End-to-end protection for an AI agent running on Azure AI Foundry, AWS Bedrock AgentCore, or GCP Vertex AI / Gemini Enterprise Agent Engine — seven defense layers from the network edge to the data plane, plus three cross-cutting planes (detection & IR, resilience & cost, posture & discovery), covering deployment-time and runtime, single-agent and multi-agent (A2A) topologies, and the MCP tool layer underneath. Every layer lists native controls for all three platforms plus best-of-breed third-party options, mapped to OWASP Agentic/LLM Top 10, MITRE ATLAS, NIST AI RMF, and DASF 3.0. v1.2 adds Microsoft Copilot Studio as the low-code build surface on the Microsoft side — same layers, different enforcement points.
One request path, guarded at every hop. Nothing reaches the agent except through the AI gateway; the agent holds no secrets and reaches nothing except through identity-scoped, policy-checked calls. A peer agent is a separate trust zone — authenticated, schema-validated, and never implicitly trusted.
Outside-in, the order an attacker meets them. Each layer states its objective, the threats it absorbs, native controls on all three platforms, and best-of-breed third-party options where native coverage runs out.
Objective: the agent is unreachable from the public internet, and can itself reach only an explicit allowlist. Deny-by-default in both directions — an agent's outbound path is the exfiltration path.
Objective: every agent is a first-class, governed identity — owned, scoped, credentialed with short-lived tokens, and revocable. No static secrets anywhere in the agent's reach; every tool call carries the least privilege for that one action, and user context propagates so the agent can never do more than the human it acts for.
Objective: a mandatory inspection point on every prompt in and every response out — and on every intermediate step. Detect and block prompt injection, jailbreaks, PII leakage, ungrounded output, and unsafe tool invocations in real time. The gateway is the single door; the runtime refuses traffic from anywhere else.
Objective: blast-radius containment. Each session runs in its own isolated compute with nothing shared across users; the model and orchestration code are pinned, scanned, and reproducible; consequential actions require a human gate. A compromised session dies with the session.
Objective: every peer agent is a separate trust zone. Agents authenticate each other cryptographically, exchange only schema-valid messages, and treat each other's output as untrusted input — a compromised agent must not be able to propagate instructions, poison memory, or replay tasks across the mesh.
Objective: the agent's hands are its highest-risk surface. Broker every tool and MCP connection through a gateway that enforces which agent may call which tool, with what arguments, under whose identity — and vet the tools themselves like third-party software, because that's what they are.
Objective: the agent can retrieve only what the calling user could read directly, memory never becomes a cross-user leak or a poisoning vector, and everything at rest sits under customer-managed keys with classification labels that survive into the index.
Three capabilities that don't sit at any single hop but decide whether the layered controls actually hold: knowing when something got through, surviving it, and finding the agents nobody registered.
Runtime controls assume the artifact that shipped was clean. These gates run in CI/CD before an agent version ever reaches L4 — fail any gate, no deploy.
How the seven layers land against the frameworks auditors and customers will ask about.
| Layer | OWASP (LLM / Agentic / MCP / NHI) | MITRE ATLAS tactics | NIST AI RMF | DASF 3.0 |
|---|---|---|---|---|
| L1 Network | LLM Top 10: supply chain, DoS | Exfiltration, Impact | Manage 2.4 | Runtime plane risks |
| L2 Identity | NHI Top 10 (all); Agentic: excessive agency | Credential Access, Priv. Esc. | Govern 1.3, Manage | Serving & ops controls |
| L3 Guardrails | LLM01 injection, LLM02 insecure output | Prompt Injection, Evasion | Measure 2.x | Inference plane risks |
| L4 Runtime | Agentic: memory poisoning, rogue agents | Persistence, Defense Evasion | Manage 1.x | Model plane risks |
| L5 Multi-agent | Agentic Top 10 (comms, impersonation) | Lateral Movement | Govern 5, Manage | v3.0 agent risks |
| L6 Tools/MCP | MCP Top 10 (all); LLM: plugins/supply chain | Execution, Collection | Map 3.x, Manage | Tool integration risks |
| L7 Data | LLM: data poisoning, sensitive disclosure | Poisoning, Collection | Map 1.x, Measure | Data plane risks |
| Planes A–C | Agentic: rogue agents, resource abuse | Discovery, Impact | Govern 6, Manage 4.x | Ops & governance controls |
If you implement nothing else this quarter, do these, in this order. Each is cheap relative to the class of incident it removes.
Every abbreviation used in the diagram and control matrix, in one place.