U.S., Australia and Five Eyes partners issue first joint agentic AI security guide
On May 1, 2026, CISA, the NSA, and cyber authorities from Australia, Canada, New Zealand, and the UK released joint guidance on securing autonomous AI agents. Titled "Careful Adoption of Agentic Artificial Intelligence (AI) Services," the document targets organizations designing, developing, deploying, and operating agentic AI systems—particularly those in critical infrastructure and defense. The agencies identified new cybersecurity risks specific to autonomous agents: prompt injection, data poisoning, expanded attack surfaces from tool integrations, over-privileged agents, cascading failures, and reduced accountability. Core recommendations include applying least privilege principles, implementing strong identity and access management, continuous monitoring and logging, rigorous testing and red-teaming, and meaningful human oversight for high-impact or irreversible actions.