AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
seven frameworks, one crosswalk to real controls

Agentic AI Security Frameworks, Compared

OWASP, NIST, AWS, Google, Microsoft, the Cloud Security Alliance and MITRE have all published guidance on AI agent risk. They overlap, and each uses its own words.

This page lines them up and maps them to controls you can deploy, including an AI agent allow list for web navigation.

7Frameworks compared
15OWASP agentic threats
4AWS agency scopes
10Controls in the crosswalk
Start here

Which framework answers which question

They are not competitors. Each was written for a different reader and a different job.

"What can go wrong?"

Threat catalogues: OWASP agentic threats, Microsoft's failure-mode taxonomy, MITRE ATLAS.

"How risky is this agent?"

Scoping tools: the AWS agentic AI security scoping matrix.

"How do we model threats?"

Method: CSA MAESTRO, a layered threat-modelling approach for agents.

"How do we manage AI risk overall?"

Management systems: NIST AI RMF and its generative AI profile.

"What principles should agents follow?"

Design principles: Google's approach to secure AI agents and SAIF.

"What do we actually deploy?"

None of them lists products. The crosswalk below turns them into controls.

Two warnings before you start. None of these frameworks is a certification you can pass.

And none replaces the others: a threat catalogue without a management system produces findings nobody owns.

The seven frameworks

What each one contains

OWASP GEN AI SECURITY PROJECT

Agentic AI Threats and Mitigations

From OWASP's Agentic Security Initiative. A catalogue of 15 agent-specific threats with mitigations.

  • Covers memory, tools, identity, multi-agent systems
  • Builds on the OWASP Top 10 for LLM applications
  • Includes "Excessive Agency" from that list
Best for: threat modelling and security reviews
NIST

AI Risk Management Framework

A general AI risk framework with four functions: Govern, Map, Measure, Manage.

  • Generative AI profile (NIST AI 600-1) adds specific risks
  • Not agent-specific, but widely used by US organisations
  • NIST has also asked for public input on AI agent security
Best for: governance programmes and audits
AWS

Agentic AI Security Scoping Matrix

Sorts agents into four scopes by how much agency they have, then lists controls per scope.

  • No agency, prescribed, supervised, full agency
  • Controls grow with each scope
  • Useful for deciding how much protection an agent needs
Best for: sizing controls per agent
GOOGLE

Secure AI agents and SAIF

Google's Secure AI Framework plus its published approach to secure agents.

  • Agents need well-defined human controllers
  • Agent powers must be limited
  • Agent actions must be observable
Best for: design principles for builders
MICROSOFT AI RED TEAM

Taxonomy of failure modes in agentic AI

A whitepaper that classifies how agentic systems fail, both security and safety failures.

  • Separates novel agent failures from existing ones
  • Includes memory poisoning case studies
  • Written from red-team experience
Best for: red-team planning
CLOUD SECURITY ALLIANCE

MAESTRO threat modelling

A threat-modelling method built for multi-agent systems, organised in layers.

  • From foundation models up to the agent ecosystem
  • Looks at threats between layers
  • Complements older methods such as STRIDE
Best for: architecture reviews
MITRE

ATLAS

A knowledge base of adversary tactics and techniques against AI systems, modelled on ATT&CK.

  • Real case studies of AI attacks
  • Tactics and techniques with IDs
  • Useful for detection engineering
Best for: SOC and detection teams

Summaries reflect each publisher's own descriptions. Always use the latest published version.

OWASP in detail

The 15 OWASP agentic threats, and where the web comes in

Highlighted threats are the ones where controlling which pages an agent may open directly reduces the risk.

T1Memory poisoningFalse data planted in agent memory.
T2Tool misuseLegitimate tools used for harmful ends, such as a browser submitting forms.
T3Privilege compromiseAgents gaining access they should not have, often via login pages.
T4Resource overloadAgents exhausting compute or services.
T5Cascading hallucinationFalse outputs spreading through steps.
T6Intent breaking and goal manipulationInjected content, often from web pages, redirects the agent.
T7Misaligned and deceptive behaviourAgents pursuing goals in harmful ways.
T8Repudiation and untraceabilityNo record of what the agent did or where it went.
T9Identity spoofing and impersonationAgents acting as users, including creating accounts.
T10Overwhelming human in the loopToo many approvals to review properly.
T11Unexpected code executionAgents running code, including through plugin installs.
T12Agent communication poisoningTampered messages between agents.
T13Rogue agentsAgents acting outside their intended scope.
T14Human attacks on multi-agent systemsPeople exploiting trust between agents.
T15Human manipulationAgents used to mislead people.
Page-level control reduces the riskNeeds other controls

Seven of the fifteen involve the agent doing something on a web page. That is why navigation policy belongs in any agent threat model.

The 8 action page types, mapped to OWASP threats

Action page typeWhat the agent could doOWASP threat
signupCreate accounts in your company's nameT9 identity spoofing
password_resetTake over or lock out an accountT3 privilege compromise
cart and checkoutSpend money without approvalT2 tool misuse
subscribeStart recurring charges or mailing listsT2 tool misuse
uploadPush files or data to outside servicesT11 code execution, data loss
post_create and commentPublish content as your organisationT13 rogue agents, T15 manipulation
AWS scoping matrix

Four scopes of agency, and the web control each needs

SCOPE 1

No agency

The model only answers. It takes no actions.

Web control: none needed for the model itself.

SCOPE 2

Prescribed agency

Actions follow fixed workflows that people designed.

Web control: allow only the pages the workflow needs.

SCOPE 3

Supervised agency

The agent plans its own steps, with human approval points.

Web control: deny action pages, require approval to pass.

SCOPE 4

Full agency

The agent acts on its own over long tasks.

Web control: default-deny, page-type policy on every request.

The higher the scope, the less you can rely on the agent's instructions. Scope 3 and 4 agents need deterministic boundaries.

Scope 2 example

A pricing-watch agent visits a fixed list of vendor pricing pages each week. Everything else is denied.

Scope 3 example

A procurement agent researches freely, but any signup or checkout page sends an approval request to a buyer.

Scope 4 example

A long-running research agent works for days. Action pages and unclassified hosts are denied, and every request is logged.

# Web policy by agency scope (illustrative) scope_2: allow: [pricing, documentation, status] default: deny scope_3: deny: [login, signup, checkout, upload, post_create] on_deny: ask_human scope_4: deny: [all 8 action types] unclassified: deny log: every_request
Crosswalk

Ten controls, mapped across the frameworks

Read across a row to see which framework asks for the control. Read the last column for what to deploy.

ControlOWASP agenticNIST AI RMFAWS matrixGoogleWhat to deploy
Agent inventoryT13 rogue agentsMapAll scopesHuman controllersAI-SPM or governance register
Scoped agent identityT3, T9ManageScope 3 and 4Limited powersNon-human identity platform
Approved tools onlyT2 tool misuseManageScope 2 and upLimited powersMCP gateway allowlist
Page-level web policyT2, T3, T9, T11ManageScope 3 and 4Limited powersAI agent allow list data at tool or proxy
Default-deny egressT13ManageScope 4Limited powersEgress proxy with unclassified = deny
Injection detectionT6MeasureScope 3 and 4Observable actionsRuntime protection
Human approval pointsT10GovernScope 3Human controllersWorkflow approvals on denied action pages
Full action loggingT8MeasureAll scopesObservable actionsObservability plus decision logs
Pre-release testingAllMeasureScope 3 and 4AssuranceRed teaming
Incident responseT8, T13ManageAll scopesObservable actionsPlaybook, kill switch, audit trail

Mappings are our reading of each framework, meant as a starting point for your own control matrix.

Rows marked "all scopes" apply even to the simplest agent. Start there if you can only do a few things this quarter.

Turning "limit agent powers" into a control

What a deterministic web boundary looks like

Every framework says agent powers must be limited. On the web, that means a check before each request.

Host layer

About 60 high-risk hosts, such as cloud metadata endpoints, always denied.

Page layer

28 page types on 40M+ domains, with action pages denied by default.

Rule layer

About 40 URL rules for risky patterns on any domain, such as wiki edits and WebDAV.

A fourth layer denies anything unclassified. Details: agent guardrails and the egress rules library.

