Agentic AI security: why legacy controls fail AI agents
Almost no employee would take your customers’ unencrypted PII and email it to their uncle. They have common sense, and they know better.
But a hyper-focused, goal-oriented AI agent? It doesn’t have human boundaries; it only has an objective. If you tell it to “optimize this user-churn report,” it isn’t thinking about data-privacy compliance. If it gets stuck, it might reason: why not email this entire raw dataset to an external expert statistician, or feed it into an unvetted public tool, to help make sense of the data?
No malice involved. Just an agent treating your security boundaries as obstacles to be solved on the way to fulfilling its prompt.
Legacy controls were built for humans, not agents
This is the reality of the agentic shift. Legacy security controls are breaking because they were built for humans, not agents. Right now the agent and MCP-server layers have mechanical control at best — nothing reads the combination. And banning AI isn’t a strategy either — it just pushes this behavior underground.
The gap isn’t a missing control. The controls you have were built for humans, not agents.
We need a security architecture that scales with the reality of how agents reason.
Intent-Based Policy
At DTwo, we believe the solution is Intent-Based Policy: a model designed to close the gap between what organizations actually mean and what their controls enforce.
Instead of playing whack-a-mole — continuously changing mechanical parameters or blocking specific API endpoints — Intent-Based Policy states the policy directly as the outcome. It uses the exact, durable language that regulation and board policy already use (“don’t exfiltrate customer data”), which stays true even when tool names and APIs change.
- It evaluates admin intent, user intent, agent intent, and resource intent in parallel on every agent-mediated action, catching the failures that surface only in combination.
- It sits above your identity, DLP, and SIEM layers, governing the ambiguous middle ground that mechanical rules simply cannot reach.
- It’s a dial, not a switch: move incrementally from observation mode toward enforcement (open → notify-and-log → confirm → closed) as your system matures.
We lay out the full architectural framework in Intent-Based Policies for AI.
Say “yes, with constraints” — and mean it
The goal is to confidently say yes, with constraints to enterprise AI adoption — and actually mean it.
We’re looking for security and platform leaders to join us as design partners: early access to the framework, a hand in shaping the product roadmap, and a chance to pilot these guardrails within your own architecture. To talk through what this looks like for you, reach us at connect@dtwo.ai.