On May 1, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the U.S. National Security Agency (NSA), and partner agencies in the United Kingdom, Australia, Canada, and New Zealand published joint guidance warning that organizations are giving agentic AI systems more access than can be safely monitored, and recommending tighter scoping, logging, and human-in-the-loop checkpoints (Source: cyberscoop.com). It is among the first formal Five Eyes joint products addressing AI-specific risks rather than general cyber risks, and the first multilateral cybersecurity guidance specifically targeting agentic AI deployment.
The official document is titled "Careful Adoption of Agentic AI Services" and is published on CISA's site as a joint guide for developers, vendors, and operators; the copy hosted by the U.S. Department of Defense carries a document date of April 30, 2026 (Source: cisa.gov) (Source: media.defense.gov).
Scope and status
The document is a joint guidance or advisory rather than a treaty or binding standard. CISA describes it as providing developers, vendors, and operators with best practices for securing agentic AI systems and recommended actions to take (Source: cisa.gov). It was issued by the Five Eyes intelligence-sharing partners: the United States, the United Kingdom, Australia, Canada, and New Zealand. The publishing agencies are CISA and the NSA in the United States, the NCSC in the United Kingdom, the ASD's ACSC in Australia, the CCCS in Canada, and the NCSC in New Zealand (Source: cyberscoop.com).
Recommendations
Based on the published summary, the guidance recommends four measures (Source: cyberscoop.com):
- Tighter scoping of agent permissions and action-affordance surfaces.
- Enhanced logging of agent decisions, tool calls, and resource access.
- Human-in-the-loop checkpoints at high-impact action junctures.
- A default deny-list for sensitive operations rather than allow-list grants.
Context
The guidance was published amid demonstrations of offensive-cyber capability in frontier AI. Anthropic's Mythos system has demonstrated such capability (Claude Mythos Preview), and OpenAI's GPT-5.5 reached comparable cyber capability per a UK AISI evaluation dated April 30, 2026. The Five Eyes partners were at the same time procuring frontier AI for classified use, including a Pentagon deal with 8 vendors announced May 1, 2026, while warning more broadly about agentic AI deployment risk, placing the same governments in the roles of both AI deployer and AI-risk regulator.
The recommendations align with the Redwood Research "fitness-seeking AIs" essay published the same day, which argued that "fitness-seeking" — agents optimizing for outcome metrics that proxy real-world influence — is increasingly the operative form of misalignment in deployed systems, and proposed mitigations centered on bounded objectives and reduced action affordances.
New Zealand's publishing agency is tracked at National Cyber Security Centre (NCSC), New Zealand, which also signed the separate June 2026 Call to Action on AI Preparedness.
Relationships
- related: Agentic AI, AI and Cybersecurity, Agent Architecture Patterns, Cybersecurity and Infrastructure Security Agency (CISA) — regulator role, National Security Agency (NSA) (if exists), UK AI Safety Institute (AI Security Institute), AI Autonomy Risk, Principal-Agent Problem Applied to AI.
- published-by: CISA, NSA, UK NCSC, Australia ASD ACSC, Canada CCCS, New Zealand NCSC.
- supports: Agent Autonomy Spectrum (5 Levels) — formal government acknowledgment that the autonomy spectrum requires graduated guardrails.
- depends-on: Post-Deployment AI System Monitoring — guidance presumes the monitoring infrastructure exists or can be built.