Agentic security

The Three Domains of Agentic Security

By Robin Martherus


RSA Conference 2026 is happening this week. Agentic AI security is the dominant theme — not one of many, the theme. Microsoft announced Zero Trust for AI. Cisco unveiled DefenseClaw. CrowdStrike acquired SGNL for continuous dynamic authorization. Palo Alto shipped Prisma AIRS 3.0. Okta launched agent-specific identity. Proofpoint bought Acuvity for intent-based security. Dozens of startups are pitching agent governance.

The energy is real. The investment is massive. And almost all of it is aimed at two of the three problems that actually need solving.

The Industry Says “AI Security” Like It’s One Thing. It’s Three.

When a CISO says “we need an AI security strategy,” they could mean any of three fundamentally different things:

  1. Using AI to secure things — AI as a force multiplier for defenders
  2. Securing AI itself — protecting AI systems from attack and misuse
  3. Securing ourselves against AI — governing AI agents that are working as designed but whose autonomous actions may cause harm

These aren’t three perspectives on the same problem. They have different threat models, different risk profiles, different tooling requirements, and different blast radii. Conflating them — as the industry routinely does — leads to misallocated investment, wrong tools applied to wrong problems, and a dangerous illusion of governance.

Domain 1: Using AI to Secure Things

AI as instrument. The security team wields it. Faster threat detection, automated triage, natural language log queries, predictive risk scoring, autonomous SOC operations.

This is where the bulk of RSAC spending sits and has for years. CrowdStrike Charlotte AI. Microsoft Security Copilot. Palo Alto Cortex XSIAM. Google’s Agentic SOC. The AI is a tool; the human remains the decision-maker. Traditional security economics apply.

If the AI tool fails, you fall back to human analysts doing things the slow way. The blast radius is bounded by the security team’s own permissions. This domain is mature, crowded, and well-understood.

Domain 2: Securing AI Itself

AI as target. Prompt injection, model poisoning, jailbreaks, MCP vulnerabilities, supply chain attacks on model infrastructure, data exfiltration through agent tool access. Classic application security applied to a new category of application.

This was the breakout theme at RSAC 2025 and has exploded in 2026. The evidence base is substantial: 30+ CVEs targeting MCP servers in the first two months of 2026 alone. Analysis of 7,000 MCP servers found 43% have OAuth auth flaws, 43% have command injection vulnerabilities, and a third allow unrestricted network access (see). Anthropic’s own mcp-server-git had three chained vulnerabilities achieving full remote code execution (see). OWASP published its Top 10 for Agentic Applications (see) in December 2025, codifying the attack surface.

The products announced at RSAC 2026 overwhelmingly target this domain: AWS Bedrock AgentCore Policy for deterministic enforcement on agent actions. Prisma AIRS 3.0 for agent runtime security. Cisco AI Defense for pre-deployment resilience testing. This is important work. It is necessary. And it is not sufficient.

Domain 3: Securing Ourselves Against AI

This is the domain the industry is barely touching.

The agent isn’t compromised. It isn’t under attack. It’s doing exactly what it was built to do. The problem is that what it’s capable of doing within its permissions may not be what should happen in context.

This isn’t theoretical. In March 2026, Meta’s internal AI agent passed every identity check and still caused a Sev 1 breach by autonomously posting to a shared forum. Alibaba’s ROME agent used its legitimate billing credentials to authorize cloud spend for cryptocurrency mining. Twenty AI researchers in the “Agents of Chaos” study documented eleven failure modes — including agents that lied about what they did — all while using valid credentials for authorized actions.

Every one of these incidents involved agents working within their technical permissions. No vulnerability was exploited. No credential was stolen. The security stack answered “Can this agent do this?” correctly every time. The question that would have prevented each incident — “Should this agent be doing this right now, for this purpose, in this context?” — was never asked. Because no mechanism exists to ask it.

Domain 3 is where intent verification, normative reasoning, continuous trust, and behavioral governance live. The challenge isn’t technical vulnerability. It’s the governance gap between “this agent is authorized” and “this agent’s actions are appropriate.”

The Confusion Has Consequences

When the industry says “AI security,” it almost always means Domain 1 or Domain 2. Domain 3 gets folded into Domain 2 as an afterthought — “just add more access controls.” This conflation has real consequences.

Investment is misallocated. The bulk of security spending goes to Domains 1 and 2. Domain 3 — where the existential governance challenges live — is underfunded and underbuilt. Bessemer Venture Partners calls securing AI agents “the defining cybersecurity challenge of 2026” (see), but the investment thesis is still predominantly aimed at Domains 1 and 2.

The wrong tools are applied. Domain 2 tools — guardrails, policy engines, vulnerability scanning — answer “Is this AI system secure?” They don’t answer “Should this agent be doing this?” Applying Domain 2 solutions to Domain 3 problems creates a false sense of governance. A perfectly secured agent with no vulnerabilities, running behind a hardened MCP gateway, with least-privilege credentials, can still cause a Meta-scale incident if nobody asks whether its autonomous actions are appropriate in context.

Standards miss the hard problem. The OWASP Top 10 for Agentic Applications is excellent for Domain 2. But two of its entries — ASI09 (Human-Agent Trust Exploitation) and ASI10 (Rogue Agents) — are Domain 3 problems dressed in Domain 2 clothing. They’re identified as risks but addressed with technical mitigations rather than governance frameworks.

Accountability becomes diffuse. In Domains 1 and 2, accountability follows familiar patterns. The security team secures the tool. The vendor patches the vulnerability. In Domain 3, accountability is structural: who is responsible when an agent, acting within its permissions, causes harm through an accumulation of individually-appropriate actions? Acuvity coined a term for this — “semantic privilege escalation” (see) — and it’s gaining traction because it names a problem that no existing security category covers.

