Reveals how attack matrices fail to address emergent agentic behavior, implying a need for new frameworks.
The security industry continues to answer agentic AI risk by producing attack matrices: adversary-indexed taxonomies of tactics and techniques. This paper argues that the most consequential class of agentic risk is structurally invisible to any such framework. Emergent agentic behavior is authorized, uncompromised, and non-adversarial; it arises from an agent’s objective, its environment, and composition effects across agents rather than from an attacker executing a method. Because attack matrices index by mechanism and attach mitigations to enumerable techniques, they have no slot for behavior that produces attack-shaped outcomes through non-attack mechanisms. The paper separates observability from enumerability, identifies runtime measurement as the perception layer that enumeration cannot supply, and frames the control model for non-enumerable behavior as an open problem requiring a different ontology rather than a longer catalog.
No takes yet. Share an insight, caveat, or question.
Narnaiezzsshaa Truong (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: