The National Cyber Security Centre (NCSC) has produced new guidance surrounding agentic AI and its cyber risks.
The new blog notes that the autonomous and complex nature of agentic systems make them more dangerous and introduces new risks to the cyber and AI landscapes.
The NCSC is warning organisations to be wary of giving agentic AI models wider access to data, tools, and external systems, as this could lead to unpredictable outcomes.
Agentic AI’s speed, while an asset, also makes it harder to spot problems as it moves faster than humans can meaningfully review it.
The model’s actions are also difficult to fully explain, due to the range of behaviours and tools available to the agents.
Because of these factors, the NCSC as well as international partners are calling on organisations to approach agentic AI adoption carefully.
Over-privileged or poorly designed agents can turn even a single failure into a serious incident.
Organisations should carefully consider what could go wrong when deploying agentic AI, and should equally reflect if AI is really needed or if a lower-risk solution could be employed.
The NCSC also suggests that organisations deploy agentic AI incrementally, with clearly defined pilots and solid foundations before expansion.
“If you cannot understand, monitor or contain an agent’s actions, it is not ready for deployment,” the guidance insists.
The NCSC further insists on human accountability, meaning that a human must be accountable for the decision to deploy an AI agent, the access it was granted, the safeguards around it, and the consequences of its operation. Crucially, these roles should be defined before the agent is connected to real systems or data. Responsible individuals should also be able to intervene with an agent if necessary.
Recommended reading
- How Is AI Impacting Traditional Hiring?
- Agentic AI Skills Demand Increased 60 Fold Over a Year
- Report: 95% of Organisations Plan to Hire Internationally as Demand for AI Skills Grows
- OpenAI to Launch AI-Powered Jobs Platform in 2026
Finally, the NCSC says organisations should apply best practices when it comes to cybersecurity, including applying least privilege, limiting the agent’s scope, avoiding long-live credentials, and using secure defaults.
Organisations should also understand dependencies, monitor agent behaviour, model threats on the deployment, and plan for incidents.
“Start small, apply existing cyber hygiene and governance from the start and plan for failure (including how you would respond to it),” the NCSC’s blog said.





