TL;DR: Agentic AI introduces memory, tool use, and execution paths that make stateless prompt inspection insufficient, while Lasso Security says its Intent Security framework evaluates behaviour across sequences of decisions, with risky actions blocked in under 50 milliseconds and detection accuracy improved by up to 80 percent. The core issue is that existing controls assume isolated interactions, but agentic systems create cumulative behavioural risk that must be governed over time.
At a glance
What this is: This is a Lasso Security analysis of why agentic AI needs behavioural baselining and intent validation instead of stateless prompt-by-prompt inspection.
Why it matters: It matters because IAM, IGA, and NHI teams need controls that govern decision chains, tool use, and scope drift, not just individual requests.
Context
Agentic AI changes the security problem from isolated prompts to sequences of decisions that can drift over time. Traditional controls were designed to inspect a single interaction at a point in time, which is enough for chatbot-style use but not for systems that remember context, choose tools, and execute actions across multiple steps.
That gap matters for identity governance because the control objective shifts from reviewing one request to validating behavioural continuity. When an agent can accumulate intent, combine tools, and adjust execution based on prior outcomes, the security question becomes whether the broader trajectory still matches the authorised mission.
Lasso Security frames this as a move from stateless inspection to behavioural baselining. The article is less about one product feature than about the governance assumption that current AI controls can keep up with agentic systems without state, continuity, or mission-aware evaluation.
Key questions
Q: What breaks when agentic AI is governed only with static policies?
A: Static policies assume the actor, context, and purpose stay stable long enough for review. Agentic AI can change actions inside a live workflow, so governance has to follow execution, not just deployment. Without runtime control, ownership and traceability appear only after the agent has already affected business systems.
Q: Why do agentic AI systems need behavioural baselines instead of prompt filters?
A: Prompt filters only judge the current message, while behavioural baselines compare actions against expected patterns over time. That matters when agents use memory, tools, and execution paths to reach an outcome through several permissible steps. The baseline lets teams spot scope expansion and indirect steering before harm is committed.
Q: What are the signs that an agent has drifted outside its intended scope?
A: Common signs include repeated attempts to reach restricted resources, unusual sequencing of tools, requests that expand beyond the original task, and behavior that bypasses normal review points. A more subtle signal is when the agent keeps making progress by exploring paths the operator did not authorize. Teams should watch the entire trajectory, not just isolated tool calls.
Q: How should teams decide where to enforce controls in agentic workflows?
A: Teams should enforce controls at the point where actions become real, such as tool invocation, API calls, or delegated execution, because that is where impact is created. If enforcement only happens after logging or review, the agent may already have crossed the line. The right test is whether the control can stop the action before it lands.
Technical breakdown
Why stateless inspection fails for agentic AI
Stateless inspection looks at prompts or outputs in isolation. That works when each interaction is self-contained, but agentic systems break that model by carrying memory, intermediate goals, and tool choices forward across turns. A single step can look compliant while the plan as a whole drifts outside scope. The security problem is therefore not just malicious output, but cumulative trajectory. This is why prompt filtering alone cannot explain whether the system stayed within its authorised purpose, especially once external inputs and retrieved content start shaping later decisions.
Practical implication: assess the full decision path, not just the latest prompt or response.
How behavioural baselining adds continuity to agentic controls
Behavioural baselining combines intent validation with historical context. First, it checks whether the current action matches the stated objective in the present interaction. Then it compares the agent’s behaviour against expected patterns across sessions, users, and applications. That gives security teams a way to detect scope expansion, deviation, and indirect steering before a harmful action is committed. In practice, this is a stateful control layer, not a point-in-time filter, because it must understand how goals, actions, and authority evolve over time.
Practical implication: define normal behaviour for each agent and compare new actions against that baseline continuously.
Why real-time enforcement becomes part of identity governance
Agentic systems operate in the action layer, not just the information layer. They call APIs, interact with other agents, and can commit changes before a human sees the full context. That means governance has to intervene at execution time, not only at review time. The article’s emphasis on machine-speed blocking and session-level analysis reflects a broader shift in identity security: the control point moves closer to authorisation and away from after-the-fact audit. For IAM and NHI teams, this changes how trust is measured and where enforcement must sit.
Practical implication: place enforcement where tool use and execution occur, not only where activity is logged.
NHI Mgmt Group analysis
Stateless AI controls are already misaligned with agentic behaviour. The article correctly exposes a structural mismatch: controls built for isolated prompts cannot govern systems that remember context, chain actions, and adapt mid-execution. That is not a tuning issue, it is a category error. For practitioners, the lesson is that security models designed for single-turn AI do not survive multi-step autonomy.
