In 2022, an attacker compromised Uber's internal systems without bypassing a single security control. Using the stolen credentials of a contractor's VPN account, the attacker flooded the contractor with push-based multifactor authentication (MFA) requests until the contractor faced MFA fatigue and finally approved one. Once authenticated, the attacker gained access to internal administrative systems and disrupted operations.1 In this scenario, Uber's controls operated precisely as designed. The problem? The assumption that push-based MFA was sufficient to prevent unauthorized access had become obsolete before the attack occurred.
Intent drift is the gradual disconnect between why an organization built a control and the threats the organization currently faces. The concept of drift is not new—what is new is the arrival of agentic artificial intelligence (AI) systems that autonomously execute governance workflows at scale. AI inherits accumulated misaligned controls and scales them without question, across thousands of systems, faster than any review process can respond. Most security teams across organizations of all sizes have a version of this problem in their environment. Not a broken control, but a control whose original rationale no longer matches the threat it was meant to address.
Intent drift arises when controls, audits, and reporting systems maintain the illusion of effective security and operations while a gap widens between enforced controls and actual environmental needs, creating false audit findings, operational bottlenecks, and weak security assurances. organizations must mitigate this stealthy risk proactively to preserve trust and maintain operational continuity and efficiency.
Why It Matters
Intent drift creates risk in 4 compounding areas:
- False assurance—When a control no longer maps to the current threat vector it creates an illusion of coverage, stalling investment in stronger detection stalls.
- Alert fatigue—Where misaligned controls generate noise practitioners learn to dismiss it, and the signal-to-noise ratio degrades when it matters most.
- Irreversibility—A stale manual control remains correctable because human friction surfaces the problem, but once that same control is embedded in automated workflows, unwinding it requires touching multiple downstream systems.
- Regulatory exposure—The US National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), COBIT®, the EU AI Act, and The EU Digital Operational Resilience Act (DORA) each require documented evidence that a control maps to a current risk scenario.2 An organization that cannot explain what threat a control mitigates is holding a liability artifact, not a governance asset.
Each risk feeds the others, and agentic AI, which removes the human friction that would otherwise surface the problem, is positioned to accelerate all 4 simultaneously. For example, when a governance workflow transitions from human execution to autonomous AI operation, the practitioner who might have flagged a misalignment is no longer in the loop. Unless explicitly designed that way, agentic AI systems do not pause and assess whether the assumptions behind the workflow still apply, it executes and scales. This is concerning, as research confirms that organizations are deploying AI faster than governance frameworks can mature to manage it.3
The Intent Check: A Practical Preautomation Review
Addressing this risk does not require slowing automation projects. What is needed is a short, structured review before any control is automated (or significantly scaled) that is focused on whether the control's original rationale still holds. This review is known as an intent check.
Three questions form the intent check’s core:
- Why does the control exist and what specific threat, regulatory requirement, or risk scenario/condition originally justified it?
- Does that condition still apply given changes in architecture, threat model, or regulation?
- What changes when the process becomes automated, and how does the introduction of AI (agentic or otherwise) multiply both the control's effect and its failure modes across the environment?
A single focused session is enough. Include the control owner, a cloud architect, and an automation engineer to cover the necessary perspectives. If the team responsible for the control cannot answer the first question from institutional knowledge, that is valuable information and must be corrected. The control's rationale has already drifted and thus must be revalidated before automation amplifies it. Figure 1 presents the framework at a glance.
Figure 1—The Intent Check Framework
| Question | Evaluation Focus | Risk If Skipped |
|---|---|---|
|
1.Origin—Why does this control exist? |
Identify the specific threat, regulatory requirement, or risk scenario that originally justified the control. |
Expired controls address threats that no longer exist in the current environment. |
|
2. Validity—Does that condition still apply? |
Assess whether changes in architecture, threat model, tooling, or regulation have altered the original assumptions. |
Controls designed for legacy environments generate noise or false assurance in modernized architectures. |
|
3. Scale—What changes under autonomous operation? |
Evaluate how an AI agent/tool multiplies the control's effect and its failure modes across the environment. |
A marginally suboptimal manual process becomes a systemic liability when replicated autonomously at scale. |
The Uber Breach
The 2022 Uber breach offers a useful lens for understanding how an intent check can be applied.
Uber’s intent drift: This assumption made sense before threat actors systematically weaponized user fatigue across thousands of fraudulent requests.
