HomeSecurityNCSC recommends cautious adoption of agentic AI

NCSC recommends cautious adoption of agentic AI

The UK's National Cyber ​​Security Centre (NCSC) recommends cautious adoption of agentic AI, highlighting the increasing cyber risks and operational risks associated with highly autonomous AI systems.

agentic AI

In a new guidance document, co-signed with international partners, the NCSC said that businesses should not rush into mass deployment of agentic AI and first understand the security implications. The guidelines recommend starting with low-risk cases, limiting system privileges and maintaining strong human oversight during deployment.

The advice comes as organizations increasingly experiment with AI systems capable of making decisions, accessing tools , and performing actions with limited human intervention.

See also: Claw Chain: OpenClaw vulnerabilities allow complete system compromise

What is Agentic AI?

Unlike traditional generative AI, which primarily generate text, images, or predictions, agentic AI systems are designed to pursue goals independently. These systems can access data sources, remember context, make decisions, interact with software tools, and even create sub-agents to complete tasks.

According to the NCSC, this additional autonomy makes agentic AI useful for areas such as cyber defense, workflow automation, and operational efficiency. However, it also introduces a broader attack surface and increases the difficulty of monitoring system behavior.

The agency noted that many of the security risks associated with AI are not entirely new. Concerns around access control, supply chain security, monitoring and incident response already exist in traditional IT systems. Agentic AI systems also inherit existing risks from large language models, including command injection attacks and jailbreaking attacks.

However, the NCSC warned that the autonomy of agentic AI systems could amplify these issues, especially if organizations deploy them without appropriate safeguards.

NCSC recommends cautious adoption of agentic AI

Why Agentic AI Increases Security Risks

The guidelines outline several risks associated with agentic AI deployments. One of the main issues is broader access to systems and sensitive data. AI agents may interact with external tools, APIs, or databases in ways that traditional AI applications do not.

See also: TeamPCP sells Mistral AI code repos

The NCSC also highlighted the potential for unpredictable behavior. Since AI agents interpret goals autonomously, they may take actions that differ from human expectations or exceed their intended scope.

Another challenge is visibility and oversight. Autonomous systems can operate at speeds that make meaningful human review difficult, particularly in business environments where many systems and workflows are interconnected.

The guidelines further noted that explaining the behavior of agentic AI systems can be more difficult than understanding conventional AI models. The combination of decision-making, tool use, and autonomous actions creates additional complexity during incident investigations or compliance audits.

NCSC Calls for Phased Development of Agentic AI

To reduce risks, the NCSC urged organizations to adopt agentic AI gradually rather than deploying it in critical systems from the start.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Authorities recommend tightly controlled pilot deployments focused on clearly defined, low-risk tasks. Organizations are also encouraged to assess whether AI is truly necessary before integrating autonomous agents into existing workflows.

“If you can’t understand, monitor, or constrain an agent’s actions, it’s not ready for deployment,” the guideline states.

The agency stressed that organizations should never provide unrestricted access to sensitive data or critical infrastructure. Maintaining visibility into AI system behavior and maintaining meaningful human control were identified as key requirements for secure deployment.

See also: OpenAI confirms breach via TanStack supply chain attack

NCSC recommends cautious adoption of agentic AI

Human Responsibility Remains Necessary

Despite the growing capabilities of autonomous AI systems, the NCSC stressed that humans remain fully responsible for how these technologies are used. The guidance states that organizations should clearly define who is responsible for approving AI access, monitoring system behavior, reviewing incidents , and shutting down systems when necessary.

Security teams are also urged to integrate agentic AI risk management into existing frameworks and governance rather than treating AI security as a separate process.

Recommended practices include implementing least-privilege access controls , limiting system scope , avoiding long-lived credentials , monitoring for unusual behavior , and planning for incidents involving AI misuse or loss of control .

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS