Key Takeaways

  • Agentic AI creates risk through actions, not only through generated content.
  • Static controls such as DLP, RBAC, prompt filtering and fixed rules are not enough for dynamic, multi-step agent behavior.
  • Intent security evaluates whether an action aligns with the user’s goal, authorized scope, context and expected behavior.
  • Behavioral baselines can help detect deviations and support runtime controls before unsafe actions propagate.

AI security is entering a new phase. The risk is no longer limited to a chatbot generating the wrong answer or exposing sensitive text. AI agents can retrieve data, call APIs, send emails, delete or modify records, approve workflows and trigger actions across systems.

That changes the security question. It is no longer only, “Is this content safe?” It also becomes, “Should this agent be doing this action, right now, for this purpose, within this scope?” That is the core idea behind the Intent Security Framework.

Why agentic AI creates a different security problem

The supplied framework highlights three major agentic security gaps:

  • Emergent context: agents accumulate memory, conversation history, retrieved data, tool outputs and prior reasoning that can influence future behavior.
  • Action execution: agents can use legitimate tools in unsafe ways, including deleting data, changing configurations, exposing information, issuing refunds or triggering external workflows.
  • Dynamic logic: behavior is shaped by prompts, retrieved context, model behavior and runtime conditions rather than fixed, auditable code.

In plain English, agents remember things, act on tools and make decisions in ways that are not always predictable from static rules. As a result, AI incidents may look less like classic data breaches and more like operational failures such as configuration drift, excessive refunds, wrong customer communications, runaway workflows or unauthorized process changes.

Diagnostic framework mapping seven questions across request, user, agent and transfer levels to assess AI agent intent and behavior

What the Intent Security Framework evaluates

The framework looks at four forces behind agent behavior:

  1. Developer intent: what the system prompt and guardrails authorize.
  2. User intent: what the human is actually trying to achieve.
  3. External intent: what retrieved documents, tools, APIs or third-party data may be injecting.
  4. Executed intent: what the agent actually does through actions, tool calls and outputs.

The goal is not simply to block risky content. It is to understand whether an agent’s action aligns with the user’s goal, the system’s authorized scope, the agent’s historical behavior and the surrounding context.

What this means for business leaders

Scaling AI agents is not only an automation challenge. It is also an operating-control challenge. Traditional controls such as DLP, RBAC, static rules and prompt filtering remain useful, but they are not designed on their own to govern dynamic, multi-step agent behavior.

The next security layer is behavioral: establish a baseline for normal intent, detect meaningful deviations and enforce controls at runtime. The organizations that move fastest with agentic AI will not necessarily be those with the fewest guardrails, but those with the smartest runtime controls.

Source / Further reading: Securing Agentic AI: The Intent Security Framework — Lasso Security

Discussion question: What do you think will be harder for enterprises: building useful AI agents, or governing what they are allowed to do?