Risk
Autonomous Policy/Compliance Violation
Description
Agent autonomously takes actions violating data retention, privacy, access, or ethical policy due to lack of integrated runtime controls.
Example
Agent copies PII to unauthorized location or outputs restricted data.
Assets Affected
Agentic platform (no code)
Model Response
Dataset / RAG
Mitigation
- Implement real-time policy enforcement at runtime
- Output filtering, data loss prevention (DLP), and automated compliance checks
- Audit and alert on policy breaches
Standards Mapping
- ISO 42001: A.5.4, A.9.3
- OWASP Top 10 for LLM: LLM06
- NIST AI RMF: GOVERN 1.1, MEASURE 2.11
- DASF v2: MODEL SERVING 9.13