Join our Newsletter — 33% off our NHI Course

Agentic AI Taxonomy

A classification scheme that separates AI agents by how they interact, where they run and whose authority they use. In identity security, taxonomy matters because those variables determine which credentials, trust boundaries and approval flows are appropriate for the agent’s actual operating model.

What an Agentic AI Taxonomy Separates

An agentic ai taxonomy is most useful when it distinguishes agents by operating model, not by branding. The practical differences are whether the system is acting directly, on behalf of a person, or through delegated authority, because those choices change who or what should be trusted, approved, and monitored.

That distinction matters because taxonomy is not just a naming exercise. A chatbot, an autonomous workflow agent, and a browser-driving agent may all use the same model family, but their security posture differs sharply once they can invoke tools, carry sessions, or act across trust boundaries. NHIMG’s AI Agents vs Agentic AI helps set that baseline.

Why Taxonomy Changes the Security Model

The taxonomy changes which controls are appropriate because the agent’s authority model determines the blast radius of a mistake or compromise. If an agent is merely assistive, the main concern may be output quality; if it can execute actions, the concern shifts to authorization, delegation, and containment.

That is why taxonomy should capture where the agent runs, what identities it uses, and whether it can inherit human credentials or operate with its own. NHIMG’s Agentic AI Identity Guide explains the identity lifecycle, while AI Agent Authorisation Guide shows why per-action authorization is different from broad user-level access.

Taxonomies also help prevent category drift, where an organisation treats every “agent” the same and accidentally grants too much trust to the most capable one. A browser automation agent, a coding agent, and a payment-facing agent may all be agentic, but they should not share the same approval flow or credential model.

Common Categories and the Boundaries Between Them

A useful taxonomy usually separates agents along a few axes: degree of autonomy, execution environment, scope of action, and authority source. These categories are practical because they map to concrete control decisions, such as whether the agent can call tools, whether it can retain state, and whether it can act across applications or tenants.

  • Assistive agents support a user but do not independently execute sensitive actions.
  • Delegated agents act with explicit authority from a person or service and need tightly scoped approval.
  • Autonomous agents decide and act within policy boundaries, which increases the need for containment and monitoring.
  • Environment-specific agents are constrained by where they run, such as a browser, desktop, IDE, or cloud workflow.

Those boundaries are not academic. NHIMG’s Browser and Computer-Use Agent Security Guide is a good example of how session scope, site scope, and confirmation prompts become part of the taxonomy itself when the agent can operate inside a signed-in user context.

How Taxonomy Supports Governance, Control Design and Review

For practitioners, the value of a taxonomy is that it creates a shared language for governance. If the organisation can classify an agent consistently, it can decide who owns it, what approvals it needs, what evidence must be logged, and when it should be retired or reclassified.

A taxonomy also helps reviewers ask the right questions: is the agent using a human session, a service credential, or a dedicated agent identity; does it have standing access or just-in-time authority; and does its runtime behavior match the approved class? NHIMG’s Agentic AI Compliance Guide is useful where taxonomy must feed audit evidence and policy mapping.

Risk and Threat Considerations

Agentic AI taxonomies reduce risk only if they are precise enough to reflect real authority. If organisations misclassify an agent, they may grant persistent access, over-trust shared sessions, or fail to notice that a supposedly assistive system can now perform actions on its own.

Failure mechanism: The common failure is category collapse, where different agent types are treated as one and the security model defaults to the most permissive operating pattern. That can expose credentials, weaken trust boundaries, and make delegated actions hard to attribute.

Impact: Once an agent is over-classified or under-classified, the result can be excessive privilege, unsafe tool access, mistaken approvals, or a compromised operating model that spreads across multiple workflows. NHIMG’s Zero Trust for AI Agents and Top 10 Agentic AI Identity Issues both show why standing trust is the wrong default for agent classes that can act.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Agentic AI Top 10 ASI03 — Identity & Privilege Abuse Agent taxonomies hinge on authority, delegation, and access scope.
ASI02 — Tool Misuse Taxonomy should distinguish agents by tool reach and execution capability.
Recommendation — Classify each agent by authority source and enforce the narrowest usable privilege. Restrict tools by agent class and validate each action before execution.
NIST SP 800-53 Rev 5 IA-9 — Service Identification and Authentication Agent classes often differ by whether they authenticate as services or delegated actors.
AC-6 — Least Privilege Taxonomy determines what access each agent class should receive.
IA-5 — Authenticator Management Agent classes depend on distinct credential and secret handling patterns.
Recommendation — Apply service authentication controls that match the agent’s operating identity. Grant each agent only the access required for its classified operating model. Manage agent credentials by class and rotate or revoke them according to lifecycle.
NIST Zero Trust (SP 800-207) 3 — Continuous Diagnostics and Mitigation Agent taxonomy supports continuous verification and dynamic trust decisions.
Recommendation — Continuously verify agent posture before allowing sensitive actions.
NIST SP 800-63 6 — Authenticator Assurance Where an agent acts on behalf of a person, assurance level affects the trust model.
Recommendation — Match delegated agent flows to the required authenticator assurance and proofing level.

Practitioner Guidance

Governance implication: Treat the taxonomy as a control input, not a documentation artifact. The class assigned to an agent should determine its identity model, its approval path, and the review cadence for its permissions and retirement.

A practical taxonomy should be specific enough that two reviewers would reach the same conclusion about authority and scope. If the class cannot tell you whether the agent acts for a human, for itself, or for a workload, then it is not sharp enough to support access decisions. NHIMG’s Agentic AI Security Guide is a useful companion when turning taxonomy into actual guardrails.