Uber’s Intent Check:
- Origin—Organizations introduced push-based MFA to mitigate credential theft which required device possession alongside a password. At deployment, the control aligned to the threat model.
- Validity—By 2022, MFA fatigue attacks demonstrated that this assumption no longer consistently held. Revalidation would have prompted controls such as number matching, rate limiting, or phishing-resistant authentication.4
- Scale—At the time of the breach, most organizations had not embraced agentic AI.
Any organization with automated identity workflows should consider the possibility that an AI agent (or other automation tool) could provision or validate access using the same push-based MFA assumption. In that case, organizations must ask themselves, how would the failure mode scale and what should be done to correct it?
Fitting Into Existing Governance
Teams do not need to treat the intent check as a standalone practice. It can seamlessly integrate into the various review cycles organizations already conduct. For COBIT practitioners, it maps directly to several objectives:
- APO12 Managed Risk
- EDM03 Ensured Risk Optimization
- BAI06 Managed IT Changes
Organizations conducting NIST CSF assessments can embed the intent check within the “Identify” function. Intent checks also support the NIST AI Risk Management Framework (RMF) and Toolkit, by ensuring that controls remain relevant to the current risk environment rather than merely operating correctly within an outdated one.5 Figure 2 presents the mapping between existing frameworks and the intent check.
| Framework | Where It Maps | How the Intent Check Applies |
|---|---|---|
|
COBIT |
APO12 Managed Risk |
Confirms that a control's risk rationale is still current before it is scaled or automated. |
|
COBIT |
EDM03 Ensured Risk Optimization |
Evaluates whether continued investment in the control still matches its actual risk-reduction value. |
|
COBIT |
BAI06 Managed IT Changes |
Positions rationale revalidation as a required step before a change is implemented. |
|
NIST CSF |
Identify function |
Documents each control's rationale as part of the function's control inventory. |
|
NIST AI RMF |
Govern / Map functions |
Validates a control's assumptions before an AI system inherits or automates it. |
|
ISACA AI Audit Toolkit |
Control assessment methodology |
Supplies the mapping structure for the intent check's 3 questions (origin, validity, scale) during AI-specific audits. |
Conclusion
Agentic AI does not create intent drift. It inherits it, executes it without questioning it, and scales it faster than any manual review process can match. The window available to governance teams to catch and correct drift through intent checks is narrowing as agentic deployments accelerate.
The organizations that navigate this transition with minimal disruption will not necessarily be those equipped with the most advanced tools. Instead, success will favor those that maintain a strong institutional understanding of the rationale behind their controls and foster an enterprise culture that prioritizes keeping this knowledge up to date and accessible before initiating automation. Selecting a small set of controls under consideration for automation, convening the control owner, the responsible architect, the implementation engineer, and working through the 3 intent drift questions is a practical starting point. Insight gained from what teams can and cannot answer reveals more about governance readiness than any dashboard metric. Addressing these gaps is significantly more cost-effective than troubleshooting post implementation and reveals areas of weakness before they can hinder organizational processes and damage reputation
Endnotes
1 Uber Technologies, Inc., Cybersecurity Incident Update [Form 8-K, Exhibit 99.1], US Securities and Exchange Commission, 19 September 2022
2 National Institute of Standards and Technology (NIST), The NIST Cybersecurity Framework (CSF) 2.0, USA, 26 February 2024; ISACA, COBIT®, USA, 2018; European Parliament, “EU AI Act: First Regulation on Artificial Intelligence,” 14 June 2023; European Commission, "The Digital Operational Resilience Act (DORA)," European Union, 2023
3 ISACA®, AI Use Is Outpacing Policy and Governance, ISACA Finds, 25 June 2025
4 Cybersecurity and Infrastructure Security Agency (CISA), Implementing Phishing-Resistant MFA, US Department of Homeland Security, October 2022.
5 National Institute of Standards and Technology (NIST), NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), USA January 2023; ISACA, Artificial Intelligence Audit Toolkit
Dhivya Balasubramanian
Is a cybersecurity leader with nearly 20 years of experience in enterprise technology transformation, specializing in identity and access management and AI-enabled security operations. She currently leads IAM enablement at Southwest Airlines, driving identity programs at enterprise scale across cloud-native and hybrid environments with an extended focus on IAM for Agentic AI. Dhivya is an active speaker, mentor, ISACA volunteer, and contributor to the cybersecurity and identity community, with a focus on leadership, innovation, and workforce development. She can be reached via LinkedIn. Opinions expressed here are solely her own and are not reflective of her employer.