The UK National Cyber Security Centre (NCSC) has issued interim guidance warning organizations to tightly constrain agentic AI systems after incidents in which AI models carried out unintended or unsanctioned actions. The agency said deployments should grant only the minimum autonomy required, use human oversight, and avoid depending solely on built-in model safety features. It urged teams to threat-model agent behavior, understand model safeguards and failure modes, and design response plans before autonomous systems are put into production.
The guidance recommends layered technical controls, including robust sandboxing, strict separation between agent execution and supporting infrastructure, default-deny network access, least-privilege credentials, and distinct identities for each agent. NCSC also called for comprehensive logging and monitoring, clear attribution of AI-originated activity, named human accountability, and an emergency capability to immediately stop autonomous operations. The agency described the advice as an interim measure based on ongoing research, with more formal guidance in development alongside partners.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
On 20 August 2026, the UK National Cyber Security Centre published a blog post with interim practical advice for organizations building or operating agentic AI systems. The guidance urges measures such as limiting autonomy, threat modelling, sandboxing, human oversight, strict credential scoping, monitoring, and emergency shutdown capability, while noting that more formal guidance is still being developed.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.