Databricks’ AI Security Framework now treats agents that act, not just models that generate text, as their own attack surface. If you are mapping controls for agentic AI, it is one of the more specific public references available.
DASF v3.0, published March 20, 2026, adds Agentic AI as the framework’s 13th canonical component, up from the 12 in prior versions. Databricks also introduces 35 technical risks tied to agent reasoning, memory, and tool use, plus six mitigation controls, including least privilege, sandboxing, and human oversight. The framework now lists 97 risks and 73 controls, with each new entry tagged “DASF v3.0” in the revision column.
The added risks are specific. A sub-component called “13A: The Agent Core” names Memory Poisoning (13.1), Cascading Hallucination Attacks (13.5), and Intent Breaking and Goal Manipulation (13.6). A separate category, “Discovery and Traversal,” describes agents reaching data paths and tools the requesting user was never authorized to touch. As Databricks puts it, “the user effectively inherits the agent’s permissions rather than their own.”
The extension also adds guidance for Model Context Protocol servers and clients, plus multi-agent and agent-to-agent communication threats, relevant as MCP becomes a default integration layer. Databricks ties its analysis to the “lethal trifecta,” the combination of private data, untrusted content, and external communication that we covered separately.
For security leaders, the control surface shifts to authorization and permission scoping, rather than output filtering. Teams already running zero-trust enforcement for APIs and service accounts can map these controls directly onto agent identity and tool access. Start with the inherited-permissions problem: check whether your agents act with their own broad service credentials or with the narrower rights of the user who asked.
Source: Databricks



Leave a Reply