ARTICLE
1 May 2026

CISA And ASDs ACSC Publish Joint Guidance On Securing Agentic AI Systems

AO
A&O Shearman

Contributor

A&O Shearman was formed in 2024 via the merger of two historic firms, Allen & Overy and Shearman & Sterling. With nearly 4,000 lawyers globally, we are equally fluent in English law, U.S. law and the laws of the world’s most dynamic markets. This combination creates a new kind of law firm, one built to achieve unparalleled outcomes for our clients on their most complex, multijurisdictional matters – everywhere in the world. A firm that advises at the forefront of the forces changing the current of global business and that is unrivalled in its global strength. Our clients benefit from the collective experience of teams who work with many of the world’s most influential companies and institutions, and have a history of precedent-setting innovations. Together our lawyers advise more than a third of NYSE-listed businesses, a fifth of the NASDAQ and a notable proportion of the London Stock Exchange, the Euronext, Euronext Paris and the Tokyo and Hong Kong Stock Exchanges.
International cybersecurity authorities have released comprehensive guidance on the secure deployment of agentic AI systems, which autonomously reason, plan and execute actions with limited human intervention. The guide addresses critical security risks including inherited LLM vulnerabilities, expanded attack surfaces, and reduced accountability, while recommending organizations embed security controls from the outset and adopt a progressive deployment approach starting with lower-risk tasks.
Australia Technology
Anna Gamvros’s articles from A&O Shearman are most popular:
  • in European Union
A&O Shearman are most popular:
  • within Insolvency/Bankruptcy/Re-Structuring and Consumer Protection topic(s)

On May 1, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA) and the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), together with cybersecurity authorities from Canada, New Zealand and the United Kingdom, published a guide titled “Careful Adoption of Agentic Artificial Intelligence (AI) Services” (the Guide).

The Guide is directed at organisations that design, develop, deploy and operate agentic AI systems and addresses the cybersecurity risks associated with their deployment, particularly in critical infrastructure and defence settings.

The Guide explains that agentic AI systems are AI systems which autonomously reason, plan and execute actions by combining large language models (LLMs) with external tools and data sources. The Guide notes that these systems are increasingly being deployed across government, critical infrastructure and industry environments to perform complex tasks with limited human intervention.

The Guide recommends that organisations should align agentic AI risks and mitigation strategies with their existing security model and risk posture and should only use agentic AI for low-risk and non-sensitive tasks.

Key risks

The Guide identifies several cybersecurity risks that agentic AI systems introduce for organisations deploying them, such as:

  • vulnerabilities inherited from the underlying LLMs (such as susceptibility to prompt injection and data poisoning)
  • an expanded attack surface arising from the system's reliance on external tools, memory components and integrations
  • increased system complexity, which can lead to cascading failures and make it difficult to isolate compromised components
  • privilege and identity risks, where agents with excessive permissions may be exploited or misused to perform unauthorised actions
  • reduced accountability and visibility, as autonomous and opaque decision-making processes can complicate monitoring, auditing and incident response.

Recommended practices

The Guide sets out several recommended practices for organisations to mitigate these risks. A central theme is that security should be embedded from the outset; organisations should design agentic AI systems with built-in security controls and least-privilege access and implement strong identity and access management for AI agents, including assigning distinct identities and continuously authenticating agent interactions.

The Guide also emphasises the importance of rigorous testing, evaluation and red-teaming throughout the system's lifecycle to identify security weaknesses and unintended behaviours. Rather than deploying agentic AI at full capability from the start, the Guide recommends a progressive approach, beginning with lower-risk tasks and expanding the system's autonomy only as security controls mature. Organisations should maintain continuous monitoring and logging of agent behaviour and tool usage and should retain meaningful human oversight over high-impact or irreversible actions.

The Guide concludes by noting that until security practices, evaluation methods and standards mature, organisations should assume that agentic AI systems may behave unexpectedly and should plan deployments accordingly, prioritising resilience, reversibility and risk containment over efficiency gain.

The Guide is available here and the ASD's ACSC press release is available here.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More