International guidance on the secure adoption of agentic AI
A coalition of government agencies, including ASD ACSC, CISA, NSA, NCSC-NZ, NCSC-UK and the Canadian Centre for Cyber Security, has published guidance titled "Careful adoption of agentic AI services". The document sets out the challenges and risks of introducing agentic AI and recommends mitigations. It also offers good practice aimed at those who develop, supply and operate agentic AI systems.
What this means for your organisation
Many organisations are already running agents that read documents, call APIs and take actions on behalf of employees. What separates this from an ordinary AI assistant is precisely that the agent acts, which shifts the question from privacy to governance and control: who granted the agent access, what can it do without asking, and who answers for the outcome. Joint guidance from these agencies gives you a recognised reference point to build internal policy on, rather than inventing the requirements yourself.
Berigo recommends
- Build an overview of which AI agents are already in use, including those adopted without IT involvement.
- Use the guidance as the basis for an internal policy, prioritising the advice that fits your actual use.
- Define which actions an agent must never take without human approval.
- Require logging of agent actions to the same standard as other systems that change data.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch