Reference Sources
The standards, incident reports, and empirical studies this framework is built on.
Numbered in order of first appearance. Standards and regulatory instruments are cited to the issuing body; verify the current version and any superseding revision before relying on a specific clause. Figures drawn from vendor and analyst surveys are reported as published and have not been independently audited.
URLs were checked in September 2026. Entries marked † resolve to a publisher landing page rather than a verified deep link, because the document sits behind registration, is distributed as a periodically revised artifact, or had no stable permalink at the time of writing—confirm the specific edition before citing it externally.
- 1“OWASP Top 10 for Agentic Applications 2026 (ASI01–ASI10),” OWASP GenAI Security Project, December 9, 2025.
- 2MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems, MITRE Corporation.
- 3AI Controls Matrix (AICM) v1.1, Cloud Security Alliance (247 control objectives across 18 domains, with mappings to ISO/IEC 42001 and ISO/IEC 27001). †
- 4“OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation,” OpenAI, July 21, 2026.
- 5“Security Incident Disclosure — July 2026,” Hugging Face, July 16, 2026.
- 6Zhun Wang, Nico Schiller, Hongwei Li, et al., “ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?” arXiv:2605.11086, May 11, 2026.
- 7“The AI Agent Governance Gap: What CISOs Need Now,” Cloud Security Alliance Lab Space, April 2026, reporting the 2026 CISO AI Risk Report survey of 235 large-enterprise CISOs and CIOs.
- 8“Top Cybersecurity Trends 2026,” Gartner, April 28, 2026, as reported by the Cloud Security Alliance. †
- 9“AI Agents at Work 2026: Securing the Agentic Enterprise,” Okta, June 2, 2026. †
- 10“Top Cybersecurity Threats 2026,” Forrester Research, as reported in Cybersecurity Insiders, July 2026. †
- 11“2026 SANS State of Identity Threats & Defenses Survey,” SANS Institute, March 10, 2026. †
- 12“The Non-Human Identity Governance Vacuum: AI Agents and the Fastest-Growing Unmanaged Attack Surface,” Cloud Security Alliance Lab Space, May 20, 2026.
- 13“State of Identity Security 2026,” Sophos, May 12, 2026 (survey of 5,000 security leaders across 17 countries). †
- 14Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, National Institute of Standards and Technology, January 2023.
- 15ISO/IEC 42001:2023 — Information Technology, Artificial Intelligence, Management System, International Organization for Standardization, December 2023. †
- 16“Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization,” draft concept paper, National Cybersecurity Center of Excellence, NIST, February 5, 2026.
- 17“OWASP Non-Human Identities Top 10,” OWASP Foundation.
- 18CIS Benchmarks, Center for Internet Security.
- 19“OWASP Top 10 for LLM Applications 2026,” OWASP GenAI Security Project, August 3, 2026.
- 20Supply-chain Levels for Software Artifacts (SLSA), Open Source Security Foundation.
- 21Secure Software Development Framework (SSDF) Version 1.1, NIST SP 800-218, National Institute of Standards and Technology, February 2022.
- 22Computer Security Incident Handling Guide, NIST SP 800-61, National Institute of Standards and Technology. †
- 23Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal of the European Union, June 13, 2024.
- 24Regulation (EU) 2022/2554 (Digital Operational Resilience Act), Official Journal of the European Union, December 14, 2022.
- 25“AI Agent Standards Initiative,” Center for AI Standards and Innovation, National Institute of Standards and Technology, launched February 17, 2026.
- 26Model Context Protocol, Agentic AI Foundation, Linux Foundation, December 2025; authorization specification built on OAuth 2.1 with PKCE and Resource Indicators (RFC 8707).
- 27Agent Control Standard (ACS), OWASP GenAI Security Project, unveiled September 1, 2026 (runtime agent governance: guardian-agent enforcement points, OpenTelemetry and OCSF observability, and an Agent Bill of Materials expressed in CycloneDX, SWID, or SPDX).
- 28Agent Observability Standard (AOS), OWASP GenAI Security Project. †
- 29“Semantic Conventions for Generative AI Systems,” OpenTelemetry (gen_ai.* namespace at Development stability; agent, workflow, tool, and model spans).
- 30“Practical Guide for Securely Using Third-Party MCP Servers,” OWASP GenAI Security Project. †
- 31“Agentic MCP Security Best Practices v1,” Cloud Security Alliance, August 2026. †
- 32Secure Production Identity Framework for Everyone (SPIFFE), Cloud Native Computing Foundation.
Version 1.3. Published August 2026; updated September 2026. This framework is offered as practitioner guidance and does not constitute legal or regulatory advice. Verify all regulatory mappings against current obligations in your jurisdiction.