AWS has proposed a useful way to simplify the security debate around agents: treat several familiar risks as failures of delegation. Prompt injection concerns what the system is allowed to trust, excessive agency concerns what it may do and information disclosure concerns what it may access.
The framework separates delegation into three control points. Input delegation determines which instructions are trusted. Tool delegation defines the actions an agent may perform. Retrieval delegation limits the information it may fetch. AWS illustrates the danger with a crafted instruction hidden in retrieved content that causes an agent to query or expose information it should not touch.
The value of the model is organisational as much as technical. Security teams can test each delegation boundary instead of treating 'agent safety' as one vague control problem. A basic exercise is to plant an unauthorised instruction in a document the agent can retrieve, then observe whether policy, identity or approval controls stop the action.
AWS positions Amazon Bedrock AgentCore as a way to enforce these boundaries, so its product claims need independent validation. The underlying principle is platform-neutral: every transfer of authority should be explicit, narrow, observable and reversible.
