Skip to content
Search
paperJune 2026Unreviewed

AgenticOS: An Intent-Oriented Secure Operating System Architecture for Autonomous AI Agents

Zhen Zhao, Yu Zhang, Yanpeng Zhu, Jia Wang, Songqiao Tao, Xin Cheng, Jiexin Gao

Abstract

Traditional OS security models based on "resource exposure plus permission checks" face structural challenges as LLM-driven autonomous agents acquire capabilities for planning, tool use, network access, and code execution. Once an agent runtime is compromised through prompt injection or malicious tool outputs, an attacker can compose POSIX-style resource primitives into behaviors far beyond the user's task authorization. To address this, we propose AgenticOS, an intent-oriented secure OS archite

Categories

Framework mappings

OWASP Top 10 for Agentic Applications
  • ASI02Tool Misuse & Exploitation
MITRE ATLAS
  • AML.T0051LLM Prompt Injection
  • AML.T0053AI Agent Tool Invocation

Suggested from the entry's categories.

Cite

@misc{zhao2026agenticos,
  title = {{AgenticOS: An Intent-Oriented Secure Operating System Architecture for Autonomous AI Agents}},
  author = {Zhen Zhao and Yu Zhang and Yanpeng Zhu and Jia Wang and Songqiao Tao and Xin Cheng and Jiexin Gao},
  year = {2026},
  month = jun,
  eprint = {2606.21129},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.21129}
}