Best Practices for Building Agents Recap
Arthur

Which framework should you use to govern AI agents? Five Eyes, OWASP, NIST, and ISO 42001 mapped

October 9, 202611 min read

Four major documents on securing AI agents landed between December 2025 and mid-2026, and each one speaks its own language. The Five Eyes cyber agencies describe five risk categories. OWASP uses ASI codes. NIST is building control overlays. ISO 42001 refers to Annex A clauses. If you read them one at a time, you come away with four separate to-do lists and no idea where they overlap.

They overlap almost everywhere. Under the different vocabularies, the same six control families show up in every framework: inventory, identity and privilege, tool and action boundaries, monitoring, human oversight, and incident response. Build your controls once per family, collect the evidence once, and that one effort answers all four documents at review time.

This is a crosswalk, not a product pitch. It maps the 2026 agent security and governance frameworks against each other so you can see which single control satisfies several at once. Where Arthur fits is narrow and called out explicitly: discovery, monitoring, evals, guardrail verdicts, and the audit record. The identity and privilege guidance below comes from the source frameworks, and we attribute it as such.

The 2026 agent framework landscape at a glance

Here is what each document is, who wrote it, and whether it binds you.

Five Eyes, "Careful Adoption of Agentic AI Services." Released on April 30, 2026 by CISA, the NSA, Australia's ASD ACSC, the Canadian Centre for Cyber Security, New Zealand's NCSC, and the UK's NCSC, it is the first coordinated multi-government guidance written specifically for agentic AI. It sorts agent risk into five categories: privilege, design and configuration, behavioral, structural, and accountability. The posture is cautious. The guidance tells organizations that "until security practices, evaluation methods and standards mature," they should assume agentic systems may behave unexpectedly. It is voluntary, not a regulation.

OWASP Top 10 for Agentic Applications 2026. Published December 9, 2025, it is a developer-facing threat taxonomy running from ASI01 to ASI10. It is the closest thing to a shared language for agent vulnerabilities. OWASP's Q3 2026 exploit roundup, published October 8, 2026, maps real incidents to those codes, including the Hugging Face intrusion carried out by evaluation agents between July 10 and 13, 2026.

NIST. The Center for AI Standards and Innovation (CAISI) launched its AI Agent Standards Initiative on February 17, 2026. Its agent-security RFI closed March 9, and the NCCoE concept paper on agent identity and authorization closed for comment April 2. The COSAiS SP 800-53 overlays for single-agent and multi-agent systems are still in development, with no finalized control text as of August 2026. Treat NIST as a direction of travel, not a standard you can conform to yet.

ISO/IEC 42001. The certifiable AI management system standard, with 38 reference controls in Annex A. It is the only document on this list you can be audited and certified against today, which is why it increasingly shows up in vendor questionnaires.

For context, Gartner published its first Magic Quadrant for AI Governance Platforms on June 16, 2026, evaluating 13 vendors with AI Agent Governance as one of its assessed use cases. And the gap these frameworks address is measurable. A 2026 CISO AI Risk Report of 235 large-enterprise CISOs and CIOs, cited by the Cloud Security Alliance, found that 92% lack full visibility into their AI identities and 86% do not enforce access policies for them.

__wf_reserved_inherit

The crosswalk: Six control families across four frameworks

The six families below appear in every framework under different names. The cells name the specific code, category, or clause each framework uses for that family.

__wf_reserved_inherit

Read it by row. Build your inventory control once, and it answers the Five Eyes structural category, the agent surface OWASP assumes you already know, NIST's inventory expectations, and ISO 42001 Clause 4 at the same time. The rest of this piece walks each family.

Family 1: Inventory and discovery

Every framework starts here, because you cannot secure, assess, or govern an agent you do not know exists. Five Eyes treats an incomplete inventory as structural and accountability risk. OWASP's entire taxonomy presupposes a known agent surface. NIST's work assumes inventory as a precondition, and ISO 42001 makes it explicit in Clause 4 scope and the A.6 life cycle controls.

The hard part is completeness. Agents enter the enterprise unregistered, through new application code, through vendor features that quietly turn on agentic behavior, and through business users building their own. Manual registration never keeps up. Multilayered automated discovery does: listeners on OpenTelemetry streams, Model Context Protocol server monitoring, network-layer analysis for LLM call signatures, and the discovery APIs that cloud platforms like AWS Bedrock and Google Vertex AI are beginning to expose.

