AI Governance Institute
← Agentic AI
AGT · Agentic AIAGT-011High effortAgent-relevant

Agent Behavior Monitoring and Anomaly Detection

Added Invalid Date

Monitor deployed AI agents for behavioral drift, unusual use of connected tools, unexpected resource use, and actions outside their permitted scope.

Objective

Detect agent misbehavior, compromise by attackers, model drift (gradual change in AI behavior), or unintended new abilities before harm occurs, by watching how agents act, not just final outputs.

Maturity Levels

1

Initial

No agent behavior monitoring exists; issues are detected only when users report problems or downstream systems fail.

2

Developing

Basic output logging exists but no behavioral baselines or anomaly alerts are in place.

3

Defined

Behavioral baselines are established per agent type; deviations from normal tool call patterns, resource use, or action sequences trigger alerts.

4

Managed

Alerts are triaged by a designated team on a defined SLA; behavioral anomalies feed into agent evaluation and update cycles.

5

Optimizing

Automated analysis identifies behavioral drift in real time; agents can be paused or constrained automatically when anomaly thresholds are exceeded.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • —Behavioral baseline documentation per agent, including normal frequency of tool use, resource consumption ranges, and action sequence patterns with the baseline period and data volume
  • —Alert configuration records showing which deviations trigger alerts, alert severity levels, and routing/escalation paths
  • —Anomaly investigation records for a sample period, showing alert triage, root cause determination, and resolution or escalation
  • —Baseline refresh records confirming baselines were re-established following intentional model or prompt changes
  • —Integration evidence showing agent behavioral alerts are routed to and actioned by a designated security or governance function within the defined service level agreement (SLA)

Implementation Notes

Key steps

  • Record each deployed agent's normal behavior (its behavioral baseline): how often it uses connected tools, common action sequences, typical usage volume and cost, expected output types, and error rates.
  • Monitor for deviation: an agent suddenly calling external services (APIs) at 10x normal rate, accessing databases it rarely touched, or producing outputs of unusual length or format warrants investigation.
  • Distinguish behavioral drift from intentional changes: re-establish baselines after model updates, changes to the agent's standing instructions (prompts), or new capabilities.
  • Build alert playbooks for the most actionable anomaly patterns: agents calling themselves in loops, first use of high-risk permissions, sudden spikes in rejection or error rates, and out-of-scope access.
  • Route agent behavioral alerts into your security operations center (SOC) workflow alongside infrastructure monitoring; agent incidents look different from application incidents but require the same urgency and documentation.

Example Implementation

Financial services firm running document processing agents over customer loan files

Agent Behavioral Baseline: Loan Document Processing Agent

Baseline period: 30 days post-deployment (sampled from 500+ sessions)

MetricNormal RangeAlert ThresholdAlert Routing
Tool calls per session8–14>25 or <3AI Eng on-call
External API calls per session2–4>10AI Eng + SOC
Session duration45–120 seconds>300 secondsAI Eng on-call
Token consumption per session4,000–8,000>20,000AI Eng on-call
Error / rejection rate<5% of sessions>20% in any 1-hour windowAI Eng + SOC
First-use of any permissionN/AAnySOC immediate

Baseline refresh: Re-established within 5 business days of any model update, prompt change, or new tool addition.

Triage SLA: P1 alerts (first-use of permission, external API spike) acknowledged within 15 minutes.

Control Details

Control ID
AGT-011
Typical owner
AI Engineering / SOC / AI Governance Team
Implementation effort
High effort
Agent-relevant
Yes

Tags

monitoringanomaly detectionbehavioral driftobservabilityagent safety

Templates for this control

Get control updates weekly

New and updated controls, maturity guidance, and the regulatory changes behind them. Every Thursday.

Powered by Buttondown.