Agent security standards and regulation

A source-led map of how agent identity, delegation, runtime decisions and evidence relate to technical guidance and applicable obligations.

Read with care

Separate control design from compliance.

Standards, draft material, voluntary frameworks and binding laws have different force. Each reference below states one control implication and the remaining customer obligation. Product controls can support evidence; they do not confer certification or guarantee compliance.

01 / Architectural guidance

Architectural guidance

NIST AI RMF and agent authorityHow can agent action controls support AI risk management?NIST SP 800-207 zero trust for agentsHow do zero-trust concepts apply to an agent action?NIST agent identity concept paperWhat identity and authorization questions does NIST raise for software agents?OWASP Agent Control StandardWhat does an agent control hook need to enforce?MCP authorization specificationWhat does MCP transport authorization establish?MITRE ATLAS for agent threatsHow should an agent authority threat model use ATLAS?NSA MCP security guidanceWhere should MCP guidance affect agent tool architecture?
02 / Regulatory and assurance context

Regulatory and assurance context

PCI DSS and payment agentsWhat evidence matters when agents touch a cardholder-data environment?HIPAA and healthcare agentsWhat changes when an agent accesses electronic PHI?DORA and financial agentsHow does autonomous action affect ICT operational resilience?NIS2 and critical infrastructure agentsWhere do agent controls fit NIS2 cyber-risk measures?EU AI Act and agent controlsWhen are agent action logs relevant under the AI Act?GDPR and autonomous processingWhat must an agent preserve when processing personal data?FedRAMP and agent servicesWhat does an agent service need within a federal cloud authorization boundary?CMMC and defense agentsHow should agent access to CUI be scoped?
03 / National guidance

National guidance

Singapore AI governance framework and agentsHow does agent authority fit Singapore AI governance guidance?Australia agentic AI security guidanceWhich agent actions need an enforceable boundary?

Architecture discussion

Begin with the applicable source and a real execution path.

Request a Conversation