Authors :
Sachin Suryawanshi
Volume/Issue :
Volume 11 - 2026, Issue 8 - August
Google Scholar :
https://tinyurl.com/2mjje64r
DOI :
https://doi.org/10.38124/ijisrt/26aug1168
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
Agentic artificial intelligence expands the enterprise security boundary because autonomous agents can plan
tasks, retain memory, invoke tools, call APIs, and initiate business actions. Authentication at session start is therefore
insufficient when later actions may be influenced by untrusted content, poisoned memory, compromised tools, or excessive
delegated privilege. This paper proposes the Zero Trust Agentic AI Security Framework (ZT-AASF), a vendor-neutral
architecture that applies continuous verification to consequential agent actions. The framework separates six control
planes: identity and delegation, context and data trust, policy and risk decision, tool and action enforcement, runtime
observability, and containment and recovery. A contextual authorization model evaluates delegated scope, source
provenance, data sensitivity, tool risk, behavioral deviation, and action impact before execution. A design-level evaluation
against ten OWASP agentic risk classes produces 27 of 30 control-coverage points for ZT-AASF versus 5 of 30 for a
conventional integration baseline. These values represent architectural coverage, not measured attack-prevention rates.
The results indicate that moving enforcement from the session boundary to the action boundary can reduce implicit trust,
constrain privilege propagation, and improve auditability while preserving useful autonomy.
Keywords :
Agentic AI; Cloud Security; Enterprise Architecture; Identity and Access Management; Runtime Governance; Secure Autonomous Systems; Tool Security; Zero Trust.
References :
- S. Yao, J. Zhao, D. Yu, N. Du, I. Shafran, K. Narasimhan, and Y. Cao, "ReAct: Synergizing Reasoning and Acting in Language Models," in Proc. International Conference on Learning Representations (ICLR), 2023.
- T. Schick et al., "Toolformer: Language Models Can Teach Themselves to Use Tools," in Advances in Neural Information Processing Systems, vol. 36, 2023, doi: 10.52202/075280-2997.
- L. Wang et al., "A Survey on Large Language Model Based Autonomous Agents," Frontiers of Computer Science, vol. 18, art. 186345, 2024, doi: 10.1007/s11704-024-40231-1.
- Q. Zhan, Z. Liang, Z. Ying, and D. Kang, "InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents," in Findings of the Association for Computational Linguistics: ACL 2024, pp. 10471-10506, 2024, doi: 10.18653/v1/2024.findings-acl.624.
- H. Zhang, J. Huang, K. Mei, Y. Yao, Z. Wang, C. Zhan, H. Wang, and Y. Zhang, "Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-Based Agents," in Proc. International Conference on Learning Representations (ICLR), 2025.
- A. Chhabra, S. Datta, S. K. Nahin, and P. Mohapatra, "Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges," IEEE Access, vol. 14, pp. 49455-49482, 2026, doi: 10.1109/ACCESS.2026.3675554.
- H. Su, J. Luo, C. Liu, X. Yang, Y. Zhang, Y. Dong, and J. Zhu, "A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents," IEEE Transactions on Pattern Analysis and Machine Intelligence, early access, Apr. 2026, doi: 10.1109/TPAMI.2026.3688650.
- S. Rose, O. Borchert, S. Mitchell, and S. Connelly, "Zero Trust Architecture," NIST Special Publication 800-207, National Institute of Standards and Technology, 2020, doi: 10.6028/NIST.SP.800-207.
- R. Chandramouli and Z. Butcher, "A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments," NIST Special Publication 800-207A, National Institute of Standards and Technology, 2023, doi: 10.6028/NIST.SP.800-207A.
- OWASP GenAI Security Project, "OWASP Top 10 for Agentic Applications for 2026," 2025. [Online]. Available: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/. Accessed: Aug. 23, 2026.
- K. Hines, G. Lopez, M. Hall, F. Zarfati, Y. Zunger, and E. Kiciman, "Defending Against Indirect Prompt Injection Attacks With Spotlighting," in Proc. CAMLIS 2024, CEUR Workshop Proceedings, vol. 3920, pp. 48-62, 2024, doi: 10.48550/arXiv.2403.14720.
- F. Jia, T. Wu, X. Qin, and A. Squicciarini, "The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents," in Proc. 63rd Annual Meeting of the Association for Computational Linguistics (ACL), pp. 29680-29697, 2025.
- L. Tsai and E. Bagdasarian, "Contextual Agent Security: A Policy for Every Purpose," in Proc. 19th Workshop on Hot Topics in Operating Systems (HotOS), pp. 8-17, 2025, doi: 10.1145/3713082.3730378.
- E. Tabassi, "Artificial Intelligence Risk Management Framework (AI RMF 1.0)," NIST AI 100-1, National Institute of Standards and Technology, 2023, doi: 10.6028/NIST.AI.100-1.
- C. Autio et al., "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile," NIST AI 600-1, National Institute of Standards and Technology, 2024, doi: 10.6028/NIST.AI.600-1.
- H. Booth et al., "Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile," NIST Special Publication 800-218A, National Institute of Standards and Technology, 2024.
- X. Hou, Y. Zhao, S. Wang, and H. Wang, "Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions," ACM Transactions on Software Engineering and Methodology, online publication, 2026, doi: 10.1145/3796519.
Agentic artificial intelligence expands the enterprise security boundary because autonomous agents can plan
tasks, retain memory, invoke tools, call APIs, and initiate business actions. Authentication at session start is therefore
insufficient when later actions may be influenced by untrusted content, poisoned memory, compromised tools, or excessive
delegated privilege. This paper proposes the Zero Trust Agentic AI Security Framework (ZT-AASF), a vendor-neutral
architecture that applies continuous verification to consequential agent actions. The framework separates six control
planes: identity and delegation, context and data trust, policy and risk decision, tool and action enforcement, runtime
observability, and containment and recovery. A contextual authorization model evaluates delegated scope, source
provenance, data sensitivity, tool risk, behavioral deviation, and action impact before execution. A design-level evaluation
against ten OWASP agentic risk classes produces 27 of 30 control-coverage points for ZT-AASF versus 5 of 30 for a
conventional integration baseline. These values represent architectural coverage, not measured attack-prevention rates.
The results indicate that moving enforcement from the session boundary to the action boundary can reduce implicit trust,
constrain privilege propagation, and improve auditability while preserving useful autonomy.
Keywords :
Agentic AI; Cloud Security; Enterprise Architecture; Identity and Access Management; Runtime Governance; Secure Autonomous Systems; Tool Security; Zero Trust.