Research2026-08-12

Forrester published a blog post introducing AEGIS, a framework for securing and governing autonomous AI agents inside large organizations. It sets out six areas of work — governance and compliance, identity and access, data security, application security, threat management, and Zero Trust architecture — plus a four-step order in which to tackle them, beginning with governance and an inventory of agents. The framework itself is described only in outline; the full report is restricted to Forrester clients.

What changed

Forrester's security guidance was framed around human-centric systems and generative AI rather than autonomous agents acting on their own.

What it unlocks

Structuring an agent security programme around six named domains and a phased sequence starting with governance and inventory.

  • six AEGIS domains
  • four-phase implementation roadmap
  • Security & Risk Forum, Washington DC, November 9–10, 2026

What you need to act on it

  • Forrester client access to read the full report

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.