Skip to main content
Policy AI

Five Eyes agencies publish guidance on securing agentic AI deployments

Five Eyes agencies publish guidance on securing agentic AI deployments Image: Primary
Cybersecurity agencies from the United States, Australia, Canada, New Zealand and the United Kingdom jointly published guidance Friday urging organizations to treat autonomous artificial-intelligence systems as a core cybersecurity concern, warning that the technology is already being deployed in critical infrastructure and defense sectors with insufficient safeguards. The document focuses on agentic AI, software built on large language models that can plan, make decisions and take actions autonomously. Co-authored by the U.S. Cybersecurity and Infrastructure Security Agency, the National Security Agency and their counterparts in the four allied nations, the guidance argues that agentic AI does not require a separate security discipline. Instead, organizations should integrate it into existing cybersecurity frameworks, applying principles such as zero trust, defense-in-depth and least-privilege access. The agencies identify five broad categories of risk. The first is privilege: agents granted too much access can cause far more damage than a typical software vulnerability if compromised. The second covers design and configuration flaws that create security gaps before systems go live. The third is behavioral risk, where an agent pursues a goal in ways its designers never intended. The fourth is structural risk, in which interconnected networks of agents trigger failures that spread across systems. The fifth is accountability, because agentic systems make decisions through processes that are difficult to inspect and generate logs that are hard to parse. The guidance also flags prompt injection, a technique in which malicious instructions embedded inside data hijack an agent's behavior. The document devotes significant attention to identity management, recommending that each agent carry a cryptographically secured identity, use short-lived credentials and encrypt all communications. For high-impact actions, a human should approve the decision, and the guidance is explicit that determining which actions require that approval is a task for system designers, not the agent itself. The agencies acknowledge that the security field has not fully caught up with agentic AI. Some risks unique to these systems are not yet covered by existing frameworks. The document calls for more research and collaboration, and advises organizations to prioritize resilience, reversibility and risk containment over efficiency gains until security practices and evaluation methods mature.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from CyberScoop and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Products
AI Products

AWS makes GPT-6 Astra generally available on Bedrock

AWS said OpenAI's GPT-6 Astra is now generally available through Amazon Bedrock. The company says customers can call the model through supported Bedrock APIs or configure ChatGPT Work and Codex to use it on Bedrock. AWS describes ...

Capital AI
Capital AI

Temporal raises $550 million at $12.55 billion valuation

Temporal said it raised $550 million in a late-stage funding round led by Lightspeed, Reuters reported. The company makes open-source software intended to help applications, including AI agents, recover from failures. Reuters said...

Capital AI
Capital AI

Buildots raises $130 million for construction AI platform

Buildots, a startup using AI to help accelerate construction of data centers, chip factories and hospitals, raised $130 million in new financing, Bloomberg reported. The bounded report does not identify investors, the financing ty...

AI Capital
AI Capital

Tandem Health raises €86.49 million for European clinic AI platform

Stockholm-based Tandem Health has raised €86.49 million ($100 million) in a Series B led by EQT-managed Scaleup Europe Fund, bringing its total funding to €138.38 million. Tandem said its medical-assistant software supports clinic...

Capital Products
Capital Products

Ferm Labs raises €3 million for ingredient bioprocessing expansion

Ferm Labs, a Zug-based B2B ingredient startup, secured €3 million to scale its bioprocessing platform, according to EU-Startups. CDP Venture Capital led the round through its Green Transition Fund/NextGenerationEU, joined by Fund...

AI Products
AI Products

TSA deploys traveler-support AI agent, Salesforce says

The Transportation Security Administration has deployed Ace, an AI agent built with Salesforce Public Sector Solutions, Salesforce said. The company says Ace went live during the summer travel surge and now handles about 100,000 r...