AI agents’ transformation of business grows more profound by the month. At some companies, corporate leaders have started drawing up hybrid organization charts showing both humans and agents. On one side, these charts show the human employees and the cost of salaries and benefits. The other half of the page shows the computing and integration budget to maintain digital labor teams.
Company leaders recognize such budgets must include adequate funds for security and governance measures to contain agents’ distinctive risks but have been hindered by the lack of neutral guidance and standards. The AI governance frameworks issued since 2023 have not been updated for autonomous AI. That leaves a crucial gap. “Past standards assume that human decision-makers are somewhere in the implementation process,” Jones Walker partner Jason Loring told the Cybersecurity Law Report.
The need for updated guidance on agent implementations arises daily, observed Freshfields partner Megan Kayo. “Companies and security teams are hungry for those standards. Clients are grasping for whatever they can get” to help with security and governance, she told the Cybersecurity Law Report.
Governments have now moved to fill the vacuum. In May 2026, the cybersecurity agencies of the Five Eyes countries, including the National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA), issued lengthy joint guidance (Guidance) recommending more than 50 best practices for agent security. Later in the same month, the Government of Canada issued a guide for managing and governing agentic AI, as well (Canadian Guide).
This article discusses the new guidance’s recommendations and impact, and presents insights on what companies should do while standards slowly develop, with perspective from Kayo, Loring and experts at Norton Rose and Panoptic Systems.
See “Eyewitness Accounts and Recommended Actions to Counter AI’s Strain on Cyber Defense” (May 6, 2026).
Five Eyes Guidance on “Careful Adoption” of Agents
CISA and the NSA co-authored the Guidance with the cybersecurity authorities in Australia, Canada, New Zealand and the United Kingdom, each part of the Five Eyes alliance on signals intelligence. The Guidance, titled “Careful Adoption of Agentic AI Services,” describes agents’ security risks, lists the cybersecurity prerequisites for implementing agents, and presents best practices for designing, developing, deploying and operating agents, detailed in separate sections.
Summary of Agents’ Novel Risks
The Guidance identifies five broad categories of risk, rooted in the agents’ autonomy, their ability to communicate and act across many organizations’ systems, and their “evolving capabilities.”
The first section examines agents’ access to digital terrain. Granting agents too many privileges can cause a trail of damage even when operating properly. The second section covers design and setup flaws, where poor configurations create security issues, putting many systems at risk.
The third section focuses on behavioral risks, including when an agent pursues a goal in ways its designers never predicted. The fourth addresses structural risk from interconnected networks of agents that can rapidly spread failures across networks and companies.
The Guidance’s fifth section addresses accountability. Many agentic systems in 2026 could leave inadequate evidence of what caused a particular action, making it hard to trace what went wrong and why.
The Guidance notes that agents have caused concrete incidents, including altered files, changes to system permissions and deleted audit trails. The authors warn, too, that agents are already acting inside critical infrastructure, and that many organizations have granted agents far more access than they can safely monitor or control. A separate May 2026 report by Token Security and the Cloud Security Alliance found that 65% of 400 organizations surveyed had experienced an agent-caused incident. Of those episodes, 61% involved the exposure of sensitive data, 43% disrupted business operations, 41% produced incorrect or unintended actions within business processes, and 35% carried a financial cost.
See our two-part series on AI agent security: “Companies See Rogue Incidents but Lag on Controls” (Mar. 18, 2026), and “What CISOs and GCs Need to Know to Defend the Enterprise” (Mar. 25, 2026).
Recommendations for the Agent Supply Chain
The cyber authorities’ expectations start with design of the agents. The Guidance’s 14 recommended practices for designers include incorporating:
- human control points;
- strong identity mechanisms;
- instructions to constrain agents; and
- overlapping layers of security controls in any agentic AI systems they build.
The Guidance also sets forth 34 recommended practices for agent developers, which include:
- integrating “comprehensive artifact logging mechanisms”;
- strengthening adversarial training by using synthetic data;
- structurally limiting each agent’s duties into separate “roles such as ‘Orchestrator’, ‘Reader’ and ‘Actuator’ with clear boundaries”; and
- managing third-party components in AI products, with 14 practices specified.
The authors urge the entire supply chain to pay attention to developer and designer practices. “Operators may want to reference these best practices when choosing AI agents and agentic applications,” they advised.
See “Contracting With Vendors to Mitigate Third-Party AI Risk” (Feb. 18, 2026).
