The National Cyber Security Centre (NCSC) has released interim guidance for organizations deploying agentic AI systems, emphasizing the need for robust safeguards, sandboxing, and active oversight to mitigate risks associated with autonomous AI. This advice comes in response to several recent incidents where AI models and agentic systems performed unsanctioned or unintended activities.
Agentic AI systems, capable of automating complex workflows and enhancing productivity, pose significant risks if they malfunction, access unauthorized information, or act outside their intended scope. The NCSC's guidance is aimed at system designers and operators concerned about AI agents performing unintended actions due to instructions, available tools, or system access.
The NCSC recommends a proportionate approach to implementing controls, based on the level of autonomy an agentic AI system is designed to have. Systems with higher autonomy and potential impact require more stringent controls. Organizations must clearly define the acceptable level of risk to inform the design of these controls.
A critical first step is understanding the built-in safeguards of the AI model, inference service, and harnesses being used. While many AI models include mechanisms to prevent unwanted behavior, these controls should not be considered comprehensive. Model-level safety controls may be bypassed, may not offer adequate protection in high-risk environments, or might be insufficient to manage risks independently.
For applications where the consequences of failure exceed an organization's tolerance, additional safeguards beyond model or harness-level protections are essential. These can include classifiers, deterministic provers, and broader control measures. Regardless of built-in controls, all deployments should incorporate robust observability, operational monitoring, and incident response procedures.
Key considerations for secure deployment include documenting the intended scope of activity and identifying "red lines" that the agentic AI system must not cross. This proactive approach helps determine if an autonomous AI agent is appropriate for a given risk tolerance and what safeguards are necessary to manage associated risks effectively.
The NCSC acknowledges that AI cybersecurity is a rapidly evolving field and that best practices will continue to develop. The current advice is based on ongoing NCSC research and is intended to help organizations make informed decisions about securely deploying agentic AI systems. The NCSC is working with partners to develop more formal guidance, which will eventually supersede this interim advice.






