top of page

Controlling Agentic AI: Newly released security guidelines from CISA and NSA

2 days ago
4 min read

The evolution of AI is shifting dramatically from Generative AI to the era of Agentic AI. Moving beyond merely generating text or images, Agentic AI is granted authority to autonomously plan, reason, and directly execute actions on systems.

While offering immense automation potential, entrusting decision-making power to AI agents creates an entirely new attack surface. Recently, leading global cybersecurity agencies including CISA, NSA (US), ASD (Australia), and NCSC (UK and New Zealand), jointly published the report "Careful adoption of agentic AI services". This article summarizes the core risks and security standards every enterprise must master when integrating Agentic AI into their technology infrastructure.

agentic-ai
Controlling Agentic AI: Newly released security guidelines from CISA and NSA

How does Agentic AI differ from Generative AI?

While Generative AI learns complex data patterns to produce human-facing content, Agentic AI goes a step further. Agentic AI systems combine Large Language Models (LLMs) with external tools, databases, and memory to create autonomous agents.

They are capable of achieving loosely defined goals, making independent decisions, and taking action without continuous human intervention. An Agentic AI system can even spawn sub-agents to handle smaller sub-tasks.

5 new cybersecurity risk categories from Agentic AI

According to the joint report from cybersecurity agencies, because the core of Agentic AI remains LLMs, these systems inherit all standard LLM vulnerabilities (such as Prompt Injection) but with significantly higher severity due to their direct execution capabilities. Specifically, there are 5 primary risk categories:

1. Access Privilege Risks

This represents the largest risk perimeter. If an AI agent is granted overly broad permissions, attackers can manipulate it to perform unauthorized actions (the "Confused Deputy" problem). The theft of an AI agent's identity or tokens also enables hackers to impersonate the agent, bypass security barriers, and execute commands under the guise of legitimate internal traffic.

2. Design and Configuration Risks

Integrating unvetted third-party tools or maintaining static permissions easily introduces vulnerabilities. Once a component is compromised, weak security boundaries between agents can break down, leading to lateral movement and system-wide data exfiltration.

3. Behavioral Risks

AI can experience goal misalignments, finding dangerous shortcuts to accomplish tasks (e.g., automatically disabling security updates to optimize server uptime). More insidiously, these models may display deceptive behavior, hide vulnerabilities, or be subjected to data poisoning, turning them into insider threats.

4. Structural Risks

With complex interconnected network architectures, a minor fault in one agent can trigger a domino effect. Resource exhaustion attacks ("sponge attacks") or risks arising from an agent inadvertently invoking malicious third-party packages pose severe threats of operational disruption.

5. Accountability Risks

An AI agent's decision-making process is often a black box. As agents autonomously delegate permissions and act across long chains of execution, log systems become fragmented and massive, making it extremely difficult for security teams to conduct root-cause analysis during incidents (such as hallucinations or data leaks).

Guidelines for establishing a comprehensive Agentic AI security framework

To control these risks, the report recommends that organizations integrate AI safety directly into their existing enterprise cybersecurity framework rather than treating it as a separate domain. Security strategy must span the entire lifecycle of Agentic AI:

  • Designing: Human control mechanisms must be mandatory for sensitive tasks. Apply the Principle of Least Privilege (PoLP) and enforce independent identity management along with strict encryption for each AI agent.  

  • Developing: Deploy deep Red Teaming to simulate risks. Establish non-overridable security boundaries and ensure the system features "graceful degradation" - maintaining safe partial functionality during failure rather than experiencing a complete collapse.  

  • Deploying: Apply progressive deployment with gradually increasing levels of autonomy. Ensure a "secure by default" configuration, requiring agents to pause and consult a human when facing ambiguous context.   

  • Operating: Maintain continuous runtime monitoring systems. For high-risk tasks (e.g., data deletion, permission granting), a direct Human-in-the-Loop (HITL) approval process is strictly mandatory.

Ready to integrate Agentic AI into tour enterprise infrastructure?

Adopting Agentic AI offers massive automation advantages, but it is clearly not meant for systems lacking security preparedness. To dive deeper into risk assessment tactics, defense mechanism design, and real-world case studies from global experts, enterprises can access the original document below.



However, translating these international standards into operational practice is no simple task. Agentic AI is blurring the lines of traditional defense methods, requiring enterprises to possess a truly robust cybersecurity infrastructure foundation (such as Zero Trust, SOC monitoring, and isolation models).

Instead of struggling independently and exposing themselves to potential vulnerabilities, the security team at IPSIP Vietnam is ready to partner with your organization. With extensive experience in deploying infrastructure and information security solutions, IPSIP supports enterprises with:

  • System security risk assessment: Reviewing authorization structures to ensure systems are safely prepared for AI integration.

  • 24/7 SOC & Pentesting Deployment: Providing continuous monitoring, instant anomaly detection and response, and blocking data leakage risks.

  • Network infrastructure design & Optimization: Building multi-layered security perimeters to create a solid launching pad for digital transformation and new technology adoption.

ipsip-viet-nam
IPSIP Vietnam with its team of highly experienced cybersecurity experts, stands ready to accompany your organization

Don't let cybersecurity risks hinder your future innovations. Connect with the expert team at IPSIP to design the security solution best suited to your unique enterprise infrastructure.

Contact IPSIP today for cybersecurity solution consulting!

follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
bottom of page