Behavioural baselining is the right identity primitive for agentic systems. Once an agent can choose intermediate steps and revise its plan, the relevant governance question becomes whether its behaviour remains consistent with mission and scope over time. That pushes identity security away from output inspection and toward trajectory validation. The practical conclusion is that continuity, not just content, becomes the control surface.
Intent validation closes a gap that traditional DLP and guardrails leave open. Data-focused controls can miss an agent that follows the workflow while still drifting toward an unauthorised objective. The article’s strongest contribution is showing that compliance with individual steps does not prove safe execution. Practitioners should treat intent alignment as a separate control plane, not as a feature of content filtering.
Machine-speed enforcement is now a governance requirement, not an optimisation. If a risky action can be committed before review, the governance model has already failed. The point of low-latency blocking is not performance vanity, it is containment before execution crosses the threshold into impact. Identity teams should re-evaluate whether their current approval and review cycles are even timed for agentic execution.
Statefulness is the named concept that should anchor this category. The article shows that agentic AI risk is not just behavioural, it is stateful. Once state, memory, and tool use interact across sessions, every decision is informed by prior context and every deviation compounds. That means practitioners must redesign control boundaries around continuity, because the old assumption that each interaction is independent no longer holds.
From our research library:
- A May 2025 Gartner poll of 147 CIOs and IT leaders found that 24% had already deployed AI agents, 50% were experimenting and 17% planned to deploy by the end of 2026.
- Read next: Agentic AI Identity Maturity Model
What this signals
Stateful identity controls will become the default requirement for agentic AI. Security programmes that still treat prompts as discrete events will struggle as agents accumulate context, use tools, and act across sessions. Teams should expect governance to move from content inspection to continuity checks, where behaviour is judged over time rather than in a single exchange.
Intent drift is the operational signal most programmes are not yet measuring. If an agent can follow each step correctly while the overall objective changes, the control failure is invisible to traditional guardrails. That is why behavioural baselining should sit alongside authorisation and logging, not after them.
69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey. That view reflects a broader shift from output-centric AI controls to mission-centric governance, where identity and execution are evaluated together.
For practitioners
- Map agentic workflows to decision chains Identify where an agent carries context across turns, calls tools, or alters execution based on prior results. Those paths need governance that evaluates the whole sequence, not isolated events.
- Define behavioural baselines for each agent Set expected patterns for goals, tool use, authority, and scope so deviations can be detected against a known profile rather than a generic policy rule.
- Place controls at execution time Use enforcement points that can block, mask, or escalate before an agent commits an action, especially where API calls or delegated actions can create irreversible impact.
- Review stateless guardrails for scope drift Test whether current prompt filters, content policies, and DLP rules can detect incremental deviation across multiple steps, or only obvious violations in a single turn.
Key takeaways
- Agentic AI changes the security problem from single-event inspection to cumulative behavioural governance across sessions and tool use.
- The article argues that behavioural baselining and intent validation are needed because stateless controls cannot detect scope drift early enough.
- For practitioners, the control question is no longer only what the agent said, but whether its full decision chain stayed inside authorised mission boundaries.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI01 — Agent Goal Hijack | The article centres on goal drift and intent steering in agentic workflows. |
| ASI02 — Tool Misuse | The post focuses on agents calling tools and APIs as part of the risk surface. | |
| ASI03 — Identity & Privilege Abuse | Behavioural baselining is used to govern authority, scope, and execution decisions. | |
| Recommendation — Apply ASI01 to detect when agent objectives diverge from the authorised mission. Map tool invocation paths to ASI02 and restrict actions to approved tool boundaries. Use ASI03 to validate that agent actions stay within assigned privilege and scope. | ||
| NIST AI RMF | MEASURE — AI Measurement and Analysis | The article emphasises behavioural monitoring, deviation detection, and control effectiveness. |
| Recommendation — Measure agent behaviour continuously and compare it against expected mission and scope. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Agent execution is governed through time-bound authorisation and access scope. |
| Recommendation — Align agent permissions with PR.AA-05 and validate access against the intended task scope. | ||
Key terms
- Stateless Inspection: A security approach that evaluates each AI prompt, response, or action on its own, without carrying forward prior context. In agentic systems, this is limited because the risk often emerges across a sequence of decisions rather than in one isolated exchange.
- Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.
- Intent Alignment: A control concept that checks whether an agent is still acting within the task it was given. For autonomous coding workflows, intent alignment matters because a system can behave correctly at a technical level while still crossing a policy boundary by doing more than the operator intended.
- Stateful Security Testing: Stateful security testing evaluates how an application behaves across multiple requests, identities, and workflow transitions. It is especially useful for finding flaws that only appear after the tester changes session, role, or object ownership during a realistic user journey.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org