The AI Runtime Threat Matrix: A Threat Taxonomy and Control Framework for Autonomous AI Agent Systems
Authors/Creators
Description
Autonomous AI agents introduce security risks that extend beyond traditional application and model-centric threat models. Agents can dynamically select tools, invoke APIs, access memory, interact with external systems, delegate tasks, and perform privileged actions across multi-step workflows. These capabilities create runtime attack paths in which untrusted influence can propagate into consequential actions.
This technical report introduces the AI Runtime Threat Matrix, a structured threat taxonomy and control framework for analyzing security risks across autonomous AI agent systems. The framework organizes runtime threats across identity, authorization and permissions, prompts and context, memory, tools and APIs, data flows, external systems, multi-agent interactions, autonomous execution, human oversight, monitoring, and governance.
The report also describes the RAAI runtime control loop—Assess, Analyze, Authorize, Act, and Audit—as an approach for evaluating agent actions at execution time rather than relying solely on static access controls. Worked attack scenarios demonstrate how prompt injection, memory poisoning, tool misuse, authority escalation, and cross-agent influence can propagate through agentic workflows.
Version 1.0 presents a practitioner-informed conceptual framework and threat-modeling methodology. It does not claim empirical validation; an evaluation methodology for future experimental research is outlined.
Files
AI_Runtime_Threat_Matrix_Technical_Report_v1.0.pdf
Files
(166.4 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:ca05942086591d99c4002e258ce9dbf1
|
166.4 kB | Preview Download |