# AI Agent Security Checklist — 24 Controls

**GCAS v0.1 — Proposed standard**
**Publisher:** Guardian Robotics
**Draft date:** September 28, 2026
**Applies to:** Frontier models, privately hosted models, and enterprise agents with access to tools or organizational data.
**Canonical page:** https://gov.guardianrobotics.com/ai-governance/ai-agent-security-checklist.html

> Autonomy must be earned, bounded, and revocable.

A concise working assessment derived from the Guardian Controlled Autonomy Standard. Use it against **one** deployment: a named use case, a specific model version, and a specific permission set.

Mark each control **Pass**, **Fail**, **Unknown**, or **Not applicable with rationale**. A control you cannot evidence is **unknown**, not a pass. Reproducible failures involving unauthorized access, tenant separation, high-impact approval bypass, or inability to stop authority should block promotion outright — a checkbox count never overrides a critical failure.

This checklist starts unassessed. Completing it is a self-assessment; it is not a certification, an audit, or evidence reviewed by Guardian Robotics.

**Full requirements, evidence expectations, and deployment gates:**
https://gov.guardianrobotics.com/ai-governance/controlled-autonomy-standard.html

---

## Evaluate models in the system where they will operate

Test the actual model, tool, and data configuration for the intended use case. A published benchmark score describes a model in isolation; it cannot tell you whether your deployment will misuse a connected tool or retrieve the wrong customer's record.

- [ ] **GCAS-01 — Assign an accountable owner.**
      Record the use case, business owner, technical owner, affected people, data classes, tools, and maximum authority before deployment.
      _Evidence:_ A dated system record and approved risk assessment.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-02 — Test the actual deployment.**
      Evaluate the model together with its prompts, retrieval, memory, connectors, and permissions against realistic tasks and adversarial inputs. Include sensitive-data disclosure, prompt injection, incorrect actions, and harmful decisions relevant to affected people.
      _Evidence:_ A versioned test suite with outcomes and unresolved failures.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-03 — Make approval specific and temporary.**
      Define measurable acceptance thresholds and a reassessment date for a named use case, model version, and permission set. Retest material changes to models, prompts, tools, memory, or access; suspend affected authority if new behavior exceeds the approved boundary.
      _Evidence:_ A release decision, recorded residual risk, expiry, and change history.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-04 — Examine provider dependencies.**
      Review applicable data handling, retention, training use, subprocessors, hosting locations, incident notification terms, and service continuity. Establish what the available assurance evidence actually covers.
      _Evidence:_ A supplier review and a documented fallback path.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

## Secure local and private models

Verify provenance, infrastructure hardening, data flows, performance, and fallback. Running inference locally is an architecture choice, not a privacy guarantee.

- [ ] **GCAS-05 — Control model provenance.**
      Record the origin, license, version, and integrity of model weights, images, libraries, and serving components. Review executable model-loading code before use.
      _Evidence:_ An artifact inventory with hashes and approval records.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-06 — Harden the inference environment.**
      Authenticate inference requests; restrict network reachability, service privileges, admin access, and resource consumption. Maintain patching and vulnerability review.
      _Evidence:_ Deployment configuration, access tests, and a maintenance owner.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-07 — Verify the data boundary.**
      Document and test outbound telemetry, logs, embeddings, backups, remote dependencies, and cloud fallback. Local inference alone does not establish that all data stays local.
      _Evidence:_ A data-flow diagram and observed network behavior under normal and failure conditions.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-08 — Maintain a qualified fallback.**
      Benchmark the selected local configuration for its authorized tasks and rehearse capacity exhaustion or model unavailability. Any fallback must have equal or narrower approved data access.
      _Evidence:_ Evaluation results, capacity limits, and a fallback exercise.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

## Give every agent limited, attributable authority

Inspect identities, tool authority, delegated access, and high-impact approvals. An agent that inherits a person's unrestricted account has no meaningful boundary and no attribution.

