CSAIChaptersEventsBlog
Learn why hybrid environments are now the norm and how to build a security architecture that embraces this. Register for the July 1st webinar →
Open Peer Review Tag

Agent Shared Security and Safety Responsibility Model (Agent 3SRM)

Open Until: 07/10/2026

Agent Shared Security and Safety Responsibility Model (Agent 3SRM)
As AI agents transition from experimental prototypes to production enterprise systems, the question of who is responsible for what becomes critical. The CSA AI Controls Matrix (AICM) v1.1 establishes a shared responsibility framework for AI systems, distributing 247 control objectives across five supply chain roles: Cloud Service Provider (CSP), Model Provider (MP), Orchestrated Service Provider (OSP), Application Provider (AP), and AI Customer (AIC). However, the AICM was designed for the general AI/ML service delivery model. Agentic AI systems, with their autonomous operation, sub-agent delegation, persistent memory, and cross-organizational tool use, introduce responsibility and accountability attribution challenges that extend beyond the AICM’s current scope. This paper presents the Agent Shared Security and Safety Responsibility Model (Agent SSSRM/3SRM), introduces the Agent Deployment Model and extends the AICM’s five-role value chain framework for ML/LLM and mapping it to the ten-layer AI Agent Reference Architecture defined in the companion paper. The Agent 3SRM maps the AICM’s control ownership assignments to each of the 10 layers Agentic Reference Architecture, defined in the companion paper, identifies agentic-specific responsibility gaps. Finally the paper introduces the concept of the Agent Owner as the entity that bears ultimate, non-delegable accountability for all agent actions and defines accountability chains for sub-agent delegation. The result is a practical framework that bridges the AICM’s control-level responsibility model with the architectural reality of deployed agent systems.

Contribute to Peer Review

Peer Review Agreement

By participating in this peer review, you acknowledge and agree to the following:

  • Your name will be included as a reviewer only if you provide substantive feedback (e.g., content, clarity, accuracy). Feedback limited to grammar, syntax, or formatting will not qualify for acknowledgement.
  • CSA's authors will have final discretion over which suggestions are incorporated into the document. Not all feedback will be implemented.
  • You will not plagiarize or submit unmodified AI-generated text. If using AI-generated content, you must apply your expertise to refine, reformat, or integrate it meaningfully into the document.
Peer Review Illustration

Open Until: 07/10/2026

Featured by CSA

Want to see your content featured here?

Contact us to learn more!

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.