Forrester published a blog post introducing AEGIS, a framework for securing and governing autonomous AI agents inside large organizations. It sets out six areas of work — governance and compliance, identity and access, data security, application security, threat management, and Zero Trust architecture — plus a four-step order in which to tackle them, beginning with governance and an inventory of agents. The framework itself is described only in outline; the full report is restricted to Forrester clients.
What changed
Forrester's security guidance was framed around human-centric systems and generative AI rather than autonomous agents acting on their own.
What it unlocks
Structuring an agent security programme around six named domains and a phased sequence starting with governance and inventory.
- six AEGIS domains
- four-phase implementation roadmap
- Security & Risk Forum, Washington DC, November 9–10, 2026
What you need to act on it
- Forrester client access to read the full report
- forrester.com2026-08-12