中文

Six Countries Including the US and Australia Jointly Release Guidelines for Safe Deployment of Agentic AI

Governments of six countries, including Australia and the United States, jointly released guidelines for the safe deployment of agentic AI, emphasizing prudent adoption, risk management, and human oversight.

2026-05-019views
Six Countries Including the US and Australia Jointly Release Guidelines for Safe Deployment of Agentic AI

Australia, together with the U.S. government and international partners including the UK, Canada, and New Zealand, released a guidance document on the secure deployment of agentic AI systems this Friday (May 15, 2026). The document aims to provide enterprises and organizations with a framework for identifying and managing risks to address the unique security challenges posed by agentic AI.

Unique Risks of Agentic AI

The guidance document notes that the automation capabilities of agentic AI may lead to "productivity loss, service disruption, privacy breaches, or cybersecurity incidents." It emphasizes: "Organizations must anticipate what could go wrong, assess the impact of agentic AI risk scenarios on operations, and establish continuous visibility and assurance mechanisms to maintain confidence in agentic AI investments."

The document also warns that secure use of agentic AI means "never granting it broad or unrestricted access, especially to sensitive data or critical systems." Enterprises "should only use agentic AI for low-risk and non-sensitive tasks."

Background of the Joint Release

The document was jointly released by the Australian Signals Directorate (ASD), the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), along with their counterparts in the UK, Canada, and New Zealand. It comes as enterprises are racing to integrate AI tools into workflows and increasingly adopting agentic AI to automate repetitive tasks.

Systemic Risks and Expanded Attack Surface

The document reminds organizations to fully understand the risks associated with agentic AI tools when evaluating them. Agentic AI is a complex system whose interconnected components create "systemic risks," and it relies on large language models and external data sources, which may introduce their own vulnerabilities—for example, maliciously crafted web search results can lead to prompt injection attacks.

The document states: "Every individual component in an agentic AI system expands the attack surface, exposing the system to more exploitable pathways." Additionally, the immaturity of AI security standards and the difficulty of applying human-centered governance models to automated technologies also make agentic AI tools less resilient to disruption or failure.

Specific Risks and Best Practices

The document lists security risks unique to agentic AI, including permission abuse, identity spoofing, unintended behavior, and deception. It also outlines risks that may arise when agentic AI is integrated with other tools, such as orchestration parameter flaws and tampering with third-party components.

In terms of best practices, the document recommends implementing strict controls over agent behavior, strengthening identity management, and establishing robust segregation of duties mechanisms to prevent cascading failures. Enterprises should also regularly evaluate agents, including red team exercises and verification of third-party components.

Other recommendations include continuous monitoring of agentic AI systems, validation of agent outputs, and human approval for actions where "errors are costly," such as system resets, network egress, or deletion of critical records.

"Strong governance, clear accountability, rigorous monitoring, and human oversight are not optional safeguards but necessary prerequisites." The document warns, "Until security practices, assessment methods, and standards mature, organizations should assume agentic AI systems may behave unexpectedly and plan deployment accordingly, prioritizing resilience, reversibility, and risk containment over efficiency gains."