# Five Eyes Issue Joint Security Guidance on Agentic AI Deployment Risks

> The Five Eyes intelligence partners have issued their first coordinated security guidance on agentic AI, the systems that do not just answer questions but take actions on a user's behalf. Cybersecurity agencies from the US, UK, Australia, Canada, and New Zealand, including CISA and the NSA, jointly published the document on May 1, and the tone is cautious rather than celebratory. The guidance sorts the danger into five categories, covering privilege, design and configuration, behavior, structure, and accountability, and catalogs more than twenty three distinct risks alongside over a hundred recommended practices. The standout warning concerns prompt injection, which the agencies call the most persistent and difficult to fix threat, noting that defenses remain immature and that no single control is enough on its own. Their core recommendation is restraint: adopt agents slowly, start only with low risk tasks, and wrap everything in strong governance, monitoring, and human oversight. Coming from the governments that set procurement and security norms for much of the Western world, this reads as an early brake on the rush to hand real authority to autonomous software.

_Section: [Daily AI Updates](https://www.wortins.com/daily-ai) · Source: Hunton Andrews Kurth · Published Saturday, July 11, 2026_

## Wortins' read

The Five Eyes intelligence partners have issued their first coordinated security guidance on agentic AI, the systems that do not just answer questions but take actions on a user's behalf. Cybersecurity agencies from the US, UK, Australia, Canada, and New Zealand, including CISA and the NSA, jointly published the document on May 1, and the tone is cautious rather than celebratory. The guidance sorts the danger into five categories, covering privilege, design and configuration, behavior, structure, and accountability, and catalogs more than twenty three distinct risks alongside over a hundred recommended practices. The standout warning concerns prompt injection, which the agencies call the most persistent and difficult to fix threat, noting that defenses remain immature and that no single control is enough on its own. Their core recommendation is restraint: adopt agents slowly, start only with low risk tasks, and wrap everything in strong governance, monitoring, and human oversight. Coming from the governments that set procurement and security norms for much of the Western world, this reads as an early brake on the rush to hand real authority to autonomous software.

## Source

[Read the full story at Hunton Andrews Kurth](https://www.hunton.com/privacy-and-cybersecurity-law-blog/cybersecurity-authorities-issue-joint-guidance-on-the-adoption-of-agentic-ai-systems)

## Related coverage

- [Researchers used AI to build a WeChat worm that spreads through phone calls](https://www.wortins.com/story/researchers-used-ai-to-build-a-wechat-worm-that-spreads-thro-8bf3f469) — [The Next Web](https://thenextweb.com/news/wechat-worm-ai-calif-tencent-zero-click)
- [Trump officials say AI will help save rural health care. Some leaders in the field don’t believe it](https://www.wortins.com/story/trump-officials-say-ai-will-help-save-rural-health-care-some-bf0e7d83) — [STAT](https://www.statnews.com/2026/09/10/rural-health-care-ai-adoption-challenges-part-4-unraveled-series/?utm_campaign=rss)
- [First ‘Take It Down Act’ Sentencing Puts Man Behind Bars for 15 Years](https://www.wortins.com/story/first-take-it-down-act-sentencing-puts-man-behind-bars-for-1-7a82b442) — [404 Media](https://www.404media.co/first-take-it-down-act-sentencing-case/)
- [Inception launches Mercury 2.5 at 1,107 tokens per second](https://www.wortins.com/story/inception-launches-mercury-2-5-at-1-107-tokens-per-second-7999ed1b) — [TestingCatalog](https://www.testingcatalog.com/inception-launches-mercury-2-5-at-1-107-tokens-per-second/)
- [Letter: the Senate disaster management subcommittee, led by Sen. Josh Hawley, is probing OpenAI's handling of the Hugging Face breach, calling it "reckless" (Axios)](https://www.wortins.com/story/letter-the-senate-disaster-management-subcommittee-led-by-se-da54156c) — [Techmeme](https://www.techmeme.com/260910/p11#a260910p11)
- [Top AI spenders cut per-employee costs by nearly 10 percent in August](https://www.wortins.com/story/top-ai-spenders-cut-per-employee-costs-by-nearly-10-percent--b31ffb0b) — [The Decoder](https://the-decoder.com/top-ai-spenders-cut-per-employee-costs-by-nearly-10-percent-in-august/)

---

_Curated and written by [Wortins](https://www.wortins.com) — The daily AI briefing. Every story links to its original source; the "Wortins read" on each is our own original analysis. [About Wortins & our editorial approach](https://www.wortins.com/about)._