- [ ] **GCAS-09 — Use a distinct agent identity.**
      Attribute access to a named agent and responsible owner. Use scoped service identities rather than a person's unrestricted account or shared administrator credentials.
      _Evidence:_ Identity inventory and attributable access records.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-10 — Issue minimum necessary permissions.**
      Default to no access; separately authorize tools, actions, resources, and duration. Use short-lived credentials where supported and broker secrets outside model context.
      _Evidence:_ Permission policy and denied-access tests.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-11 — Bind approval to the action.**
      Require independent human approval for defined high-impact actions such as payments, bulk deletion, permission changes, and consequential external commitments. Bind approval to recipient, resource, parameters, time limit, and scope; changed actions need new approval.
      _Evidence:_ An approval record linked to the executed action and rejection of altered or replayed approvals.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-12 — Constrain delegation.**
      Child agents and connected tools must receive no more authority than the authorized parent task permits. Restrict delegated credentials, recursion, tool registration, and the ability to spawn more agents.
      _Evidence:_ An agent/tool dependency map and tests that delegation cannot expand privilege.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

## Restrict data access and prove isolation

Restrict retrieval, outbound data, memory, and tenant or session state. Enforce permissions before data reaches the model, and demonstrate separation with negative tests rather than assuming it.

- [ ] **GCAS-13 — Limit retrieval at the source.**
      Enforce row, document, tenant, and purpose restrictions before data reaches the model. Start with synthetic or minimized data and explicitly authorize broader use.
      _Evidence:_ Retrieval authorization tests across users and data classes.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-14 — Test tenant and session separation.**
      Isolate identities, workspaces, browser state, files, caches, queues, vector indexes, and persistent memory. Test both concurrent use and reuse after cleanup. Shared infrastructure requires demonstrated boundaries; dedicated infrastructure still requires controls.
      _Evidence:_ Cross-tenant and cross-session negative tests with synthetic markers.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-15 — Restrict outbound disclosure.**
      Apply destination allowlists, export limits, and appropriate content checks to tools, messages, uploads, and network traffic. Prevent an agent from turning a new connector into an unauthorized exit path.
      _Evidence:_ Blocked-export tests and access-controlled egress records.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-16 — Govern memory and retention.**
      Define purpose, access, retention, and deletion for prompts, outputs, logs, and persistent memory. Keep secrets out of model context where practical; verify cleanup on session termination and tenant teardown.
      _Evidence:_ Retention configuration and deletion tests, including documented backup limitations.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

## Enforce limits outside the model

Enforce independent authorization, budgets, monitoring, and revocation. A model cannot be trusted to police itself once its context contains untrusted content.

- [ ] **GCAS-17 — Put authorization at the execution boundary.**
      Use independent enforcement to check each tool action against identity, scope, resource, approval, and current policy. Untrusted content cannot authorize action. Deny new privileged actions when authorization cannot be verified.
      _Evidence:_ Bypass, stale-policy, and enforcement-outage tests.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-18 — Cap the damage a task can cause.**
      Set per-task and aggregate ceilings for spending, runtime, tool calls, concurrency, data exports, and records changed. Enforce limits across retries and child agents.
      _Evidence:_ Boundary tests showing the enforced stop condition.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-19 — Observe consequential activity.**
      Record action requests, authorization decisions, approvals, tool results, state changes, and agent identity in protected logs. Minimize sensitive content. AI may assist detection and investigation, but cannot independently grant broader access or suppress oversight.
      _Evidence:_ Traceable action records and tested alerts with a human response owner.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-20 — Stop authority independently.**
      Provide a control outside the agent's reach to revoke credentials, block egress, disable connectors, and stop scheduled, queued, in-flight where feasible, and delegated work. Stopping generation alone is insufficient.
      _Evidence:_ A timed containment drill documenting remaining irreversible effects.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

## Prepare for the worst credible failure

Rehearse cascading failures, preserve evidence, restore operations, and require an explicit restart decision. Some consequences — a message already sent, information already disclosed — cannot be restored from a backup.

