The UK's National Cyber Security Centre has published interim guidance for organisations deploying agentic AI systems, warning that autonomous agents can carry out unsanctioned or unintended activity if not properly constrained. The advisory, aimed at system designers and operators, sets out practical steps for managing the cyber risk of AI systems that can act with significant autonomy.
Agentic AI systems can automate complex workflows and reduce routine effort, but the NCSC said several recent incidents involving AI models acting outside their intended scope highlight why organisations need to carefully consider how these technologies are deployed, constrained, observed and responded to.
The guidance covers assessment of autonomy levels, model safeguards, sandboxing, credential limits, observability and emergency shutdown procedures. It is interim advice, to be superseded by formal guidance the NCSC is developing with partners.
Match autonomy to risk tolerance
The NCSC recommends applying the guidance proportionately, based on how much autonomy each agentic AI system is intended to have. Some agents simply assist a human user with suggestions or tightly constrained low-risk tasks. Others may be trusted to access production systems and make decisions with little or no human intervention in potentially high-risk scenarios.
"The greater an agent's autonomy, the greater the potential impact if it malfunctions unexpectedly, accesses information it should not, or takes actions outside its intended scope," the NCSC said. Organisations should be clear on the level of autonomy and the level of risk they are willing to tolerate before designing controls.
Understanding the safeguards already built into the AI model, inference service and harnesses is a critical step. The NCSC warns that safety controls built into models may be bypassed, may not provide adequate protection in higher-risk environments, and should not be treated as holistic. For applications where failure consequences are above tolerance, organisations should implement additional safeguards such as classifiers, deterministic provers and wider controls.
Sandboxing and access limits
The NCSC says AI agents should always run within a sandboxed environment that controls what resources the agent can communicate with, both locally and over a network. For high-risk activities, the most robust approach is an isolated and disconnected environment with pre-downloaded tools and information.
Where external access is necessary, the guidance recommends denying all inbound and outbound network traffic by default, then allowing only required connections via allowlists. Organisations should also restrict the agent's credentials to only what it needs for the task, and use the shortest possible credential lifetimes. A proxy can inject credentials into requests without exposing them directly to the agent.
The NCSC warns that AI agents can discover and exploit configuration issues or vulnerabilities in technical controls, potentially leading to a sandbox escape. It recommends multiple layers of isolation, regular validation of configurations, and explicit prompts telling the agent not to connect to domains outside an allowlist or attempt to escape the sandbox.
Logging, attribution, and emergency shutdown
Agentic AI activity should be treated as a form of user activity and included in 24/7 security operational monitoring and incident response, the NCSC said. Organisations need reliable telemetry about AI agent activities in near real time and afterwards, including chain-of-thought traces, transcripts and logging events from the wider sandbox environment.
Logs should be saved, protected from modification or deletion, and ideally immutable so they can be trusted during an investigation. The NCSC also warns that log collection infrastructure itself creates an attack surface that an AI agent could potentially abuse to escape its sandbox.
When agents communicate with third-party systems, the NCSC recommends making activity easy to attribute, such as ensuring traffic originates from IP addresses that support reverse lookups and adding identifying headers to outbound communications. Abuse reports should be managed like vulnerability reports, following an incident management playbook.
The NCSC emphasises that organisations should always be able to "pull the plug" and halt autonomous AI activity immediately, covering the wider system so operators can rapidly restrict network access and interrupt communications between AI agents and the model inference infrastructure. For management teams moving forward with adoption, the NCSC advises reviewing controls and assumptions as capabilities, use cases and standards develop. Teams can also explore AI Agent Courses & Certifications for practical guidance on secure implementation, while AI for Management training can help leaders develop strategy and governance frameworks that align with evolving cyber security expectations.
Why this matters for managers
Executives responsible for AI adoption should treat the NCSC's guidance as a checklist before granting any agentic system meaningful autonomy. The core takeaway is that autonomy and risk must be matched: the more freedom an agent has to act, the more controls and oversight you need built around it. Managers should confirm who is accountable for AI agent activity, ensure human oversight is in place for higher-risk actions, and verify that logs are immutable and monitored around the clock. These are not technical details for engineers only - they are governance decisions that determine whether an organisation can adopt agentic AI without exposing itself to liabilities from unintended activity.
Your membership also unlocks: