← All Articles

Security Architecture in the AI Era: From SABSA and TOGAF to Agent Trust Boundaries

February 15, 2026 · 7 min read

AI agents are now operating inside enterprise environments—reading emails, querying databases, making decisions, triggering workflows. Established security architecture frameworks remain valid but require extension to accommodate AI agents as a new tenant category.

Three Foundational Frameworks

SABSA

Business-driven, risk-derived. Provides the "why" through traceability from business requirements to controls. Six layers from contextual to component.

TOGAF

Ensures security aligns with enterprise architecture lifecycle. Provides the "where" in enterprise context: application portfolios, migration, governance.

OSA

Technical control patterns and reference architectures. Delivers the "how": perimeter security, identity federation, data protection.

AI Agent-Specific Changes

1. Trust Boundaries Transformation

Agents traverse multiple zones within single task execution at speed and breadth exceeding traditional user patterns. Requires cross-zone traversal models and cumulative access monitoring.

2. Non-Human Identity (NHI) Governance

New identity category requiring lifecycle management, rotation, task-scoped least-privilege enforcement, behavioural monitoring, and attestation of agent actions.

3. Data Flow Architecture

Agents create derived sensitive data through multi-source queries. Data exfiltration through inference API calls. Classification needed at agent access point, not just at rest/transit.

4. Decision Authority Framework

Explicit mapping of autonomous vs. human-approval decisions across: read-only retrieval, low-risk modification, high-risk operations, access provisioning, financial transactions.

Seven Key Deliverables

  1. Agent inventory and cataloguing
  2. Trust zone mapping for agent traversal
  3. NHI governance framework
  4. Data classification for agent access
  5. Prompt injection defence patterns
  6. Human-in-the-loop decision framework
  7. Comprehensive audit logging for autonomous actions
These frameworks work. They’ve been stress-tested across industries. They require extension—not replacement—to account for agent autonomy.

Need help implementing this?

First strategy session is complimentary. We typically respond within 4 hours.