Recommendations for Deployers and Operators
For the broad swath of companies that use agents, the Guidance offers 23 practices for “deploying” them and 37 for “operating” them. Throughout the Guidance, which uses British Commonwealth spelling, the authorities urge companies to apply established principles like zero-trust segmentation of systems, “layered defence,” and strict access controls to protect their systems, data and business.
The Guidance emphasizes the need for “monitoring and auditing,” offering 14 recommendations, while also focusing on “privileges and authentication,” listing 10 best practices.
One of the Guidance’s top messages for deployers and operators is that agentic AI does not require an entirely new security program. The authorities suggest that organizations start by applying their existing cybersecurity frameworks and governance structures to their new AI agentic systems. “AI systems are fundamentally IT systems, as they run on software and hardware, operate over networks and interact with other digital services,” the Guidance notes.
However, the Guidance points out that existing frameworks are inadequate for agents’ array of challenges, cautioning companies to go slow. “Until security practices, evaluation methods and standards mature, organisations should assume that agentic AI systems may behave unexpectedly and plan deployments accordingly, prioritising resilience, reversibility and risk containment over efficiency gains,” the authorities wrote.
See “Benchmarking AI Governance Practices and Challenges” (May 7, 2025).
The Guidance’s Impact
The Guidance focuses more on agents’ security than their risks to the broader enterprise, an approach that usefully addresses the most obvious threats but does not satisfy all of companies’ concerns.
Useful Recommendations for Many Deployers of Agents
The Guidance offers companies’ cybersecurity program managers a practical boost. “CISOs and other leaders have acknowledged and understand their teams’ need to be involved with these deployments,” but few have created a full roadmap, Loring observed.
The Guidance’s reference to established security concepts throughout “helps some organizations avoid the paralysis that can come with not having any idea where to start,” said Jones Walker special counsel Michelle Ramsden.
To anchor its best practice recommendations, the Guidance usefully provides examples and scenarios, Norton Rose partner Susana Medeiros told the Cybersecurity Law Report. “We can expect that organizations’ legal, security and even their red teams will attempt to test their agentic systems in line with many of the issues that CISA has highlighted using real-world scenarios,” she predicted.
See “Using ‘Red-Teaming’ to Test and Improve Cyber Defenses” (Sep. 11, 2019).
A Breakthrough Contribution
The Guidance likely will earn influence as a practical aid because CISA and the other cybersecurity agencies collectively have “access to insight from around the world,” which is “a really helpful benchmark for organizations to understand the realistic attack vectors to expect in these systems,” Medeiros predicted.
The Guidance offers an early stabilizing guidepost amid the marketplace’s churn forward in 2026 and 2027. “We’re seeing traction developing everywhere with agents. Without a consistent framework that everybody can refer back to, and with the speed at which everybody is moving, companies and developers are all going to spread out and do their own thing,” Panoptic Systems CEO Dave Medeiros told the Cybersecurity Law Report. This first set of recommendations will need to be followed by an array of technical standards and neutral frameworks. Otherwise, “that vacuum is going to be filled by commercial interests that want to set the standards the way they want to set them,” he added.
Agent security discussions often omit accountability or treat it as a secondary consideration, so the Guidance stands out for issuing strong recommendations in this area. The Guidance helpfully frames the lack of visibility into agents’ decisions and actions “as a top-tier risk” and governance bottleneck, Dave Medeiros continued. “The real critical gap with agents is going to be attribution,” i.e., not being able to say who took a troubling action or why it happened, he said. The Guidance urges organizations to retain “unified audit logs for all inter-agent interactions” and “ensure observability of and reasoning behind agent decisions.”
See “Navigating NIST’s AI Risk Management Framework” (Nov. 15, 2023).
Practical Limitations
Despite offering useful guardrails, the Guidance leaves key gaps and may have limited practical impact for more advanced adopters. Some of the Guidance’s suggested practices are concrete or technical, while others are higher-level statements about what is needed.
As with earlier frameworks, companies must adapt the Guidance’s best practices for their idiosyncratic governance and risk management operations, Freshfields partner Anna Gressel advised. “For example, the Five Eyes framework talks about validating outputs with a human in the loop – but giving some color and meaning to that requires a company to put it into employee guidance and playbooks” as well as assigning engineers to help, she elaborated.
