Home / Standards / AIGS 500
Exposure Draft

AIGS 500 Agent and Tool Security

Agents act with least privilege, and dangerous combinations of capability are found and treated, because risk lives in the combination, not in any single part.

Document
AIGS 500, Exposure Draft ED-2026-500
Status
Founding draft, open for member comment
Working Group
TWG-500 Agents and Tools

1. Objective

To prevent AI agents from being turned against the organization, by limiting what each agent can do and by finding the specific combinations of capability that make an agent exploitable.

2. Key terms

Capability profile. A record of what an agent can take in, read, write and send, the tools it can call, and how autonomously it acts.

Exposure leg. One of four capabilities that together form an exploitable path: (1) accepts untrusted input, (2) reads private or confidential data, (3) writes to shared systems other people or agents rely on, (4) sends data outside the organization.

Exposure path. An agent, or a chain of connected agents, that holds a dangerous combination of exposure legs. An agent holding all four is a complete exposure path.

AI agent holds all four legs 1 Untrusted inputemail, web, documents, users 2 Private data readconfidential or personal data 3 Shared writerecords others rely on 4 External sendemail, web calls, APIs Each leg can pass review on its own. The path is a property of the combination.
The four exposure legs. Removing any one leg breaks the path.

3. Requirements

500.1The organization shall maintain a capability profile for every AI agent, recording its inputs, data reads, writes, external sends, tools and autonomy level.
500.2The organization shall analyze each agent, and each chain of agents that pass data to one another, for exposure paths. Agents holding all four exposure legs shall be treated as high risk regardless of the risk rating of each component.
500.3Every tool action available to an agent shall be classified (for example read, write, send, delete). An action that has not been classified shall be reported as unmeasured and shall never be assumed to be read-only.
500.4Agents that send data outside the organization shall do so only to destinations on an approved allow-list, reviewed by the owner of record.
500.5Non-human identities used by agents (service principals, keys, tokens) shall be inventoried, owned under AIGS 100, scoped to least privilege and rotated. Standing, broad write credentials shall not be granted to agents.
500.6Tool and integration servers that agents may call shall be listed in an approved registry. New servers and changes to their tools shall be reviewed before use.
500.7Actions with material impact (payments, deletions, external commitments, privilege changes) shall require human approval unless an exception is approved and recorded.
500.8The organization shall map its controls to a recognized catalog of AI and agent threats (for example the OWASP lists for LLM applications and agentic systems) and shall state, for each threat, what is covered and the limit of that coverage.

4. Evidence

  • Capability profiles and exposure-path findings with treatment decisions.
  • Tool action classification, including the unmeasured list.
  • Egress allow-lists and reviews.
  • Non-human identity inventory and rotation records.
  • Tool server registry and change approvals.
  • Threat coverage map with stated limits.

5. Metrics

MetricDefinition
Complete exposure pathsNumber of agents or chains holding all four exposure legs.
Unmeasured actionsTool actions not yet classified, divided by all tool actions available to agents.
Egress controlExternally sending agents with an approved allow-list, divided by externally sending agents.

6. Basis for conclusions

Prompt injection turns any agent that reads untrusted content into a possible insider. Whether that matters depends on what else the agent can do. Reviewing components one at a time misses the risk, because no single leg fails its own review. The draft therefore requires analysis of combinations and chains. Requirement 500.3 addresses a common error: treating unknown tool actions as harmless reads.

7. Questions for respondents

  1. Are the four exposure legs the right decomposition? Should others be added?
  2. Should agents holding three legs also be rated high risk by default?
  3. Is human approval for material actions practical for high-volume agents?