- [ ] **GCAS-21 — Rehearse realistic incidents.**
      Exercise unauthorized messages, bulk deletion, exfiltration, cross-tenant exposure, malicious tools, model/provider compromise, runaway spending, and cascading agent failures. Include control-plane failure and physical consequences where agents affect equipment.
      _Evidence:_ A tabletop or sandbox drill with named responders and recorded decisions.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-22 — Preserve evidence and coordinate response.**
      Assign incident command, severity criteria, evidence handling, escalation, and notification decision owners. Contain the incident while preserving useful evidence where feasible; avoid duplicating sensitive data unnecessarily.
      _Evidence:_ An incident runbook and tested communication paths.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-23 — Restore verified business operations.**
      Maintain protected backups, recovery targets, reconciliation procedures, and a manual operating mode. Measure recovery time and data loss during exercises. External disclosures and messages require consequence management; a restore cannot undo them.
      _Evidence:_ A successful restore or reconciliation drill and a verified fallback procedure.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

- [ ] **GCAS-24 — Require evidence before restart.**
      Remove the failure path, rotate affected credentials, repair or clear compromised memory, repeat relevant evaluations, and obtain accountable human approval before restoring autonomy.
      _Evidence:_ A remediation record, regression results, and a restart decision.
      _Status:_ ______________  _Owner:_ ______________  _Reviewed:_ __________

---

## Compact list

Before you give an AI agent access:

1. Assign an accountable owner.
2. Test the actual deployment.
3. Make approval specific and temporary.
4. Examine provider dependencies.
5. Control model provenance.
6. Harden the inference environment.
7. Verify the data boundary.
8. Maintain a qualified fallback.
9. Use a distinct agent identity.
10. Issue minimum necessary permissions.
11. Bind approval to the action.
12. Constrain delegation.
13. Limit retrieval at the source.
14. Test tenant and session separation.
15. Restrict outbound disclosure.
16. Govern memory and retention.
17. Put authorization at the execution boundary.
18. Cap the damage a task can cause.
19. Observe consequential activity.
20. Stop authority independently.
21. Rehearse realistic incidents.
22. Preserve evidence and coordinate response.
23. Restore verified business operations.
24. Require evidence before restart.

## Deployment gates

| State | Permitted authority | Evidence required to advance |
|---|---|---|
| Sandbox | Synthetic or public test data; isolated tools; no production credentials | Owner, threat assessment, scoped evaluation plan, artifact and provider review |
| Constrained pilot | Explicitly approved data subset; read-only or individually approved writes; quotas | Passed boundary tests, access and isolation evidence, monitoring, tested stop mechanism |
| Bounded production | A defined set of actions within approved limits and change control | All applicable controls evidenced, incident and recovery exercise, authorized residual-risk decision, review expiry |

## Record your evidence

`Control ID | System/version | Owner | Requirement | Test method | Expected result | Observed result | Evidence location | Status | Exception/expiry | Reviewed date | Next review`

Keep sensitive evidence private; publish only appropriately reviewed summaries. This draft checklist starts unassessed.

## Put the standard to work

Discuss frontier-model evaluation, private-model deployment, agent access design, containment testing, or incident readiness with Guardian Robotics.

- Contact: https://gov.guardianrobotics.com/contact.html
- Email: info@guardianrobotics.com

## Status and limitations

This document states requirements. It does not assert that Guardian Robotics or any other organization has implemented, tested, or independently verified them. It is not a certification, a SOC 2 report, or a statement of legal compliance. Missing evidence is **unknown**, not a pass.

## Foundations

GCAS is Guardian's proposed operational policy. Framework associations are explanatory and do not imply endorsement or compliance. The thematic crosswalk and its scope limitation are published on the standard page:
https://gov.guardianrobotics.com/ai-governance/controlled-autonomy-standard.html#crosswalk

- [NIST CSF 2.0](https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf)
- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)
- [NIST Generative AI Profile (AI 600-1)](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf)
- [AICPA SOC suite of services](https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services)
- [OWASP Top 10 for Agentic Applications (2026)](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/)
- [NIST Cyber AI Profile project](https://www.nccoe.nist.gov/projects/cyber-ai-profile)

---

© 2026 Guardian Robotics. Guardian Controlled Autonomy Standard v0.1 (Proposed standard).
