In Part 1, we established why autonomous AI agents break traditional deterministic security controls and why you cannot “patch” or “firewall” your way out of probabilistic behavior, only become resilient.
In this part, we will look at how you can assess the maturity and readiness of your security program to be better prepared for going agentic.
If your organization is deploying agentic workflows this year, you need a realistic maturity model. Something that is grounded in the NIST AI RMF and contains the blast radius before a rogue agent impacts production.
Here is the 4-level framework to evaluate where your enterprise stands today, how to reach a defensible security posture and be prepared for issues when they occur.
4 Levels of Agentic AI Security Maturity
Level 1: Ad-Hoc (High Risk)
AI agents are being built in “the shadows” in low/no code environments. There is no IT awareness of their existence or approval for their creation. With little to no visibility, you are flying blind.
No visibility into deployed agents.
No logging or monitoring of execution or access.
No review or approval of technologies or platforms being used.
Level 2: Managed (Developing)
Light has begun to shine on AI hiding in the shadows. Some foundational governance guardrails, reviews and approval gates are in place. Visibility into what the agent actually does is being established.
Some basic (likely manual) visibility and inventory processes are beginning to take shape and being improved.
Logging and monitoring are being integrated and telemetry data evaluated.
Guardrails are being developed along with written policy to codify them.
Agentic security and observability tools are being evaluated for implementation.
Level 3: Optimized (Minimum Viable Baseline for Production)
This is where the enterprise has become resilient and practiced enough in their AI governance to begin securing their agentic and AI landscape.
Logging and Monitoring has been established and is operationalized.
Agentic security and observability tools are in place and integrated with operations and adjacent tools.
Baseline guardrails are defined and mandatory for production deployments.
Metrics and KPIs are established and actively reported to stakeholders.
Incident response processes and ‘kill-switch’ capabilities are in place.
Level 4: Advanced (Predictive & Continuous Red-Teaming)
Once steady state is achieved, we move on to operational excellence. At the Advanced level, the focus pivots to continuous improvement. Developing capabilities and process to further secure the software and AI supply-chain.
Automated and manual red-team of agentic applications.
Automated detect and respond capabilities.
Streamlined review and approval of agentic applications that conform with approved technologies and architectural patterns.
Improving the lifecycle management and documentation of agentic systems.
Mapping to the NIST AI RMF Governance Loop
To move from Level 1 to Level 3, align your architecture with the four core functions of the NIST AI Risk Management Framework:
Mind the Gap: Most teams build Discovery (MAP), Monitoring (MEASURE) and even some Runtime Controls (MANAGE) but skip Governance (GOVERN). Having data without explicit decision authority or enforcement policies isn’t security, it’s theater.
7 Questions IT Leadership
Take these seven questions to your next security review to help identify your team’s material operational gaps:
Discovery: Do we have an automated inventory of every active AI agent across our SaaS and low-code environments?
Approval: Is there an enforced governance gate before new agents get tool access?
Least Privilege: Are agent tool calls scoped strictly to the minimum permissions required?
Orchestration: Can we track how our agents interact with each other and third-party APIs?
Chain Visibility: Do we know our potential blast radius if a single downstream sub-agent is compromised?
Auditability: Can we produce compliance audit trails for agent decision sequences?
Runtime Monitoring: Can we detect and terminate agents exhibiting anomalous behavior in real time?
If you answered “No” or “Unsure” to three or more of these questions, your program is likely operating at Level 1 or Level 2.
Final Thoughts
Establishing clear, defensible boundaries, supporting processes and enforcable policies is key to becoming resilient. This is best achieved by honestly assessing your agentic maturity and charting a path to reach operational excellence using a framework like this one.




