How the AEGIS framework mitigates agentic AI risks

Learn how Forrester's AEGIS framework can help organizations securely deploy agentic AI, shifting from static controls to dynamic risk assessment that balances innovation with safety.

The next big wave of AI adoption is underway as executives across industries plot how to bring agentic AI into their organizations. Many believe agentic AI will remake the workforce, creating an environment where humans and agents work alongside each other to reduce costs, boost productivity and scale services.

Agentic AI enables organizations to automate entire workflows, with agents capable of making decisions autonomously to execute complex, multistep processes across multiple digital systems. Some 17% of organizations have already deployed agents, according to the "2026 CIO and Technology Executive Survey" from Gartner, and more than 60% expect to do so within the next two years.

But the reality of agentic AI is more complex than a list of anticipated benefits for the organization. It also carries risks, and the technology's autonomy can have consequences that extend far beyond those associated with traditional automation. As agentic AI transforms enterprise operations, analysts at Forrester argue that traditional "block or allow" security models designed for predictable, human-initiated actions are inadequate for autonomous agents that operate at machine speed, make independent decisions and adapt their behavior dynamically. Instead, CISOs must pivot to a "probability of success" approach that continuously assesses risk in real time based on agent behavior, context and potential impact.

One emerging option for managing agentic AI risk is the Agentic AI Enterprise Guardrails for Information Security, or AEGIS, framework from Forrester Research. AEGIS aims to help organizations deploy agentic AI with reasonable guardrails in place, enabling innovation without recklessly exposing the enterprise to risk. By implementing continuous monitoring, threat detection and adaptive controls, AEGIS can help organizations build resilient AI operations that detect and respond to anomalies before they escalate into crises.

Agentic AI risks

Agentic AI significantly expands an organization's attack surface, creating more pathways for adversaries to breach enterprise systems and exploit agent behavior. Additionally, agentic AI can lead to cascading failures. As agents execute tasks through multistep workflows across interconnected platforms, they're subject to goal drift or hijacking through manipulated prompts, data inputs or tool permissions. An unintentional error or a maliciously prompted action taken by an agent anywhere along the way can ripple through the connected systems. Depending on the work an agent performs, the consequences can be severe.

Few organizations today are prepared to guard against such situations, according to research. Deloitte's 2026 "State of AI in the Enterprise" report found that only 21% of organizations had a mature model for governance of autonomous agents. That means they lack clear boundaries for what decisions agents can make, have few or no real-time monitoring systems to track agent behavior and flag anomalies, and have no audit trails to capture the full chain of agent actions.

Security leaders acknowledge that traditional cybersecurity architectures, designed for digital systems where humans ultimately execute actions, cannot handle enterprise environments in which AI agents act autonomously.

AEGIS offers CISOs, CIOs and CTOs a framework for building architectural and operational foundations that enable safe and responsible agentic AI deployments.

A framework for responsible agentic AI deployment

According to Forrester, AEGIS offers CISOs, CIOs and CTOs a framework for building architectural and operational foundations that enable safe and responsible agentic AI deployments. AEGIS hinges on the following principles:

  • Least agency. An agentic AI-specific version of the principle of least privilege, least agency gives AI agents as few capabilities, tools and permissions as possible. While least privilege limits users' ability to access resources, least agency limits agents' ability to make decisions and take action.
  • Continuous risk management to maintain trust. Environments where agentic AI has the ongoing ability to make decisions and take action require continuous monitoring of agents, models and data. The goal, according to Forrester, is to provide moment-by-moment assurance that agentic AI deployments are secure.
  • Explainable outcomes. Agentic AI makes decisions based on learning, context and intent, rather than static rules. Both people and systems must therefore be able to understand and explain security guardrail outcomes.

6 domains of the AEGIS framework

The AEGIS framework features the following six domains, which Forrester says organizations should adopt in phases:

  1. Governance, risk and compliance. Includes real-time risk and compliance monitoring, automated detection of behavior drift, cross-functional risk mapping and policy-as-code guardrails to enforce machine-executable policies.
  2. Identity and access management. Calls for managing agents as first-class entities with ownership, credentials, lifecycle management and auditability, and to have just-in-time, least-privilege authorization.
  3. Data security and privacy. Implements unified definitions of sensitive data, purpose-bounded data access, expanded data security posture management, data loss prevention, digital asset management for agent actions and privacy-preserving techniques such as masking, encryption and synthetic data.
  4. Application security. Includes the use of AI-specific threat modeling, rigorous validation of agent-generated code, software bills of materials, AI bills of materials for provenance, secure prompt engineering and continuous observability across the agent lifecycle.
  5. Threat management. Calls for detailed logging of prompts, actions and reasoning steps, errors; detection for prompt injection, hallucinations and drift; purple teaming for agent behaviors; and automated response playbooks tied to agent actions.
  6. Zero-trust architecture. Includes microsegmentation, API gateways, privilege and objective constraints, access brokers and network-level containment.

CISOs should note that implementing AEGIS requires specialized expertise in both AI systems and enterprise security architecture. Many enterprises operate hybrid environments with legacy systems that lack modern security capabilities. Integrating AEGIS controls with older infrastructure can be technically complex and could require significant modernization efforts, particularly in areas such as identity management and zero-trust architecture. Organizations might need to invest in training or external expertise to execute the framework effectively.

The phased long-term implementation timeline also requires sustained organizational commitment and resources. Despite these challenges, AEGIS offers a path forward for organizations serious about deploying agentic AI responsibly. Critically, the framework acknowledges that agentic AI is not simply another application to secure, but a fundamentally new category of enterprise actor requiring purpose-built governance and protection.

Mary K. Pratt is an award-winning freelance journalist with a focus on covering enterprise IT and cybersecurity management.