Subscribe to the Non-Human & AI Identity Journal
Home FAQ Cyber Security What breaks when a PRD is treated as…
Cyber Security

What breaks when a PRD is treated as a one-time planning document?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 2, 2026 Domain: Cyber Security

The implementation trail breaks. AI-assisted work changes as the agent learns from tests, logs, and phase-by-phase decisions, so an outdated PRD quickly stops matching the actual system. That creates review confusion, weak auditability, and hidden drift between intent and delivery.

Why This Matters for Security Teams

A PRD that is treated as a single handoff artifact becomes a control gap once AI-assisted delivery starts changing behaviour during testing, review, and integration. Security, product, and engineering teams then argue from different versions of “the plan,” which weakens change traceability and makes it harder to prove why a system ended up with a given access pattern, data flow, or guardrail. That is especially risky when autonomous agents can modify workflows, call tools, or influence downstream decisions.

Current guidance suggests treating requirements as living security artefacts, not static project paperwork. That aligns with the NIST Cybersecurity Framework 2.0 emphasis on governance, risk treatment, and continuous improvement. For AI-enabled delivery, the issue is not only whether the original PRD was sound, but whether each material change was re-approved, logged, and mapped back to the intended controls. Without that discipline, audit evidence becomes fragmented and review committees end up validating the latest build rather than the intended design.

In practice, many security teams encounter the mismatch only after a production review, incident, or compliance request has already exposed the drift.

How It Works in Practice

A PRD should be treated as a control anchor that is updated as the system changes, not as a frozen design note. For AI-assisted work, that means the document must capture not just features and acceptance criteria, but also model dependencies, tool permissions, human approval points, logging expectations, and constraints on data use. When the agent’s behaviour changes after prompt tuning, retrieval updates, or test feedback, the PRD should be revised in step with the implementation trail.

Practically, this works best when the PRD is paired with version control, change tickets, and decision records. Each material change should answer three questions: what changed, why it changed, and which risk or control it affected. Teams often map this to governance checkpoints in NIST Cybersecurity Framework 2.0, then add AI-specific review for prompt logic, training data sources, and output validation. If agentic tools are involved, the PRD should also specify whether the agent can act independently, which systems it can reach, and what conditions require human approval.

A simple operational pattern is:

  • Baseline the PRD before build work begins.
  • Update it when tests, logs, or reviews change the implementation.
  • Link every material delta to a ticket, risk decision, or approval.
  • Keep security controls tied to current behaviour, not original intent.

This approach improves auditability because reviewers can trace the final system back through documented decisions rather than reconstructing intent from stale prose. It also helps identify when a feature request has become a policy exception, which is where many governance failures begin. These controls tend to break down in fast-moving teams that ship directly from chat-based specifications into production because there is no stable change record to reconcile against the live system.

Common Variations and Edge Cases

Tighter documentation discipline often increases delivery overhead, requiring organisations to balance speed against traceability. That tradeoff is real, especially in teams using agile, product-led, or experimentation-heavy workflows. Current guidance suggests avoiding heavyweight approvals for every minor edit, because that can stall delivery and encourage shadow changes outside the documented process.

The right approach depends on the kind of change. Minor wording updates, UI copy changes, or low-risk prompt refinements may only need lightweight versioning. By contrast, changes that affect agent permissions, data retention, external tool access, or model behaviour should trigger a formal update cycle. Best practice is evolving here, but the underlying rule is consistent: if the PRD no longer describes what is actually being built, it is no longer a reliable security reference.

Edge cases appear when multiple teams share the same PRD, when vendor tools auto-generate implementation details, or when an AI agent iterates faster than human review can keep pace. In those environments, the PRD should be supplemented with live control mappings, release notes, and approval logs. For agentic systems, the governance question is not just “what was planned?” but “which version of the plan governed the action that actually executed?”

For teams building AI-enabled products, the practical answer is to treat the PRD as a versioned control artifact, not a one-time planning document, and to keep it synchronized with implementation evidence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATLAS address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST AI 600-1 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01Living requirements support governance and documented organisational context.
NIST AI RMFGOVERNAI systems need ongoing accountability as behaviour changes through testing and tuning.
OWASP Agentic AI Top 10Agentic systems can change behaviour and tool use outside a static PRD.
MITRE ATLASModel and agent behaviour drift can emerge during iterative delivery and testing.
NIST AI 600-1GenAI systems require ongoing documentation of prompts, data, and outputs.

Keep the PRD versioned and tied to current governance decisions and risk ownership.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org