DOI: 10.69554/miwg3713 ISSN: 2398-5119

Securing agentic AI workflows: A defence-in-depth framework for autonomous systems

Sushma Mahadevaswamy
The rapid enterprise adoption of agentic artificial intelligence (AI) has introduced a category of security risk that existing cyber security frameworks were not designed to address. With 78 per cent of Fortune 500 companies projected to deploy agentic AI by 2026 and the global market expected to reach US$89.6bn, the attack surface created by these autonomous workflows demands urgent attention from security practitioners. This paper examines the distinct threat model presented by agentic AI, drawing on recent high-profile incidents, including the weaponisation of a large language model in a state-sponsored espionage campaign affecting 30 organisations and the compromise of an open-source agent framework exposing 30,000 Internet-facing instances, to illustrate the consequences of inadequate controls. Grounded in the Open Worldwide Application Security Project’s Top 10 for Agentic Applications (2026) and the National Institute of Standards and Technology’s ongoing agentic AI security initiative, the paper proposes a five-layer defence-in-depth framework encompassing input validation, identity and least privilege, runtime sandboxing, human-in-the-loop governance, and continuous behavioural monitoring. It identifies sandboxing and least-privilege enforcement as the highest return on investment controls, provides a prioritised implementation roadmap, and discusses the emerging paradigm of cryptographic workflow authentication. The analysis concludes that organisations treating agentic AI security as an extension of traditional application security will find themselves critically exposed and that a purpose-built security architecture is now a business imperative. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.

More from our Archive