Careful adoption of agentic AI services
ASD ACSC hosts primary joint guidance from ASD ACSC, CISA, NSA, the Canadian Centre for Cyber Security, NCSC-NZ, and NCSC-UK on careful adoption of agentic AI services for operators that design, deploy, or operate LLM-based agentic systems.
Date
May 1, 2026
First Seen
May 1, 2026
Last Reviewed
May 13, 2026
Publisher
ASD Australian Cyber Security Centre
Source Type
docs
Source Summary
What It Contains
ASD ACSC hosts primary joint guidance from ASD ACSC, CISA, NSA, the Canadian Centre for Cyber Security, NCSC-NZ, and NCSC-UK on careful adoption of agentic AI services for operators that design, deploy, or operate LLM-based agentic systems.
Extracted Claims
- Agentic AI systems inherit LLM risks such as prompt injection while adding risk from autonomy, tool access, memory, external data sources, integrations, and delegated execution.
- Organisations should not grant agentic AI broad or unrestricted access, especially to sensitive data or critical systems.
- Recommended deployment posture includes incremental rollout, low-risk use cases, strict privilege controls, strong identity management, continuous monitoring, human oversight, and alignment with existing security frameworks.
- For tool-using agents, external data sources and two-way tool integrations can introduce instruction backflow, confused-deputy behavior, unsafe tool chaining, and accountability gaps.
Evidence Quality
Primary official multi-agency guidance. Strong evidence for canonical controls around least privilege, sandboxing, monitoring, approval gates, and operational risk assessment for OpenClaw-style local agent deployments.
Follow-Up
- Use this primary source instead of secondary coverage when explaining the agentic AI careful-adoption control family.
- Track concrete incidents or vulnerability reports that demonstrate these guidance categories in deployed coding or tool-using agent systems.