When an AI Agent Escapes Containment, the First Question Is 'Who Authorized It?'

NIST's AI Agent Standards Initiative names identity and authorization as core problems, and the agent-specific control overlays are not finished. Defense deployers cannot wait for the standard to answer who authorized an autonomous action.

By Containment.ai Research  ·  Published August 3, 2026  ·  Product status: Trust page →
One control plane, three moments of risk. The same deterministic discipline governs three boundaries: the human prompt (AI Chat Firewall, between an employee and the AI provider), the agent action (Agent Governance, between an agent and a tool or system), and the mission boundary (Mission Authorization Gateway, between an AI system and an edge, domain, or OT environment). All three run intercept, canonicalize, evaluate, enforce, audit.
FIG. A — ONE ENFORCEMENT LAYER, THREE MOMENTS OF RISKCONTAINMENT.AI

NIST does not usually editorialize, so it is worth reading its own words about where autonomous AI agents stand today. In February 2026, the Center for AI Standards and Innovation (CAISI) at NIST announced the AI Agent Standards Initiative and observed that "AI agents can now work autonomously for hours, write and debug code, manage emails and calendars, and shop for goods." In the same breath, it named the constraint that turns that capability into a governance problem: an agent's real-world utility is "constrained by their ability to interact with external systems and internal data."

That sentence is the whole story behind the recent wave of reporting about agents slipping the boundaries meant to contain them. An autonomous agent is only useful because it reaches across a boundary — into a repository, a database, a partner system, a mission enclave — and acts. When one of those actions lands somewhere it should not, the first forensic question is not "what did the model say?" It is "who authorized this action, and can we prove it?"

For most deployments running today, there is no clean answer.

An agent is not a user, but your controls think it is

Enterprise and federal security programs are built around a simple assumption: an actor is either a human with an identity or a system with a service account. An autonomous agent is neither. It acts on behalf of a human principal, but it makes its own sequence of decisions, calls its own tools, and touches data the original human may never have seen. Strip away the novelty and the governance problem is old and specific — identity, authorization, and attribution:

  • Identity — can you distinguish this agent's actions from the human it acts for, and from every other agent?
  • Authorization — was this specific action, against this specific system, permitted for this principal at this moment?
  • Attribution — after the fact, can you produce non-repudiable evidence of who authorized what, in an order an auditor or an investigator will accept?

NIST has put exactly these questions at the center of its agenda. One of the three pillars of the AI Agent Standards Initiative is "advancing research in areas of AI agent security and identity to enable new use cases and to promote trusted adoption." Alongside it, CAISI opened a Request for Information on AI Agent Security (comments due March 9) and pointed to an AI Agent Identity and Authorization concept paper (comments due April 2). The government is telling you where the gaps are.

The answer is coming — on a standards clock

The hard part is timing. The controls that will eventually make this concrete are still being written. NIST's Control Overlays for Securing AI Systems (COSAiS) project "will develop a series of overlays for securing AI systems using the NIST Special Publication (SP) 800-53 controls." Two of its five proposed use cases are squarely about agents — "Using AI Agent Systems (AI Agents) – Single Agent" and "Using AI Agent Systems (AI Agents) – Multi-Agent."

But proposed is the operative word. As of the January 8, 2026 update, the only overlay with a published annotated outline is the one for "Using and Fine-Tuning Predictive AI." The single-agent and multi-agent overlays — the ones a defense program actually needs to govern an autonomous system reaching across a classified boundary — remain use cases on a roadmap, not draft controls you can cite in a System Security Plan. The identity and authorization work is at the concept-paper stage. Sector-specific listening sessions began in April.

This is not a criticism of NIST; standards should be deliberate. It is a description of the gap defense deployers are standing in right now: the agents are already autonomous, already touching internal data, already crossing boundaries — and the standard that will tell you how to govern them is a year or more from being enforceable.

For defense, the boundary is the control you can enforce today

You cannot pause an agent program until the standards land, and you cannot govern an autonomous action after it has already crossed the wire. The one place a defense program can put a hard, enforceable control today is the same place the agent's risk lives: the boundary — the moment an agent tries to move data or take an action across it.

That is the design premise of the Containment.AI Mission Authorization Gateway. Rather than asking a probabilistic model to police itself, the gateway evaluates every agent action routed through it against explicit policy and returns a deterministic decision — permit, modify, deny, or defer — tied to a named principal. Every decision emits a signed, tamper-evident receipt: a non-repudiable record of who authorized what, against which policy, at what time. That is precisely the identity–authorization–attribution triad NIST is building standards around, expressed as a control designed for the edge — architected for disconnected and degraded operation, without shipping sensitive data to a third party to make the call. Current deployment modes and their status are on Trust.

It is worth being precise about what that is and is not. A boundary gateway does not replace the forthcoming NIST overlays; it is the enforcement point that will implement them when they land, and the interim control while they are still drafts. It is designed to meet FedRAMP- and IL-context deployment postures, not a claim of a completed authorization — the gateway's job is to produce the tamper-evident decision record and deterministic enforcement those processes ask for.

What to require of an agent program now

While NIST finishes the rulebook, a defense program can hold its own deployments to the questions the rulebook will ask:

  1. Principal binding. Every agent action the gateway evaluates is attributable to a specific human or service principal — not to a shared key or a generic "AI" account.
  2. Per-action authorization. Each cross-boundary action is checked against policy at the moment it happens, not assumed safe because the session started safe.
  3. Deterministic enforcement. The decision to permit or deny is made by an evaluator that behaves the same way every time — not by the model whose behavior you are trying to contain.
  4. Non-repudiable evidence. Every decision produces a signed record you can hand to an auditor or an incident investigator, in order, without reconstruction.
  5. Edge-resident. The control works where the mission is — disconnected, on-prem, air-gapped — because that is where forward-deployed agents actually run.

When an agent escapes its intended boundary, the organizations that can answer "who authorized it?" in seconds — with a signed receipt, not a reconstructed guess — are the ones that were governing at the boundary all along. NIST is writing that expectation into the standard. Defense does not have to wait for it to start enforcing it.


Containment.AI builds deterministic, signed-receipt governance for forward-deployed AI in safety- and security-critical environments. See the platform overview for how the Mission Authorization Gateway enforces policy at the boundary.

READY TO CLOSE THE GAP?
Deterministic AI governance for regulated and mission environments.
Request a 30-minute Boundary Review → Apply to the Design Partner Program → Keep controlled data out of public AI →