The UK’s National Cyber Security Centre (NCSC) urging organizations deploying agentic AI systems to follow stronger security controls, here are four experts with comments on these recommendations.
Agentic AI systems have shown potential to transform how organisations work, at times delivering unparalleled productivity gains. They can automate complex workflows, reduce routine effort and enable people to focus on higher-value tasks.
As organisations deploy increasingly autonomous uses of AI at pace, it is important to consider how these systems behave when they do not function as envisaged or expected – and plan accordingly.
Recently, there have been several incidents involving AI models and agentic AI systems carrying out unsanctioned or unintended activity. These events highlight why organisations need to carefully consider how these technologies are deployed, constrained, observed and responded to.
John Strand, Owner, Black Hills Information Security, Inc.:
“I absolutely love this.These recommendations and guidelines actually look like they were written by people who have spent time working with AI and testing these systems in the real world. They’re practical, they make sense, and frankly, I wish we’d had guidance like this five years ago. But we’ll take it now. Once again, it feels like the EU is considerably further ahead of the United States when it comes to establishing meaningful guidance and requirements around how these tools are tested and used.”
Seemant Sehgal, Founder & CEO, BreachLock:
“Agentic AI changes the security model because software is no longer just responding to instructions; it is making decisions and taking actions on its own. Giving an AI agent broad access without clear guardrails is similar to handing out privileged accounts without oversight. The strongest offensive security approach is to treat every agent as a potential point of failure, limit what it can reach, require human review for high-impact actions, and continuously verify that its behavior matches its intended purpose.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“The NCSC published a controls checklist for a problem most organizations haven’t scoped yet. Sandboxing, least privilege, human approval gates, continuous monitoring, all sound right. They also assume you know which agents are running in your environment, what credentials they hold, and which systems they can reach. Most enterprises cannot answer those questions.
“Shadow AI is harder to inventory than shadow IT ever was. An employee spinning up a SaaS application left a procurement trail. An employee configuring an AI agent inside an already-approved platform like Salesforce or Microsoft 365 leaves none. The agent inherits the platform’s existing access, never triggers a security review, and no one in procurement knows it exists.
“The gap widens when agents acquire credentials at runtime, spawn subagents, or chain actions across multiple systems in a single task. Every delegation step creates an identity your IAM system was never designed to track. Most organizations have no ownership model for agent identities and cannot trace an agent’s action back to the human who authorized it.
“These recommendations are step three of a three-step problem. Step one is discovery, mapping which agents exist and who deployed them. Step two is measurement, tracking what those agents actually do at runtime. Most organizations are stuck on step one.
“You cannot sandbox what you have not found. You cannot scope permissions for credentials you have not inventoried.”
Doc McConnell, Head of Policy and Compliance, Finite State:
“This NCSC guidance shows that the recent incidents of autonomous AI agents breaking out of testing environments and executing cybersecurity intrusions have already shifted the risk calculus.
“The NCSC offers two specific pieces of guidance that feel provocative in a time when so many organizations are racing to implement agentic AI in faster, more autonomous ways. First, the NCSC recommends formal threat modeling of AI escape scenarios. Second, it applies a familiar ‘zero trust’ model to agentic AI, including robust sandboxing and deny-by-default permission structures. This shifts the conversation around AI governance from treating agents as potentially reckless to treating them as actively adversarial.”
I pretty much said it earlier today but I will say it again. If you are running AI without guard rails, you are asking for trouble. Organizations need to take that into account or bad things wll happen.
Related
This entry was posted on August 21, 2026 at 3:34 pm and is filed under Commentary with tags UK. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
NCSC urges stronger security controls for agentic AI
The UK’s National Cyber Security Centre (NCSC) urging organizations deploying agentic AI systems to follow stronger security controls, here are four experts with comments on these recommendations.
Agentic AI systems have shown potential to transform how organisations work, at times delivering unparalleled productivity gains. They can automate complex workflows, reduce routine effort and enable people to focus on higher-value tasks.
As organisations deploy increasingly autonomous uses of AI at pace, it is important to consider how these systems behave when they do not function as envisaged or expected – and plan accordingly.
Recently, there have been several incidents involving AI models and agentic AI systems carrying out unsanctioned or unintended activity. These events highlight why organisations need to carefully consider how these technologies are deployed, constrained, observed and responded to.
John Strand, Owner, Black Hills Information Security, Inc.:
“I absolutely love this.These recommendations and guidelines actually look like they were written by people who have spent time working with AI and testing these systems in the real world. They’re practical, they make sense, and frankly, I wish we’d had guidance like this five years ago. But we’ll take it now. Once again, it feels like the EU is considerably further ahead of the United States when it comes to establishing meaningful guidance and requirements around how these tools are tested and used.”
Seemant Sehgal, Founder & CEO, BreachLock:
“Agentic AI changes the security model because software is no longer just responding to instructions; it is making decisions and taking actions on its own. Giving an AI agent broad access without clear guardrails is similar to handing out privileged accounts without oversight. The strongest offensive security approach is to treat every agent as a potential point of failure, limit what it can reach, require human review for high-impact actions, and continuously verify that its behavior matches its intended purpose.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“The NCSC published a controls checklist for a problem most organizations haven’t scoped yet. Sandboxing, least privilege, human approval gates, continuous monitoring, all sound right. They also assume you know which agents are running in your environment, what credentials they hold, and which systems they can reach. Most enterprises cannot answer those questions.
“Shadow AI is harder to inventory than shadow IT ever was. An employee spinning up a SaaS application left a procurement trail. An employee configuring an AI agent inside an already-approved platform like Salesforce or Microsoft 365 leaves none. The agent inherits the platform’s existing access, never triggers a security review, and no one in procurement knows it exists.
“The gap widens when agents acquire credentials at runtime, spawn subagents, or chain actions across multiple systems in a single task. Every delegation step creates an identity your IAM system was never designed to track. Most organizations have no ownership model for agent identities and cannot trace an agent’s action back to the human who authorized it.
“These recommendations are step three of a three-step problem. Step one is discovery, mapping which agents exist and who deployed them. Step two is measurement, tracking what those agents actually do at runtime. Most organizations are stuck on step one.
“You cannot sandbox what you have not found. You cannot scope permissions for credentials you have not inventoried.”
Doc McConnell, Head of Policy and Compliance, Finite State:
“This NCSC guidance shows that the recent incidents of autonomous AI agents breaking out of testing environments and executing cybersecurity intrusions have already shifted the risk calculus.
“The NCSC offers two specific pieces of guidance that feel provocative in a time when so many organizations are racing to implement agentic AI in faster, more autonomous ways. First, the NCSC recommends formal threat modeling of AI escape scenarios. Second, it applies a familiar ‘zero trust’ model to agentic AI, including robust sandboxing and deny-by-default permission structures. This shifts the conversation around AI governance from treating agents as potentially reckless to treating them as actively adversarial.”
I pretty much said it earlier today but I will say it again. If you are running AI without guard rails, you are asking for trouble. Organizations need to take that into account or bad things wll happen.
Share this:
Like this:
Related
This entry was posted on August 21, 2026 at 3:34 pm and is filed under Commentary with tags UK. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.