Choosing a framework

Which one to adopt first

Your situationStart withAdd next
You already run an AI governance programmeNIST AI RMFOWASP agentic threats for the agent layer
You build agents on AWSAWS scoping matrixOWASP threats per scope
You need a threat model this monthOWASP agentic threatsCSA MAESTRO for multi-agent designs
You run a red teamMicrosoft taxonomyMITRE ATLAS for technique IDs
Your SOC needs detectionsMITRE ATLASOWASP threats for context
You design agent productsGoogle's agent principlesAWS scopes to size controls

Framework terms in plain words

Excessive agencyAn agent has more tools, permissions or autonomy than its task needs.
Tool misuseA legitimate tool is used to do something harmful.
Agency scopeHow far an agent may act without a person deciding each step.
Human controllerThe named person accountable for what an agent does.
Goal manipulationOutside content changes what the agent is trying to achieve.
RepudiationNobody can prove afterwards what the agent did.
Rogue agentAn agent acting outside its intended scope, by fault or by attack.
Deterministic controlA rule that gives the same answer every time, whatever the prompt says.
Common gaps

Where framework adoption usually stalls

Controls stay on paper"Limit agent powers" is written in the policy, but no system enforces it on web requests.
Only the prompt is checkedTeams add injection filters and stop there. Destinations stay open.
Vendor agents are left outSaaS agents that act for your staff never reach your gateways.
Logs lack the targetTraces show the model's words, not the URL the agent opened.
No owner per agentEvery framework asks for one, yet many agents have none.
Scopes drift upwardAn agent approved at scope 2 gains tools until it is really scope 4.
Method

Build your own control matrix in five steps

1. List every agent

Name, owner, tools, credentials, and whether it reaches the web.

2. Assign a scope

Use the four AWS scopes. Be honest about full agency.

3. Pick the threats

From the 15 OWASP threats, keep the ones each agent can realistically face.

4. Map to controls

Use the crosswalk above. One control can cover several threats.

5. Prove it works

Test each control, keep the logs, and review after every agent change.

Repeat quarterly

Agents gain tools over time, so scopes and controls must be re-checked.

Audit evidence

What auditors ask for, and where it comes from

Evidence requestedFramework linkSource system
Register of agents with ownersNIST Govern and MapGovernance tool or AI-SPM
Proof that agent powers are limitedGoogle principles, AWS scopesIdentity scopes, tool allowlists, page policy
List of blocked action attemptsOWASP T2 and T13Page-policy decision log
Record of every page an agent openedOWASP T8Egress proxy or tool logs
Test results before releaseNIST MeasureRed-team reports
Response to a past incidentNIST ManageIncident tickets and timelines

A page-policy decision log answers two of these rows directly: blocked attempts and pages visited.

Keep those logs for at least as long as your incident review window. Auditors often ask for twelve months of history.

The frameworks, tested against real 2026 incidents

  • The DseWiki edits map to OWASP T2 tool misuse and T13 rogue agents.
  • The account takeovers map to T3 privilege compromise and T9 identity spoofing.
  • In our replay, page data plus egress rules would have stopped almost all of them.
See the incident-by-incident prevention analysis The account takeovers

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

Framework questions

What is the best agentic AI security framework?
There is no single best one. OWASP's agentic threats are the most specific to agents, NIST AI RMF is the broadest management framework, and the AWS scoping matrix is the most practical for sizing controls.
What is the AWS agentic AI security scoping matrix?
A model that sorts agents into four scopes by how much agency they have: no agency, prescribed, supervised and full agency. Each scope comes with a larger set of recommended controls.
Does OWASP have guidance specific to AI agents?
Yes. OWASP's Agentic Security Initiative published a catalogue of 15 agentic threats with mitigations, alongside the OWASP Top 10 for LLM applications.
Does NIST cover AI agents?
The NIST AI RMF and its generative AI profile apply to agents, but they are not agent-specific. NIST has also requested public input on securing AI agent systems.
How do the frameworks handle agents browsing the web?
They ask you to limit agent powers and log agent actions. None names a specific control, so teams use page-level URL policy, such as an AI agent allow list, to make that limit enforceable.
Which framework covers multi-agent systems best?
CSA MAESTRO was built for multi-agent designs, and OWASP covers them in threats T12 to T14. Use both when agents talk to other agents.
Do these frameworks require specific products?
No. They describe risks, principles and controls. The choice of products is yours, which is why a crosswalk from framework items to deployable controls is useful.
Can I test a page-level control before adopting it?
Yes. The free sample covers 100 real domains, and the lookup API starts at $99 a month. See pricing.

Make "limit agent powers" enforceable on the web

One page-type check before each request, mapped to every framework above.

Download the sample