Agent Security Framework is a comprehensive, layered security framework designed to address the unique risks introduced by autonomous AI agents, agentic workflows, multi-agent systems, and AI-powered automation platforms. The framework organizes agent security into eight architectural layers spanning infrastructure, foundation models, data and memory, reasoning and planning, identity and authorization, tool and action execution, orchestration, and human-agent interaction, supported by cross-cutting governance and observability controls. The framework provides a structured methodology for identifying threats, implementing controls, validating security measures, and mapping requirements to leading industry standards and guidance, including NIST AI Risk Management Framework (AI RMF), ISO/IEC 42001, ISO/IEC 23894, the European Union AI Act, Cloud Security Alliance (CSA) AI Controls Matrix (AICM), CSA MAESTRO, OWASP Agentic Top 10, OWASP LLM Top 10, and MITRE ATLAS. Version 1.1 expands coverage of Model Context Protocol (MCP) security, computer-use and browser-based agents, multi-modal prompt injection, multi-agent orchestration risks, provenance preservation, reversibility classification, and least-agency design principles. The framework also introduces maturity models, validation methodologies, incident mappings, and practical implementation guidance intended for security engineers, AI platform teams, governance and compliance professionals, researchers, auditors, and executive leadership. This publication is intended to serve as a vendor-neutral reference architecture and control framework for designing, assessing, securing, and governing AI agent systems in both commercial and government environments. The framework emphasizes defense-in-depth, traceability of controls, measurable validation, and alignment with emerging regulatory and industry requirements for trustworthy AI systems.
Pendleton et al. (Tue,) studied this question.