New Research: Runtime Authority-Aware Threat Modeling for Agentic AI Systems
The AI Runtime Threat Matrix: A Threat Taxonomy and Control Framework for Autonomous AI Agent Systems
Ravindra Annam
Technical Report · Version 1.0 · 2026
DOI: 10.5281/zenodo.22063227
The AI Runtime Threat Matrix is a structured threat taxonomy and control framework for analyzing security risks across autonomous AI agent systems. The framework organizes runtime threats across identity, authorization and permissions, prompts and context, memory, tools and APIs, data flows, external systems, multi-agent interactions, autonomous execution, human oversight, monitoring, and governance.
The report also introduces the RAAI runtime control loop — Assess, Analyze, Authorize, Act, and Audit — for evaluating agent actions at execution time rather than relying solely on static access controls.
Research Identifiers
Author: Ravindra Annam
ORCID: 0009-0002-0986-1184
DOI: 10.5281/zenodo.22063227
Publisher: Zenodo
Version: 1.0
Publication year: 2026
Resource type: Technical Report
License: Creative Commons Attribution 4.0 International (CC BY 4.0)
Research Discovery & Profiles:
Zenodo | DataCite | OpenAIRE | ORCID | ResearchGate
Keywords: Agentic AI; AI Security; Autonomous AI Agents; Runtime Security; Threat Modeling; Runtime Authorization; Authority Escalation; Prompt Injection; Memory Poisoning; Tool Security; MCP Security; Multi-Agent Systems; AI Agent Security; Cybersecurity
Recommended citation
Annam, R. (2026). The AI Runtime Threat Matrix: A Threat Taxonomy and Control Framework for Autonomous AI Agent Systems (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22063227