Moreover, the Guidance’s “‘start small’ recommendation will likely be taken to heart by organizations that are not the ones that the Five Eyes and CISA are most concerned about,” Ramsden noted. “The organizations that are really on the cutting edge of agentic AI, developing and pushing tools that may have a broader impact, are likely way past starting small,” she pointed out. Companies that have strategically focused on deploying agents may have moved past the Guidance’s recommendation to use phased deployments and permissions, for example.
The Guidance also excludes practical recommendations for non-security governance controls for agentic AI systems, such as steps to increase transparency, accountability and enterprise risk assessment.
See “New Jersey and Oregon Advisories Contribute to AI Guidance From State AGs” (Feb. 12, 2025).
How Companies Can Navigate a Transitional Moment in Governance
Agents’ autonomy and speed in completing tasks expose the limits in “traditional” AI governance tools, but companies can prepare for the regulatory mandates for agent oversight that eventually will be issued by using the Guidance and Canadian Guide, as well as other advisories and frameworks that also have begun to appear.
Monitor for Updated Frameworks
Finding best practices to adopt and technological tools to govern agents has become an “enormous area of focus for organizations as they attempt to implement agents at scale, extract value from them, and really come up with a working paradigm for having employees functioning in tandem with agents as members of their team and organizations,” Gressel observed.
Beyond the Guidance, other governance frameworks and technical standards for agents are under development. The National Institute of Standards and Technology’s (NIST) Center for AI Standards and Innovation launched the “AI Agent Standards Initiative” in February 2026 and received more than 500 public comments through March in response to an associated Request for Information about AI agent security. In May 2026, the Cloud Security Alliance started administering the Agentic Trust Framework, which includes an associated assessment companies can use. That same month, Singapore released an updated agentic AI governance framework that might be a helpful resource for many companies, Gressel pointed out.
See “Anthropic’s Mythos Model Forces Companies to Regroup for a New Cyber Era” (Apr. 22, 2026).
Prioritize Safeguards Early On
Several preventive strategies are emerging in the Guidance and other recent discussion about agent security, commentators said.
Inventories
Organizations must address foundational issues such as inventorying systems and identifying “shadow agents,” ensuring they understand where agents are already in use, experts said, echoing the Guidance. According to the Token Security survey, 82% of respondents have discovered previously unknown agents in their systems in the past year, with 41% of respondents saying this happened multiple times.
Zero Trust
The frameworks released so far have converged around a Zero Trust security model, Dave Medeiros noted. “They all are looking in the same direction,” he said. Because agents “have no real concept of consequences,” organizations must “assume fallibility. And the only way that you can operate under that assumption is in a Zero Trust world, giving agents only provisional access to” tools in segmented environments, he emphasized. The Guidance directs organizations to harmonize AI agent controls with Zero Trust principles, citing NIST’s and NSA’s Zero Trust implementation publications.
Bounded Autonomy
The Canadian Guide urges organizations to focus on “bounded autonomy,” only running agents “with tight, explicit parameters that limit data, tools, permissions and scope.” This preventive control “reduces the chance of unsafe actions before they happen.” Other commentators call this idea the “least agency” principle, echoing the principle of granting users the least access necessary for a task.
Installing Brakes
Given all the uncertainty and flux in agent architecture, companies need to focus on creating controls to advance resilience, Susana Medeiros stressed. Empowering systems “to stop an agent in its tracks because it performs risky actions” using mechanisms like kill switches is an important measure, she said.
The highest costs a company might face with agents are from their actions, Dave Medeiros observed, agreeing that “it is important that the company can govern what the agents do” during their workflows with safeguards enforced before execution.
Reversing unintended actions will be a key layer of control, too, Susana Medeiros highlighted. “There’s a desire for more guidance around what level of auditability, traceability and rollback controls organizations will need so that they can manage cyber and legal risk, and also business continuity,” she pointed out. The Canadian Guide urges organizations to focus on “recoverability,” in which agents can be “guided easily, paused or stopped when needed, and quickly returned to a safe and stable state.”
See “AI Compliance Playbook: Adapting the Three Lines Framework for AI Innovations” (Jun. 2, 2021).
Mind the Gap
As consensus grows on governance principles, a significant tooling gap remains, Kayo noted. “The tools still don’t necessarily exist to fully implement what these frameworks set out,” she said.
There is a demand for tools to manage, observe and control agents, Gressel observed. “Many companies are working on entering this space and maturing the orchestration layer [of controls], but it’s definitely an area where there is still work to be done,” she said. It likely will change in the near term, with many “industry actors rowing together to make that happen,” she predicted.