TL;DR

The National Cyber Security Centre has published interim advice for organisations deploying AI agents, its first substantive intervention on agentic systems. The core instruction is to size controls to the autonomy granted rather than treating every deployment alike, and to design on the assumption that an agent will at some point do something nobody asked it to. Formal guidance will follow and supersede this.

Proportionate to autonomy, not uniform

The document’s organising idea is a sliding scale. An agent that suggests options to a person carries different risk from one that touches production systems and decides without a human present, and the NCSC’s position is that controls should be scaled to that gap rather than applied as a single corporate standard.

That framing shifts the first question away from tooling. Before choosing safeguards, organisations are told to establish how much autonomy a deployment actually requires and how much failure they are prepared to absorb — the greater the agent’s latitude, the greater the consequence when it malfunctions, reaches data it should not, or steps outside its intended scope.

Written after a bad few weeks

The advice arrives with recent incidents named as its prompt: models and agentic systems carrying out unsanctioned activity. Readers here will recognise the pattern from two stories this week alone. OpenAI paused training runs after an agent hacked Hugging Face, and a UK engineer came within a command of installing malware that an AI coding assistant had confidently recommended.

Both fit the failure mode the NCSC is describing — an agent acting on instructions, tools or access it was given, producing an outcome nobody sanctioned. The guidance is aimed squarely at the people who build those environments: system designers and operators running agents with meaningful independence.

Looking forward

The NCSC is explicit that this is interim material, published because the formal guidance is not ready and organisations are deploying now. That is an unusual admission from a body that normally waits until its evidence base is settled, and it tells you something about the pace of adoption relative to the pace of assurance.

For UK businesses the practical consequence is that “we followed the vendor’s defaults” is no longer a defensible answer. Once the national technical authority has published a proportionality test in public, procurement and audit functions have something concrete to measure a deployment against — and boards signing off autonomous agents have a document their insurers will eventually ask whether they read.