securitycontrols.ai
Working notes on securing autonomous AI agents — the threats, the controls, and how to prove they hold. Companion writing to the Agentic Security Control Matrix.
THOUGHT-LEADERSHIPMost of securing an AI agent is well-trodden ground. Three gaps are not. They are the reason a crosswalk needs to exist, and the places I planted a flag of my own.
THOUGHT-LEADERSHIPMost matrices tell you what a control is. The hard part is showing it actually holds. Every control here carries three proofs: is it configured, does it survive an attack, and what artifact says so on an ongoing basis.
THOUGHT-LEADERSHIPSecuring an agent is not one job. The same control means something different to the engineer, the detection analyst, the red teamer, the GRC lead, and the responder. So every control in the matrix reads through all five.
LAYER · IDENTITYThe first layer of the matrix. Five controls that decide which agent did what, and what each one was allowed to do, plus how to prove each holds.
LAYER · CONTAINMENTThe second layer of the matrix. Nine controls built on one assumption: sooner or later the agent will be wrong or hijacked, so bound the blast radius before it happens.
LAYER · PROTOCOLThe third layer of the matrix. Seven controls for the wires between an agent and everything it talks to, where the supply chain and the injection risk concentrate.
LAYER · GOVERNANCEThe fourth layer of the matrix. Nine controls for the human checkpoints, the records, and the accountability that keep an autonomous system answerable.
LAYER · RUNTIMEThe fifth layer of the matrix. Eight controls for watching an agent as it runs, including the frontier ones nobody has fully solved yet.
LAYER · ASSURANCEThe sixth layer of the matrix. Seven controls that prove an agent is safe to run, before it goes live and re-proven on every change after, the gates, the supply-chain checks, and the proof that it holds at all.
VENDOR-LANDSCAPE · IDENTITYA snapshot of who is building agent identity and authorization, organized by the controls they map to. Standards first, vendors second, no recommendations.
VENDOR-LANDSCAPE · CONTAINMENTA snapshot of who is building agent containment, organized by the controls they map to. Standards first, vendors second, no recommendations, and an honest map of where no product exists yet.
VENDOR-LANDSCAPE · PROTOCOLA snapshot of who is building the protocol layer, organized by the controls they map to. Standards first, vendors second, and an honest note on how much of the security is still missing.
VENDOR-LANDSCAPE · GOVERNANCEA snapshot of who is building agent governance, organized by the controls they map to. Standards and regulation first, vendors second, no recommendations.
VENDOR-LANDSCAPE · RUNTIMEA snapshot of who is building the runtime supervision layer, organized by the controls they map to. Standards first, vendors second, no recommendations.
VENDOR-LANDSCAPE · ASSURANCEA snapshot of who is building continuous assurance, organized by the controls they map to. Standards and open work first, labs and vendors second, no recommendations.
VENDOR-LANDSCAPE-CAPSTONEStepping back from the six layers: where the field is consolidating, where the genuinely new energy is, and who is, and is not, moving on the three gaps no framework closes.