AI Agents: Architecture and Control Plane
Open Until: 07/10/2026
AI agents introduce architectural and security challenges that extend beyond traditional application engineering. Their autonomous operation, tool access, persistent memory, and inter-agent communication create attack surfaces that conventional application security frameworks were not designed to address. This paper presents a ten-layer reference architecture for AI agent systems, organized into three operational domains: Infrastructure, Intelligence, and Knowledge (Layers 1–3); Agency, Environment, and Execution (Layers 4–7); and Governance and Accountability (Layers 8–10). It then develops an integrated security overlay aligning the CSA Agentic Control Plane framework, the OWASP Top 10 for Agentic Applications (2026), the CSA AI Controls Matrix (AICM), and the NIST AI Agent Standards Initiative, with per-type threat models, an integrated controls matrix, a six-level security maturity model, and an operational Identify-Classify-Control-Monitor-Assure lifecycle. The reference architecture also provides the structural foundation for the CSA MAESTRO threat modeling framework. This paper is the second in a multi-part series; the foundational definitions, capability model, and taxonomy are provided in the companion paper AI Agents: Definition, Capabilities, and Taxonomy, which is assumed as background.
Topics:



