CSAIChaptersEventsBlog
Learn why hybrid environments are now the norm and how to build a security architecture that embraces this. Register for the July 1st webinar →
Open Peer Review Tag

AI Agents: Architecture and Control Plane

Open Until: 07/10/2026

AI Agents: Architecture and Control Plane
AI agents introduce architectural and security challenges that extend beyond traditional application engineering. Their autonomous operation, tool access, persistent memory, and inter-agent communication create attack surfaces that conventional application security frameworks were not designed to address. This paper presents a ten-layer reference architecture for AI agent systems, organized into three operational domains: Infrastructure, Intelligence, and Knowledge (Layers 1–3); Agency, Environment, and Execution (Layers 4–7); and Governance and Accountability (Layers 8–10). It then develops an integrated security overlay aligning the CSA Agentic Control Plane framework, the OWASP Top 10 for Agentic Applications (2026), the CSA AI Controls Matrix (AICM), and the NIST AI Agent Standards Initiative, with per-type threat models, an integrated controls matrix, a six-level security maturity model, and an operational Identify-Classify-Control-Monitor-Assure lifecycle. The reference architecture also provides the structural foundation for the CSA MAESTRO threat modeling framework. This paper is the second in a multi-part series; the foundational definitions, capability model, and taxonomy are provided in the companion paper AI Agents: Definition, Capabilities, and Taxonomy, which is assumed as background.

Contribute to Peer Review

Peer Review Agreement

By participating in this peer review, you acknowledge and agree to the following:

  • Your name will be included as a reviewer only if you provide substantive feedback (e.g., content, clarity, accuracy). Feedback limited to grammar, syntax, or formatting will not qualify for acknowledgement.
  • CSA's authors will have final discretion over which suggestions are incorporated into the document. Not all feedback will be implemented.
  • You will not plagiarize or submit unmodified AI-generated text. If using AI-generated content, you must apply your expertise to refine, reformat, or integrate it meaningfully into the document.
Peer Review Illustration

Open Until: 07/10/2026

Featured by CSA

Want to see your content featured here?

Contact us to learn more!

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.