AI Governance Library

Careful Adoption of Agentic AI Services

Until security practices, evaluation methods and standards mature, organisations should assume that agentic AI systems may behave unexpectedly and plan deployments accordingly, prioritising resilience, reversibility and risk containment over efficiency gains.
Careful Adoption of Agentic AI Services

⚡ Quick Summary

Jointly authored by cybersecurity authorities from Australia (ASD ACSC), the United States (CISA, NSA), Canada (CCCS), New Zealand (NCSC-NZ), and the United Kingdom (NCSC-UK), this guidance outlines technical risks and defensive controls for implementing large language model (LLM)-based agentic AI systems. Moving beyond static generative AI, agentic systems autonomously plan, spawn sub-agents, call external tools, and execute workflows across digital infrastructure. The guidance establishes that autonomous decision-making exponentially expands the attack surface, creating vulnerabilities such as confused deputy exploitation, specification gaming, cascading multi-agent failures, and goal drift. Defending these architectures requires embedding AI within established Zero Trust and Secure by Design models, enforcing strict privilege scoping, establishing human-in-the-loop checkpoints, and prioritizing reversibility and blast-radius containment over efficiency.

🧩 What's Covered

The guidance breaks down agentic AI security across structural risk domains and the complete engineering lifecycle:

  • Understanding Agentic Architecture: How LLM backbones interact with external tools, long-term memory, planning modules, and autonomous sub-agent spawning mechanisms, distinguishing goal-driven autonomous systems from standard content-generating models.
  • Five Core Security Risk Domains:
    • Privilege Risks: Overly broad entitlements, scope creep across handoffs, credential hijacking, and confused deputy patterns enabling low-privileged users to invoke high-privileged actions.
    • Design and Configuration Risks: Static authorization checks failing dynamic executions, unvetted third-party components, and inadequate network enclave segmentation.
    • Behavioral Risks: Specification gaming, strategic deception to circumvent evaluation or shutdown, unintended emergent behaviors, prompt injection, and data poisoning.
    • Structural Risks: Orchestration loops, sponge attacks exhausting resources, tool squatting, untrusted dynamic package loading, and inter-agent communication tampering.
    • Accountability Risks: Opaque multi-step reasoning, stochastic reproducibility gaps, and bloated, loosely structured audit logs obscuring root cause attribution.
  • Lifecycle Best Practices:
    • Designing Secure Agents: Hierarchical prompt context structuring, grounding with retrieval-augmented generation (RAG), cryptographic identity registries (mTLS/PKI), and multi-layer defence in depth.
    • Developing Secure Agents: Adversarial red teaming, sandbox simulation, active learning against specification gaming, tuned data loss prevention (DLP), and unified inter-agent audit trails.
    • Deploying Agents Securely: Threat modeling against OWASP GenAI Top 10 and MITRE ATLAS, progressive deployment with graduated autonomy, fail-safe defaults, and declarative safety contracts.
    • Operating Agents Securely: Continuous runtime behavioral monitoring, anomaly detection, just-in-time credentials, output validation against redundant models, and mandatory human approval checkpoints for high-impact actions (e.g., system resets or log deletions).
  • Future Defense Methodologies: Applying System-Theoretic Process Analysis (STPA, STPA-Sec) and Causal Analysis using System Theory (CAST) to assess emergent system-level failure modes.

💡 Why it matters?

As organizations integrate autonomous agents across IT environments and critical infrastructure, security boundaries between AI and core systems dissolve. Autonomous execution amplifies common misconfigurations into rapid, widespread breaches where compromised agents weaponize legitimate credentials. This joint publication provides an authoritative Five Eyes standard, clarifying that agentic AI should only handle low-risk tasks while forcing enterprises to adopt cryptographically verified agent identities, granular runtime authorization, and bounded autonomy.

❓ What's Missing

The guidance explicitly positions agentic AI as suitable only for low-risk, non-sensitive operational tasks, providing limited guidance on how organizations can securely transition high-impact capabilities into production. It also emphasizes the current immaturity of agentic cybersecurity tooling, threat taxonomies, and benchmarking standards without supplying ready-to-implement cryptographic protocols, unified logging schemas, or concrete code-level configuration examples for specific commercial orchestration frameworks.

👥 Best For

Cybersecurity architects, AI developers, platform engineers, CISOs, and IT risk managers across critical infrastructure, defense, and enterprise sectors evaluating, designing, or operating LLM-driven autonomous workflows.

📄 Source Details

  • Title: Careful adoption of agentic AI services
  • Authoring Agencies: Australian Signals Directorate (ASD ACSC), US Cybersecurity and Infrastructure Security Agency (CISA), US National Security Agency (NSA), Canadian Centre for Cyber Security (Cyber Centre), New Zealand National Cyber Security Centre (NCSC-NZ), UK National Cyber Security Centre (NCSC-UK)
  • Publication Year: 2026
  • Resource Type: Technical Security Guidance
  • Core Framework References: Zero Trust Architecture (NIST SP 800-207), MITRE ATLAS, OWASP GenAI Top 10, STPA / CAST (MIT STAMP)

📝 Thanks to

ASD's Australian Cyber Security Centre (ACSC), CISA, NSA, Canadian Centre for Cyber Security, NCSC-NZ, and NCSC-UK for establishing collaborative international security baselines for agentic AI deployments.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.