Intent Is The New Epicenter Of Agentic Security
Cybersecurity spent decades trying to stop things from happening, identifying them, and then investigating what happened. Agentic AI challenges us with a much more difficult question:
What was the system trying to do?
Agents don’t just execute instructions. They interpret objectives, select tools, access data, cross systems, and change tactics.
In most cases, a user hints at a destination. The agent chooses the route. Even that isn’t true in the most sophisticated multi-agent systems which creep closer and closer to autonomy.
That destroys one of our foundational assumptions in cybersecurity:
If the outcome is bad, trace the actions back to users.
In the old world that made sense, because users could reason, applications and infrastructure could not. Today, agents reason. Users no longer decide every action.
Intent tells you whether an agent should have acted at all.
Traditional Controls See Actions But They Miss Purpose
Let’s clear one thing up that you’ll sometimes see out there about intent:
A prompt is not intent.
Imagine that written 35 times in a row, bolded, and underlined. We didn’t have to imagine it because we actually did it. Then our editor removed it.
Instead, our definition of agentic intent is:
Agentic intent is the relationship between an assigned objective, its constraints, and the action path an agent selects over time. An agent can follow its task, reach its destination, and violate policy at every turn along the way.
In our analysis of how an OpenAI evaluation became Hugging Face’s security incident, models pursued an assigned benchmark objective, escaped a constrained environment, reached the internet, and compromised another company’s production infrastructure while searching for answers. The intent was not to hack a company. It was to satisfy its objectives.
Prompt inspection won’t solve this. Neither will guardrails. Security teams need to evaluate goals, delegation, reasoning, tool calls, data movement, state changes, and outcomes to understand intent.
The reasoning trace is the new stack trace.
For the first time, security leaders might have to decide between initiating an incident response procedure to investigate an incident OR creating a Jira ticket to correct behavior. We’ve never confronted a choice like that before. But it’s here now.
Intent Is A Stack, Not A Prompt
Intent exists across five layers:
-
- Maker intent: What was the agent designed to do?
- Organizational intent: Why did the enterprise deploy it?
- Role intent: What should this user or function be allowed to request?
- User intent: What is the person trying to accomplish?
- Agent intent: What action path did the agent select?
Any layer can diverge. That divergence can produce useful emergent behaviors, act as expected to provide engineered benefits, accidental harm, or purposeful harm.
It can also expose how much of the control stack enterprises don’t operate. Our analysis of how Fable 5 and Mythos 5 change AI security, data retention, and vendor risk showed that provider safeguards have become enterprise security dependencies. Our follow-up analysis of Fable 5 and Mythos 5 showed what happens when access to that dependency disappears.
AEGIS Established The Foundation; Securing Intent Reinforces It
We introduced AEGIS, the guardrails CISOs need for the agentic enterprise because traditional security architectures were not designed for autonomous systems with persistent goals and adaptable action paths. One of the pillars – least agency – is now a fundamental building block of agentic design.
Now, we are establishing intent as a security domain and giving CISOs a framework to understand, classify, and secure it.
The approach helps security leaders:
-
- Separate task adherence from goal adherence.
- Evaluate evidence across five layers of intent.
- Distinguish helpful emergence from accidental or purposeful harm.
- Apply proportionate controls and response based on intent awareness.
- Build identity, monitoring, governance, and adaptive protection around agent behavior.
The point is not to create another framework for the shelf. Instead, we want to help security leaders create what cybersecurity will need next to operate in the agentic enterprise. Part of that includes recognizing the benefits and limitations of existing regulatory frameworks that many AI governance and compliance efforts are built on. Today, there is an intent gap.
Agentic Security Will Rise Or Fall On Intent
Agentic systems will take paths nobody explicitly programmed and make decisions no user directly approved. Security teams cannot govern that future by inspecting isolated prompts or waiting for harmful outcomes. They must secure the relationship between objectives, constraints, and actions.
Forrester clients can read the full report for key actions to take, how to design operations for securing intent, and adapt response actions based on intent classification.
Connect With Us
Forrester clients with questions related to this research can connect with us through an inquiry or guidance session.