Forrester published a framework arguing that securing AI agents requires examining what a system was trying to do, not only what it did. It defines agent intent as the relationship between an assigned goal, its constraints and the path the agent takes, and splits it into five layers from the builder's design purpose down to the agent's chosen actions. The detailed guidance sits in a report available only to Forrester clients.
What changed
Security practice traced bad outcomes back to user actions and inspected prompts and outputs.
What it unlocks
Classifying an agent's chosen action path against the objective it was given, and matching the response to that classification rather than to the outcome alone.
- five layers of intent
What you need to act on it
- Forrester client access for the full report
Sources