New Research: Runtime Authority-Aware Threat Modeling for Agentic AI Systems
A Framework for Intent, Tool, Memory, and Delegation Risk
Ravindra Annam | Journal of Recent Trends in Computer Science and Engineering | Vol. 14, No. 4 | 2026
About the Research
As AI systems evolve from generating information to autonomously executing actions, conventional threat modeling can leave critical runtime risks implicit. This research introduces the Authority-Aware Agentic Threat Model (AATM), a structured threat-modeling approach for analyzing how intent, context, authority, tool capability, memory, delegation, and action composition interact in agentic AI systems.
AATM introduces three practical security abstractions — authority surface, influence flow, and authority graph — to help security architects identify task-authority mismatch, transitive privilege, persistent influence, and sequence-dependent risks in autonomous AI workflows.
Key Contributions
Agent Authority Surface — models the authority available to an AI agent during execution.
Seven-Dimensional AATM Model — Intent, Context, Authority, Tool Capability, Memory, Delegation, and Action Composition.
Influence & Authority Flows — exposes paths through which untrusted information can influence privileged actions.
Runtime Authorization — emphasizes independent authorization of consequential agent actions.
Enterprise Case Study — demonstrates how AATM changes concrete security architecture decisions.
Cite This Research
Annam, R. (2026). Runtime Authority-Aware Threat Modeling for Agentic AI Systems: A Framework for Intent, Tool, Memory, and Delegation Risk. Journal of Recent Trends in Computer Science and Engineering, 14(4), 10–26.
Research Areas
Agentic AI Security • AI Agents • Threat Modeling • Runtime Security • Prompt Injection • Authorization • Tool Security • Memory Poisoning • Multi-Agent Systems • Least Privilege