Autonomous AI agents are reaching production faster than the controls meant to govern them. This paper relocates the agentic security problem from the model to the control layer that surrounds it, the trust and security harness, and shows that this layer is a present-day instance of a specification more than fifty years old: the reference monitor of Anderson (1972) and the protection principles of Saltzer and Schroeder (1975). It supplies a threat model, three planes of agentic zero trust, a set of testable assurance conditions, and a capacity-aware account of how mediation quietly fails under load. The aim is a reference architecture for judging whether an autonomous agent is actually mediated before it can act on enterprise systems.
S. Michelle Farr (2026) studied this question.