Skip to content
Review Open access

An Action-Centric Zero Trust Maturity Model for Agentic AI Environments

Aug 2026 · Italian National Conference on Sensors · Vol 26, pp. 5205 · 0 citations · 40 references
Medicine

TL;DR

Results show that AI-ZTMM complements the CISA ZTMM by providing action-level security controls, and extends CISA’s five-pillar structure to action-level trust evaluation.

Abstract

Large language model–based agentic AI systems can independently interpret user goals, develop plans, and interact with external tools. These capabilities introduce security concerns that extend beyond traditional access control. However, existing Zero Trust Maturity Models, such as the CISA ZTMM, mainly focus on how resources are accessed and provide limited guidance on how to evaluate actions taken after access has been granted. This paper proposes AI-ZTMM, which extends CISA’s five-pillar structure to action-level trust evaluation. The model defines forty-one security Functions based on ten threat categories and thirty-one security requirements and introduces Action Space and seven Action Risk Factors for organizational self-assessment. Its scope includes software agents and the software action layer of agents in IoT, robotic, and OT/ICS environments. The model was refined through reviews by eleven domain experts and evaluated using thirty-eight MITRE ATLAS case studies. The CISA ZTMM lacked directly relevant controls for 59.7% of the analyzed attack stages, whereas AI-ZTMM addressed 75.4% of this gap, achieving a combined direct coverage of 84.4%. These results show that AI-ZTMM complements the CISA ZTMM by providing action-level security controls.

Read PDF

Similar papers

Open access Sep 2026

Security Architecture for Agentic AI in Enterprise Cloud Environments: A Zero-Trust Framework for Secure Autonomous Systems

Agentic artificial intelligence expands the enterprise security boundary because autonomous agents can plan tasks, retain memory, invoke tools, call APIs, and initiate business actions. Authentication at session start is therefore insufficient when later actions may be influenced by untrusted content, poisoned memory,...

S. Suryawanshi · 0 citations
Conference Aug 2026

TrustTwin: World-Model-Enhanced Twins for Trustworthy AIoT Decision Making

Recent advances in large language models are pushing IoT systems toward autonomous Artificial Intelligence of Things (AIoT) paradigms, where system behavior depends on protocol semantics, internal state, interaction history, and environmental context. This creates a gap between AI-generated decisions and the behavior o...

Xiao-Yue Ma, Hua-Li Lu, Xiang-Xiang Dai et al. · 0 citations
#artificial intelligence Review Sep 2026

Trustworthy Agentic AI: Failure Modes, Mitigation Strategies, and a Lifecycle Framework for Autonomous LLM Systems

Agentic AI systems built on large language models can plan over multiple steps, use external tools, retain information in memory, and coordinate with other agents. These capabilities make them more useful than static language models, but they also introduce new security and operational risks. Untrusted content from web...

Fayeq Jeelani Syed, Rehan Ahmad, Ali Al Bataineh et al. · 0 citations
#artificial intelligence Review Sep 2026

Connecting the Dots in Agentic AI Security: A Cross-Dimensional Threat Taxonomy, Evaluation Maturity, and Open Challenges

Agentic AI extends LLM security beyond generated content to persistent state, autonomous actions, tool use, and interactions with humans and other agents. Existing threat classifications often emphasize individual dimensions, obscuring connections among entry points, affected components, and security consequences. The...

Heewon Baek, Alsharif Abuadbba, Kristen Moore et al. · 0 citations
#artificial intelligence Preprint Sep 2026

AI-GRACE: A Use-Case Operationalization Framework for Agentic AI: From Organizational Objectives and Obligations to Deployment Capabilities and Architecture

Organizations deploying agentic artificial intelligence must determine more than whether a model is trustworthy; they must establish what to validate, control, and observe for a use case to deliver its intended outcome while meeting applicable obligations. This paper proposes AI-GRACE (Agentic Intelligence-Governance,...

John Cuneo, David Chun, Gaurav Khanna · 1 citation
Preprint Aug 2026

Bounded Agents: Delegation Security for Multi-Agent AI Systems

The compromised-model evaluation tests APC independently of model behavior by inserting the ground-truth attack call after the first legitimate tool call, which proves Blast Radius Monotonicity and Composition Soundness for APC implementations and proves Blast Radius Monotonicity and Composition Soundness for APC imple...

Xabier Muruaga · 6 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.