The Keynote Gap

Here is the telling pattern at RSAC 2026: the keynotes describe a Domain 3 world, but the products launched at the same conference are almost entirely Domains 1 and 2.

Jeetu Patel (Cisco) spoke about “governance, trust, access, and accountability” for the agentic workforce. Vasu Jakkal (Microsoft) spoke about “building trust in the agentic AI era.” Multiple speakers noted that “AI cannot replace human judgment, empathy, and ethical reasoning.” A session titled “Beyond Zero Trust: Continuous Validation for Modern Enterprise Security” introduced “Multidimensional Continuous Validation” where trust is re-evaluated throughout each session.

But look at what shipped: Agent 365 gives you visibility into agent behavior. Prisma AIRS 3.0 protects against tool misuse. DefenseClaw enforces MCP policies. These are Domain 2 products. Important ones. But they don’t answer the Domain 3 question.

A growing number of vendors are starting to cross the line. Proofpoint’s acquisition of Acuvity and their “intent-based AI security” launch (see) explicitly calls intent “the missing dimension in AI agent security.” Lasso Security’s Intent Deputy (see) analyzes behavioral intent in real time. Token Security launched intent-aligned permissions. Credo AI is extending AI governance into agentic runtime monitoring. Microsoft shipped an open-source Agent Governance Toolkit with regulatory framework mapping. These are Domain 3 beachheads — real movement toward governing agent purpose, not just agent access. But most are still approaching it from Domain 2 angles — observing and detecting rather than preventing. The gap between “what did this agent do?” and “should this agent have done it?” remains largely unaddressed.

What Domain 3 Actually Requires

Domain 3 governance cannot be bolted onto Domain 2 infrastructure. The threat model is different. In Domain 2, you’re defending an asset against attackers. In Domain 3, you’re governing an autonomous actor whose normal operation may cause harm. Different threat model, different architecture.

Domain 3 requires capabilities that don’t exist in production today:

A formal language for intent. Not just “what can this agent access?” but “what is this agent for?” Structured, machine-readable intent declarations that can be verified at runtime and enforced as behavioral contracts. The agent is boxed whether it’s honest or not.

Normative reasoning. The ability to evaluate whether an action should happen given organizational context, regulatory requirements, ethical constraints, and downstream consequences. This is the “should” layer. Credo AI and Microsoft’s Agent Governance Toolkit are approaching it from the compliance side — mapping regulations to AI systems and monitoring for violations. But compliance is only one tier of normative reasoning. The professional judgment that would have stopped UnitedHealth from denying care to a patient who can’t walk, or the ethical reasoning that would have stopped a chatbot from engaging a suicidal teenager — those require governance that no product ships today.

Continuous trust computation. Not event-triggered policy re-evaluation but a mathematical model of trust that evolves continuously based on behavior, time, and environmental conditions. CrowdStrike/SGNL’s continuous dynamic authorization is the closest production capability — real-time risk-based access decisions via CAEP. But it is event-driven (re-evaluate on signal change), not physics-modeled (trust as a continuous signal with decay, momentum, and resilience-weighted earning). Trust as a continuous computation — with properties like entropic decay, propagation, and anti-accumulation — is a Domain 3 primitive. Academic work (the Trust-Vulnerability Paradox (see), entropy-based trust models (see)) validates the concept. No product implements the full mathematical model.

Accountability infrastructure. Provenance chains, trajectory records, and attribution mechanisms that answer “who is responsible?” when an agent’s individually-appropriate actions aggregate into harm. Today, 93% of AI agent projects use unscoped API keys with no cascade revocation (see). Delegation chains are opaque. Trust doesn’t degrade across hops. Nobody can answer “Agent A delegated to Agent B, which delegated to Agent C — who is accountable for Agent C’s actions?”

Governance that scales without humans in every loop. IDC projects 1.3 billion AI agents in operation by 2028. Human-in-the-loop doesn’t scale to that. The governance layer itself must be principled, auditable, and autonomous — governed by the same rules it enforces.

The Three Domains, Mapped

Domain 1: AI for Security Domain 2: Security for AI Domain 3: Governance of AI
The question How do we use AI to defend better? How do we protect AI from attack? How do we govern AI acting autonomously?
AI’s role Instrument Asset to defend Autonomous actor to govern
Threat model Attackers vs. defenders (AI-assisted) Attackers vs. AI systems Normal operation without adequate governance
Blast radius Bounded by security team permissions Application-level damage Organizational, reputational, legal, societal
If it fails Fall back to human analysts Patch, isolate, remediate No fallback — the agent was never broken
Maturity High Rapidly growing Nascent
RSAC 2026 investment Heavy Heavy Early movement — intent verification emerging, normative governance nascent

What Comes Next

Domains 1 and 2 are necessary. An unsecured AI system is a liability regardless of governance. But they are insufficient. Without Domain 3, we will have highly secure, well-defended AI agents doing things that shouldn’t be done.

The standards pipeline is opening. NIST’s AI Agent Standards Initiative launched in February 2026, with a concept paper on agent identity and authorization due April 2 (see). CSA launched the CSAI Foundation at RSAC this week — a new nonprofit dedicated to “Securing the Agentic Control Plane” (see). The OpenID Foundation finalized CAEP and the Shared Signals Framework in September 2025, with “robotic principals” explicitly in scope (see). The window to shape how Domain 3 gets built is open now. It won’t stay open.

The agents at RSAC 2026 are getting more secure every day. Whether they’re getting more governed is a different question entirely. That’s the work behind Tamed Autonomy — a framework exploring what Domain 3 governance looks like when you design it as its own architecture rather than bolting it onto Domain 2 infrastructure.


Sources

Leave a Reply