{"id":335,"date":"2026-05-06T14:00:00","date_gmt":"2026-05-06T13:00:00","guid":{"rendered":"https:\/\/www.auravere.com\/insights\/?p=335"},"modified":"2026-06-24T15:22:44","modified_gmt":"2026-06-24T14:22:44","slug":"five-eyes-agentic-ai-governance","status":"publish","type":"post","link":"https:\/\/www.auravere.com\/insights\/five-eyes-agentic-ai-governance\/","title":{"rendered":"Understanding Risks of Agentic AI: Security Guidance from Five Agencies"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Last week I wrote about the governance gap in AI agent identity. The argument was that organisations are deploying autonomous agents with the same IAM frameworks built for humans, that those frameworks assume access is requested, granted, reviewed, and revoked through processes a person initiates, and that AI agents operate entirely outside those assumptions. Agents find credentials, inherit permissions, chain tools together, and act at a speed and scale that no human workflow was designed to handle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This week, five intelligence agencies confirmed it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On May 2, CISA, the NSA, the NCSC, and their counterparts from Australia, Canada, and New Zealand published joint guidance titled &#8220;Careful Adoption of Agentic AI Services.&#8221; The document opens by noting that agentic AI systems are already operating across critical infrastructure and defence sectors. It then lists 23 distinct risks and over 100 individual best practices. The tone throughout is measured but unambiguous. The conclusion is worth quoting directly: &#8220;Until security practices, evaluation methods and standards mature, organisations should assume that agentic AI systems may behave unexpectedly and plan deployments accordingly, prioritising resilience, reversibility and risk containment over efficiency gains.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is not a call to stop deploying agents. It is a call to stop deploying them faster than you can govern them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The document illustrates the risks with two scenarios that are notable for how operational they are. In the first, an agent tasked with applying security patches is also given broad write access. A malicious insider crafts a prompt asking the agent to apply the patch and clean up the firewall logs. The agent does both, because its permissions allow it and nothing in its design distinguishes between a legitimate maintenance task and evidence destruction. In the second, an agent managing procurement approvals accumulates implicit trust from other agents over time. A low-risk tool in its workflow is compromised. The attacker inherits the agent&#8217;s over-generous privileges, modifies contracts, approves unauthorised payments, and fakes audit logs that do not trigger alerts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Neither of these scenarios requires a sophisticated attack. Both require only that the agent was given more access than it needed and that nobody had designed a control that would detect the abuse.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The guidance was published on a Friday. By Monday the market had made its own position clear.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cisco announced its intent to acquire Astrix Security, a non-human identity security startup founded by veterans of Israel&#8217;s Unit 8200, for approximately $400 million. Astrix had built its platform around exactly the blind spot the Five Eyes document describes: the API keys, service accounts, and OAuth tokens that AI agents rely on to access data and execute work at scale. Cisco&#8217;s stated rationale was extending zero trust principles to what it called the emerging &#8220;agentic workforce.&#8221; That is a significant commitment of capital to a problem that, twelve months ago, most security teams would have described as theoretical.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cisco was not the only one. The week also produced Palo Alto Networks&#8217; announcement of its intent to acquire Portkey, a specialist in AI gateway technology that processes trillions of tokens per month and provides a centralised control plane for managing autonomous agent traffic. The stated rationale from Palo Alto&#8217;s Chief Product and Technology Officer was direct: &#8220;As autonomous agents join the enterprise workforce, they also become a new, unmanaged attack surface.&#8221; And Silverfort announced the acquisition of Fabrix Security, an AI-native identity startup whose technology evaluates access requests at runtime using a knowledge graph of identity, permissions, intent, and business context, replacing the static rule sets that traditional IAM platforms rely on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three acquisitions in one week, all targeting the same problem. Silverfort acquired Fabrix on April 28. Palo Alto announced Portkey on April 30. Cisco announced Astrix on May 4. That is not a coincidence. That is an industry reaching the same conclusion simultaneously.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The pattern here is important and it is one that security leaders should recognise. When a risk moves from theoretical to documented to the subject of government guidance in the space of a few months, and when three of the largest names in enterprise security spend hundreds of millions of dollars in the same week to address it, the question of whether to take it seriously has already been answered. The question that remains is how quickly your organisation can close the gap between where its governance is and where these acquisitions are pointing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Five Eyes guidance describes what good looks like. Apply least privilege rigorously to every agent identity. Treat agents as distinct entities with their own lifecycle, not extensions of the human accounts that deployed them. Monitor agent behaviour at runtime rather than relying on access rules defined at deployment. Build in human escalation points for unexpected scenarios. Prefer reversible actions over irreversible ones. Audit continuously.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">None of this is new advice in isolation. Security practitioners will recognise all of it. What is new is that it now applies to a class of identity that most organisations do not have in their asset inventory, operating in systems that were not designed with their presence in mind, at a speed that makes after-the-fact review largely academic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The market is moving. The regulators are moving. The question is whether your governance programme is moving with them, or whether you will be reading a postmortem that explains exactly which rules were violated.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week I wrote about the governance gap in AI agent identity. The argument was that organisations are deploying autonomous agents with the same IAM frameworks built for humans, that those frameworks assume access is requested, granted, reviewed, and revoked through processes a person initiates, and that AI agents operate entirely outside those assumptions. Agents&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"Five intelligence agencies warned that agentic AI governance isn't keeping pace with deployment. The market responded with three acquisitions in one week.","jetpack_seo_html_title":"Five Eyes Warned Agentic AI Governance Gap Exists | Auravere","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[25,22,7,24,23],"tags":[32,31,33,37,41,10,35,34,36,38,39,40],"class_list":["post-335","post","type-post","status-publish","format-standard","hentry","category-artificial-intelligence","category-cyber-awareness","category-governance","category-information-security","category-security-leadership","tag-agentic-ai","tag-ai-governance","tag-ai-security","tag-cisa","tag-cisco-astrix","tag-cyber-security","tag-five-eyes","tag-identity-security","tag-ncsc","tag-non-human-identity","tag-palo-alto-portkey","tag-silverfort-fabrix"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts\/335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/comments?post=335"}],"version-history":[{"count":2,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts\/335\/revisions"}],"predecessor-version":[{"id":340,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts\/335\/revisions\/340"}],"wp:attachment":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/media?parent=335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/categories?post=335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/tags?post=335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}