The cybersecurity agencies of the United States, Britain, Canada, Australia, and New Zealand have jointly published their first coordinated guidance on agentic AI security, signalling that autonomous AI systems are now treated as a national security concern across the Five Eyes alliance.

The 30-page document, titled Careful Adoption of Agentic AI Services, was released on May 1 by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency, Britain's NCSC, the Canadian Centre for Cyber Security, New Zealand's NCSC, and Australia's ASD Cyber Security Centre. The opening line of the guidance is striking: organisations should "assume that agentic AI systems may behave unexpectedly" until security practices, evaluation methods and standards catch up.

Five categories of risk

The agencies identify five distinct categories of risk specific to agentic systems, as reported by CyberScoop and The Register.

The first is privilege risk: an agent granted broad system access becomes a single point of failure far worse than a typical software bug. The second is behavioural drift, where an agent pursues its assigned goal in ways its designers never anticipated. The third is prompt injection, which has reached a maturity where attackers embed instructions inside the data an agent reads, hijacking the agent's reasoning loop. The fourth is structural risk arising from communication between multiple agents. The fifth is accountability, the still-unsolved question of who is responsible when an autonomous system causes harm.

Old principles, new context

The guidance is notable for what it does not say. It does not call for a new regulatory regime, and it does not propose agentic-specific certifications. Instead, the agencies argue that existing security principles like zero trust, defence in depth, and least privilege apply to agentic systems too, provided organisations actually apply them.

The specific recommendations are concrete. Each agent should carry a cryptographically verifiable identity. Credentials should be short-lived. Inter-agent traffic should be encrypted by default. Bank Info Security's summary notes that the agencies effectively recommend treating every agent like a junior employee who has just been handed the password vault.

An honest admission

There is a quieter point in the document that deserves more attention. The agencies acknowledge that threat intelligence for agentic AI is "still evolving," because catalogues like OWASP and MITRE ATLAS currently focus on standalone LLMs rather than autonomous systems acting on their behalf. That is an honest admission that the defensive community is genuinely behind the curve.

For the AI industry, the message is that agentic capabilities can no longer be shipped as if they were minor extensions of existing chat products. The Five Eyes have set a baseline, and large enterprises in regulated sectors will start asking vendors to meet it. Forrester has already begun framing the guidance as the de facto floor for procurement teams evaluating agentic vendors.

The guidance lands at the same week the EU agreed to delay parts of its AI Act. The contrast is sharp. Brussels is loosening one set of rules while five national security agencies quietly set another, and the second one is the one enterprise buyers will end up taking more seriously.

Sources

  1. i. cyberscoop.com
  2. ii. www.theregister.com
  3. iii. www.bankinfosecurity.com
  4. iv. www.techgines.com
  5. v. lyrie.ai
  6. vi. www.forrester.com

Commentarii · 0

Add · a · Comment