Careful Adoption of Agentic AI Services: The First Multi-Nation Government Guidance for AI Agents
Read the original on CISA / NSA and Five Eyes partners ↗The Summary
CISA and NSA, together with the national cyber security centres of Australia, Canada, New Zealand and the United Kingdom, published the first multi-nation government guidance written specifically for agentic AI rather than for AI models in general. The document sorts agentic risk into five categories — privilege, design and configuration, behavioral, structural, and accountability — and argues that each requires a distinct control response rather than a single uniform governance overlay. Its recommendations are unusually concrete for guidance of this type: cryptographically anchored per-agent identity, short-lived task-scoped credentials, mutual TLS on agent-to-agent traffic, no static keys or shared service accounts, allowlisting of verified and version-pinned tools, prompt-injection defense as a baseline design requirement, oversight checkpoints encoded in the workflow architecture rather than left to the agent's own judgment, circuit-breaker patterns that halt and escalate on anomalous behavior, and preserved reasoning traces alongside human-readable tool-usage logs. It also names a finding most security teams will recognize: organizations generally cannot distinguish agent actions from human actions in the logs they already keep.
Why It Matters for Governed Autonomy
This is the closest thing to independent validation the Governed Autonomy Doctrine has received. Three of the four threats the doctrine names — Prompt Injection, Behavioral Drift and Cascading Failure — have verbatim or near-verbatim counterparts in the guidance's own risk language, and the doctrine's threat surface was locked before the guidance was published. The guidance's privilege-risk category is the failure mode Least Agency constrains; its insistence that trust be verified rather than inherited transitively is Trust Does Not Travel; its rule that an agent must never decide when oversight applies is Humans Retain the Right to Intervene. Where the two differ is layer, not substance. The guidance is a control catalogue and is materially more prescriptive on mechanism than the doctrine is. The doctrine supplies what a catalogue cannot: an architecture that says which Plane each control belongs to, which controls must hold simultaneously for a single agent action to be sanctioned, and — through the Governed Autonomy Maturity Model — how far an organization has earned the right to extend autonomy today. For federal programs, that ordering matters more than the control list itself: an agency can implement every recommendation in isolation and still be unable to answer whether what an agent is doing right now is sanctioned.
Maps to the doctrine
This story illustrates the following principles of the independent Governed Autonomy Doctrine:
MissionHarness.ai curates third-party reporting and adds original doctrine analysis. The summary and commentary above are our own; the original article is the property of CISA / NSA and Five Eyes partners and is linked, not reproduced. Doctrine terms link to the independent standard at governedautonomy.org.