This is where Arthur's agent discovery and governance maps directly. Automated, continuous discovery across those four layers builds the inventory that every other family depends on, then routes unregistered agents for triage and ownership.

Family 2: Identity, privilege, and ephemeral credentials

This is the heart of the Five Eyes guidance and the control family with the widest gap between recommendation and practice. The guidance is specific: organizations should replace static, long-lived secrets with ephemeral credentials that expire when the job is complete. OWASP covers the same ground in ASI03 (excessive privilege), NIST's NCCoE is working on agent identity and authorization, and ISO 42001 touches it in A.9 and A.4.

The CSA numbers show how far practice lags: 92% of surveyed enterprises lack full visibility into their AI identities, and 86% do not enforce access policies for them. The practical steps, scoped credentials, short-lived tokens, least-privilege tool grants, and a trusted registry of which agent holds which access, come from the frameworks above and belong with your identity and platform teams.

To be clear about scope, Arthur does not issue credentials or act as an identity provider. Its contribution to this family is visibility: surfacing which agents hold access to which tools and data as part of the discovered inventory and risk surface, so the teams who do manage identity can see what they are governing.

Family 3: Tool use, supply chain, and MCP

Agents act through tools, and tools are where the worst incidents happen. OWASP covers this in ASI02 (tool misuse) and ASI04 (supply chain), and its Q3 2026 roundup uses the Hugging Face evaluation-agent intrusion as the worked example of both. Five Eyes files it under design and configuration and structural risk. External MCP servers are third-party dependencies, which is exactly how ISO 42001 A.10 treats them: suppliers that need a named owner and a review.

The control is a boundary. Validate tool selection and actions before they execute, and record the decision. Arthur maps here through guardrail verdicts on tool and action validation, emitted as telemetry so you can see what each guardrail caught and how often. The best practices for building agents cover the pre-execution and post-execution guardrail patterns in detail.

Family 4: Monitoring, evals, and accountability evidence

Five Eyes behavioral and accountability risk, OWASP's runtime detection, NIST's monitoring expectations, and ISO 42001's A.6.2.6 operation and A.6.2.8 event logs all describe the same requirement: prove the agent behaved, and keep the record.

Three artifacts do most of the work. Traces capture what the agent did, step by step. Continuous evals run against production traffic and flag behavioral failures as they emerge. Guardrail pass/fail history shows the runtime controls fired when they should have. Together they are the accountability evidence every framework asks for, and the record an auditor or incident responder reads after the fact. This is Arthur's strongest lane.

Family 5: Human oversight and escalation thresholds

Five Eyes places oversight in its accountability and behavioral categories, ISO 42001 covers it in A.9, and OWASP describes human-in-the-loop patterns. The control is an escalation threshold: the point at which an agent must pause and hand off to a person, and the routing that makes the handoff happen.

The oversight policy itself, what triggers an escalation and who reviews it, is the organization's to set. Arthur maps on the detection-and-route side. Eval and guardrail failures can alert a team immediately or queue interactions for human review, depending on how confident you are in the check. That is the mechanism that turns a threshold into an action.

Family 6: Incident response

Five Eyes folds this into accountability, and OWASP's exploit roundup is the "this already happened" evidence that agent incidents are real and recent. ISO 42001 carries standard incident expectations.

When an agent misbehaves, the forensic record is the traces and guardrail telemetry you were already collecting for Family 4. The organizational half is ownership: every agent needs a named owner so there is someone accountable to respond. Discovery that assigns ownership and monitoring that preserves the record are what make incident response possible rather than a scramble through logs.

What is still unsettled, and how to stay current

Parts of this landscape will change. NIST's COSAiS SP 800-53 overlays are in draft with no final control text as of August 2026, and the NCCoE identity work is open. In Europe, prEN 18286 is pending as the harmonized standard that would align agent governance with the EU AI Act, which means ISO 42001 certification does not yet grant a presumption of conformity there. OWASP's ASI codes will keep evolving with each quarterly exploit roundup.

None of that changes the six families. Inventory, identity, tool boundaries, monitoring, oversight, and incident response are stable across every framework published so far and every draft in progress. Build your controls around the families rather than any single document, and you will not have to re-platform each time a framework updates.

If your work is in a regulated sector, the controls get sharper. Our deep dive on security controls regulators expect for agentic AI in financial services covers the sector-specific version of this crosswalk.

One control effort per family answers four frameworks. Start with inventory, because every other family depends on knowing what you have. Book a demo to see how Arthur discovers agents across your environment and builds the evidence base the rest of the families need.

‍

SHARE