Have you been considering deploying AI agents and want some guidance on security issues you need to consider? Then head to the National Cyber Security Centre’s website as they have co-authored a set of guidelines covering just that.
The guidance urges organisations to:
-
consider existing risks which are amplified by agentic AI, e.g. access control, supply chain risk, monitoring, incident response and accountability and the fact agents inherit known LLM weaknesses such as jailbreaking and prompt injection.
-
adopt a think before you deploy approach. What could go wrong? Is AI needed for this?
-
start small, using agents only for tightly defined, low‑risk tasks, and embedding existing cyber security controls from day one.
-
ensure a human being owns the system, approving its access, monitoring its use and able to stop it if necessary.
-
adopt cyber security best practices such as least privilege, incident planning, monitoring etc.
-
make sure they can understand, monitor and contain an agent’s actions.
The full guidance can be found here.