---
title: "The AI Security Framework | Anomity"
description: "A practical framework for securing AI agents and MCPs: the artifact attack surface, MCP trust tiers, permission hygiene, policy patterns, and audit."
url: "https://anomity.ai/reports/ai-security-framework/"
source: html
---

- Home

- Reports

- The AI Security Framework

Report

# The AI Security Framework

Defining security for AI agents and MCPs.

![Anomity robot illustrating The AI Security Framework]

## What's inside

- The AI artifact attack surface: the eight artifact types that now live on every endpoint (agents, MCP servers, extensions, skills, plugins, secrets, hooks, and CLIs) and why they fall outside existing controls.

- MCP trust tiers: a classification model for sorting servers and integrations into official, community, and unknown, and what each tier should be allowed to do.

- Permission hygiene: how to reason about inferred capabilities (filesystem, shell, network, credentials) and why blanket grants like Bash(*) or Write(*) are the patterns to eliminate first.

- Dangerous-combination detection: capability pairings that are low-risk alone but high-risk together, and how to flag them before they reach production.

- Secret handling: keeping credentials on the endpoint, redacting before anything leaves the device, and avoiding plaintext secrets in agent configuration.

- Policy patterns: writing enforceable rules (approved-MCP allowlists, no blanket permissions, no plaintext secrets) that evaluate continuously rather than at a single point in time.

- Audit requirements: the record of every added, removed, and modified artifact you need so that 'what changed last Thursday?' is answerable as a single query.

## About this report

This framework is built for the people who now own a surface that did not exist a year ago. AI agents and MCPs have become the new shadow IT: they install in minutes, request broad permissions, connect to outside services, and leave little trace for the security team. Network gateways, EDR, DLP, and GRC tooling each see a slice of the picture, but none of them was designed to inventory or govern the AI artifact layer itself. The result is a blind spot, and you can't govern what you can't see. This report defines a vocabulary and a set of controls for closing it, organized around discovery, classification, permission hygiene, policy enforcement, and audit.

Anomity is an early-access company building toward this framework rather than claiming it as a finished standard. The patterns here reflect how we approach Agentic AI Security: a lightweight, unprivileged Endpoint Sensor that discovers AI artifacts across Windows, macOS, and Linux, a managed browser sensor that covers the AI services people reach in a tab, and read-only cloud connectors that find the AI applications holding OAuth grants on your tenant. Each artifact is classified by trust and inferred capability, evaluated against rules you define, and kept in a 90-day record of every change. The framework is product-independent and meant to be useful whether or not you ever deploy Anomity. We share it to give security teams a common way to talk about agentic risk before it becomes an incident.

## Get the report

Tell us a bit about you and we'll be in touch. No spam.

Full Name

Work Email

Company

Phone

Your Role Select your role CISO / VP Security Security Engineer IT Admin DevOps / Platform Engineering Lead Other

Request the report
Thanks you're on the list. We'll be in touch shortly with **The AI Security Framework**.

## Structured data

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://anomity.ai/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Reports",
      "item": "https://anomity.ai/reports/"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "The AI Security Framework",
      "item": "https://anomity.ai/reports/ai-security-framework/"
    }
  ]
}
```
