{"id":649308,"date":"2026-05-04T16:00:10","date_gmt":"2026-05-04T16:00:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/649308\/"},"modified":"2026-05-04T16:00:10","modified_gmt":"2026-05-04T16:00:10","slug":"five-eyes-warn-agentic-ai-is-too-dangerous-for-rapid-rollout-the-register","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/649308\/","title":{"rendered":"Five Eyes warn agentic AI is too dangerous for rapid rollout \u2022 The Register"},"content":{"rendered":"<p>Information security agencies from the nations of the Five Eyes security alliance have co-authored guidance on the use of agentic AI that warns the technology will likely misbehave and amplifies organizations\u2019 existing frailties, and therefore recommend slow and careful adoption of the tech.<\/p>\n<p>The agencies delivered that position last Friday in a guide titled <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/regmedia.co.uk\/2026\/05\/04\/supplied_careful_adoption_of_agentic_ai_services.pdf%E2%80%9D\">Careful adoption of agentic AI services<\/a> [PDF] that opens with the observation that \u201cAgentic artificial intelligence (AI) systems increasingly operate across critical infrastructure and defense sectors and support mission-critical capabilities,\u201d making it \u201ccrucial for defenders to implement security controls to protect national security and critical infrastructure from agentic AI-specific risks.\u201d<\/p>\n<p>Until security practices, evaluation methods and standards mature, organisations should assume that agentic AI systems may behave unexpectedly<\/p>\n<p>The thrust of the document is that implementing agentic AI will require use of many components, tools, and external data sources, creating an \u201cinterconnected attack surface that malicious actors can exploit.\u201d<\/p>\n<p>\u201cConsequently, every individual component in an agentic AI system widens the attack surface, exposing the system to additional avenues of exploitation,\u201d the document warns.<\/p>\n<p>To illustrate the risks agentic AI poses, the document offers the example of an AI agent empowered to install software patches that is thoughtlessly given broad write access permissions, with the following unpleasant results:<\/p>\n<p>Here\u2019s another nasty agentic mess the document uses as a warning:<\/p>\n<p>An organization deploys agentic AI to autonomously manage procurement approvals and vendor communications, and gives the agent access to financial systems, email and contract repositories;<\/p>\n<p>This user only considers permissions for the agent when deploying it;<\/p>\n<p>Over time, other agents rely on the procurement agent\u2019s outputs and implicitly trust its actions;<\/p>\n<p>A malicious actor compromises a low-risk tool integrated into the agent\u2019s workflow and inherits the agent\u2019s over-generous privileges;<\/p>\n<p>The attacker uses that privileged access to modify contracts and approve unauthorized payments, and evades detection by creating faked audit logs that don\u2019t trip alerts.<\/p>\n<p>Australia\u2019s Signals Directorate and Cyber Security Centre (ASD\u2019s ACSC) contributed to the document, working with the USA\u2019s Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA), the Canadian Centre for Cyber Security (Cyber Centre), the New Zealand National Cyber Security Centre (NCSC-NZ) and the United Kingdom National Cyber Security Centre (NCSC-UK).<\/p>\n<p>The document contains more scary stories, then lists 23 different risks and over 100 individual best practices to address them.<\/p>\n<p>Much of the advice targets developers who deploy AI, but the authors also urge vendors to ensure they test their wares thoroughly and ensure their products \u201cfail-safe by default requiring agents to stop and escalate issues to human reviewers in uncertain scenarios.\u201d<\/p>\n<p>The document also urges security practitioners and researchers to spend more time contemplating AI.<\/p>\n<p>\u201cThreat intelligence for agentic AI systems is still evolving, which can introduce significant security gaps,\u201d the document warns, because resources like the Open Web Application Security Project and MITRE ATLAS currently focus on LLMs. \u201cAs a result, some attack vectors unique to agentic AI may not be fully captured or addressed.\u201d<\/p>\n<p>Given the huge to-do list for anyone creating agentic AI, or contemplating its use, the document argues for very cautious adoption.<\/p>\n<p>Prioritize resilience, reversibility and risk containment over efficiency gains<\/p>\n<p>\u201cOrganisations should therefore approach adoption with security in mind, recognizing that increased autonomy amplifies the impact of design flaws, misconfigurations and incomplete oversight,\u201d the document concludes. \u201cDeploy agentic AI incrementally, beginning with clearly defined low-risk tasks and continuously assess it against evolving threat models.\u201d<\/p>\n<p>\u201cStrong governance, explicit accountability, rigorous monitoring and human oversight are not optional safeguards but essential prerequisites. Until security practices, evaluation methods and standards mature, organisations should assume that agentic AI systems may behave unexpectedly and plan deployments accordingly, prioritizing resilience, reversibility and risk containment over efficiency gains.\u201d \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Information security agencies from the nations of the Five Eyes security alliance have co-authored guidance on the use&hellip;\n","protected":false},"author":2,"featured_media":649309,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[256,254,255,64,63,105],"class_list":["post-649308","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-au","tag-australia","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/649308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=649308"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/649308\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/649309"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=649308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=649308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=649308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}