Britain has no law that tells a company how to deploy an autonomous AI agent. Its cyber security authority has, over the course of 2026, written the controls anyway, and the instruction underneath them is blunt: treat the agent as something that will, at some point, do something nobody asked it to.
That is the through-line of a cluster of guidance from the National Cyber Security Centre, the defensive arm of GCHQ. On 20 August the NCSC published a technical blog, Managing the cyber risk of agentic AI, setting out how organisations should contain systems that can access data, make decisions, use tools and take actions towards a goal without a human in the loop for every step. It followed a 15 May post, Thinking carefully before adopting agentic AI, and a joint international guide, Careful Adoption of Agentic AI Services, that the NCSC co-signed on 1 May alongside cyber agencies in the United States, Australia, Canada and New Zealand.
Controls built for an insider you do not trust
The August guidance is not written in the language of AI ethics or model safety. It is written in the language of network defence, and the controls it names are the ones a security team would apply to a privileged account it did not fully trust.
Least privilege comes first: an agent should hold only the permissions it needs, and no more. Scope should be constrained to the resources required for the task, with monitoring for any attempt to reach wider access. Credentials should carry “the shortest possible lifetime”, so a compromised or misbehaving agent cannot keep acting on stale authority. The default network posture the NCSC recommends is to deny all inbound and outbound traffic to the agent’s environment and open only what is needed. And then the line that reframes the whole exercise: agentic activity “should be treated as a form of user activity” and folded into 24/7 security monitoring and incident response, with early experiments run during office hours when a human is watching.
Put together, that is not a description of a tool. It is the profile a security team builds for an insider whose behaviour it cannot fully predict. The named risks make the point explicit: unsanctioned or unintended actions, escape from a sandbox through a misconfiguration, data access beyond the intended scope, and goals pursued in ways the operator did not mean because the instruction was read too literally.
A deployment gate, not a checklist
The May post supplies the governance rule the controls hang from. Its message is that firms should “walk before they run”, starting with tightly bounded pilots on low-risk tasks, and its sharpest sentence functions as a veto: if you cannot understand, monitor or contain an agent’s actions, it is not ready to deploy. Accountability for the decision to deploy, for the access an agent is granted, and for the consequences of its actions stays with a human. None of it can be handed to the model or the vendor.
That is where security guidance quietly becomes governance. The United Kingdom has chosen not to legislate a bespoke AI regime, preferring principles and existing law to a rulebook. The European Union went the other way, classifying AI used in areas such as credit and insurance as high-risk under its AI Act, though it has since pushed the hardest of those obligations back to December 2027. In the gap the UK has left, the operative constraints on how an autonomous agent may be let loose inside a corporate network are the ones the NCSC has written, and because six national agencies published a common version of them, they carry the weight of an emerging international standard rather than one country’s advice.
The NCSC’s leadership has been raising the temperature in parallel. In a 4 August statement responding to incidents in which frontier models took unsanctioned actions during evaluations, and showed what it called human-like deceptive behaviour, chief technology officer Ollie Whitehouse warned that “relying on detection alone after the fact of an incident will not be enough”. The controls, in other words, are meant to sit in front of the agent, not behind it.
Why this lands on boards, not just security teams
For UK firms, the practical shift is in where the accountability sits. An organisation that treats agent adoption as an IT productivity decision is reading it in the wrong department. The NCSC’s framing pulls the choice up to the level of risk ownership, and for regulated firms that ownership already has a name. Under the Senior Managers and Certification Regime, a named individual owns the function an agent would operate inside, and cannot delegate that responsibility to software. The Consumer Duty asks firms to evidence good outcomes however a decision is reached. Data protection law attaches to whatever the agent touches. The security guidance does not create those duties, but it describes, in operational terms, what discharging them now looks like when the actor is autonomous.
The complicating factor is that much agent use will not be sanctioned at all. The NCSC’s own guidance on shadow IT, refreshed in 2026 to cover what it calls shadow AI, warns that staff routinely reach for unapproved tools when the sanctioned ones fall short, turning an unmanaged tool into an unmanaged risk. An agent wired into a corporate mailbox or code repository without least privilege, short-lived credentials or monitoring is precisely the profile the August controls are meant to prevent, and precisely the one a productivity-first rollout produces.
What to watch
The signal to track is whether this guidance hardens, as supervisory expectations tend to, into something firms are effectively audited against: in procurement questionnaires, in insurers’ underwriting, in the assurance a board’s own risk committee demands before an agent is switched on. The NCSC has pointed firms towards ETSI EN 304 223, a baseline security standard for AI systems, as the technical floor. None of it is law. But a firm that deploys an agent it cannot contain, after the country’s cyber authority has spelled out how to contain it, will find that “the guidance was not mandatory” is a weak defence when the agent does the thing nobody asked.
Discussion
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.