into existing security, vendor-risk, incident, and assurance processes.
  • Use evidence from controlled implementations to refine policy and risk thresholds.

Related Studio assets

Related advisory service

AI Governance & Responsible Adoption

Clarify accountability, risk tiers, policies, controls, and oversight for AI and agentic systems.