CISA and collaborators publish agentic AI best practices
CISA and partners have released guidelines emphasizing security awareness in adopting agentic AI, advising organizations to restrict access to sensitive data and prioritize safety measures amidst evolving risks.
The authoring organizations emphasize security awareness when it comes to AI adoption. Key suggestions:
Utilize your organization’s current security practices.
Organizations should not give agentic AI access to “sensitive data or critical systems,” or anything high-risk.
The guidance gives an overview of the risks of using this technology, potential scenarios, prevention tips, and safety solutions. The authors conclude, “Until security practices, evaluation methods and standards mature, organizations should assume that agentic AI systems may behave unexpectedly and plan deployments accordingly, prioritizing resilience, reversibility and risk containment over efficiency gains.”