[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-F_T5mDkAENrfmtinWVeguy-g34z-BEh4hADsOpdTq4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"c215d5dd-d20c-47a4-9e0e-9b71ddf79d37","custody-framework-aims-to-rein-in-ai-agents-on-enterprise-networks","7d949664-565a-4f32-bf28-03eccd0c61cd","CUSTODY Framework Aims to Rein In AI Agents on Enterprise Networks","As AI agents become increasingly embedded in enterprise environments, they introduce novel attack surfaces that traditional security controls were not designed to address. The attacks targeting Hugging Face demonstrated that AI systems with broad network access and autonomous capabilities can be compromised or manipulated to act as powerful internal threats. Without explicit constraints on what AI agents can access, execute, or exfiltrate, organizations effectively grant unchecked privilege to systems that may be vulnerable or adversarially influenced. The CUSTODY framework addresses this gap by applying least-privilege and containment principles specifically tailored to agentic AI behavior. This matters because the blast radius of a compromised AI agent can far exceed that of a compromised human account due to its speed, scale, and automation.","**Immediate actions:**\n- Audit all deployed AI agents to inventory their current network access, permissions, and data touchpoints.\n- Apply least-privilege principles to AI agent service accounts, restricting them to only the resources required for their specific tasks.\n\n**Long-term improvements:**\n- Adopt or adapt a structured AI containment framework (such as CUSTODY) to define and enforce behavioral boundaries for all agentic AI systems.\n- Implement network segmentation to isolate AI agent workloads from sensitive systems and lateral movement paths.\n- Establish a formal AI agent lifecycle policy covering deployment approval, permission reviews, and decommissioning procedures.\n\n**Detection measures:**\n- Deploy behavioral monitoring and anomaly detection specifically tuned to AI agent activity, flagging unexpected API calls or data access patterns.\n- Integrate AI agent logs into your SIEM to enable correlation of agent actions with broader threat detection workflows.\n- Conduct regular red-team exercises simulating adversarial manipulation of AI agents to test containment effectiveness.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 3: Data Protection","CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 6: Access Control Management","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST AC-2: Account Management","NIST AC-6: Least Privilege","NIST SC-7: Boundary Protection","NIST SI-3: Malicious Code Protection","NIST AI RMF: GOVERN 1.1 – Policies for AI Risk Management","NIST AI RMF: MAP 1.5 – AI System Boundaries and Context","ISO\u002FIEC 42001: AI Management System Standard","MITRE ATLAS: Tactic – ML Model Access","GDPR Article 25: Data Protection by Design and by Default","published","2026-08-20T22:20:36.185866+00:00","2026-08-20T22:20:35.928+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fwww.darkreading.com\u002Fperimeter\u002Fnew-custody-framework-constrains-ai-agents-inside-network","new-custody-framework-constrains-ai-agents-inside-the-network-0c1b8a","New CUSTODY Framework Constrains AI Agents Inside the Network",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":41,"name":42,"slug":43,"description":44,"color":45},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":47,"name":48,"slug":49,"description":50,"color":51},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]