CTIPilot

NCSC UK interim guidance on managing the cyber risk of agentic AI (August 2026)

policy · policy:ncsc-uk-agentic-ai-risk-guidance-2026

Interim practical guidance published by NCSC UK on 2026-08-20 for organisations deploying agentic AI: proportionality to autonomy and blast radius, pre-deployment threat modelling, human-in/on/out-of-the-loop oversight tiers with named accountability, a four-level network-sandboxing maturity model, credential scoping to task and shortest practicable lifetime, agentic activity treated as user activity in 24/7 monitoring with immutable logs, and a maintained emergency shutdown. Explicitly interim, to be superseded by formal guidance in development (NCSC UK, 2026-08-20).

Aliases: Managing the cyber risk of agentic AI

Coverage timeline
0
first 2026-08-23 → last –
no data
Peak priority
·
no matching entries
Sources cited
0
0 hosts
Sections touched
0
·
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

No published entries reference this entity yet.

explore in graph

Entries about NCSC UK interim guidance on managing the cyber risk of agentic AI (August 2026)

No published entry references this entity yet · entries match by registry key, by the entity's name or a public alias appearing in the entry title or body, or (for CVE entities) by exact CVE id.