Quick summary

  • AWS recommends extending zero trust, least privilege, and defense in depth to govern autonomous, probabilistic agents that can take action.
  • Agents can authenticate, call APIs, and chain actions faster than a security team can respond through a manual process.
  • Give every agent a distinct short-lived identity, log tool activity, and use tiered automated containment with human approval for high-impact actions.

What happened

The threat model has changed

AI agents do more than generate text. They can authenticate for users, invoke tools, connect to APIs, and execute multi-step workflows without approval at every action. Their autonomy and probabilistic behavior mean the same prompt may produce a compliant result once and a policy violation later. A one-time predeployment assessment is therefore insufficient for agentic workloads.

AWS argues that familiar foundations still apply: identity governance, least privilege, defense in depth, backup, and recovery. The difference is continuous enforcement. Each agent needs its own identity, temporary scoped credentials, independently authorized requests, and a traceable chain showing why every consequential action was allowed.

Behavioral detection and tiered response

Static rules built around human activity cannot fully follow agents that adapt over time. Security teams need living baselines and telemetry for tool calls, accessed data, communication destinations, and action outcomes. Anomalies must surface in real time, but response should be tiered. Clearly dangerous behavior can be contained automatically; ambiguous cases should preserve evidence and escalate to a person.

A critical boundary is preventing one component from simultaneously reading sensitive data, communicating externally, and consuming untrusted content. Separating those capabilities reduces the blast radius of prompt injection. Policies must also be enforced at the tool and identity layers, not only in a system prompt, because prompts are not access-control mechanisms.

Adoption should begin with an inventory of agents, owners, credentials, tools, and data. Add kill switches, action budgets, approval gates for high-impact operations, and recovery exercises. The goal is a response fast enough for automated threats while keeping human judgment over decisions with significant consequences.

Source

Agentic security: Detection and response at machine speed

Why developers should care

Agents can authenticate, call APIs, and chain actions faster than a security team can respond through a manual process.

  1. 1Give every agent a distinct short-lived identity, log tool activity, and use tiered automated containment with human approval for high-impact actions.