Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →Five Eyes Guidance on the Careful Adoption of Agentic AI Services
Issued by
Cybersecurity and Infrastructure Security Agency (CISA) and Five Eyes partner agencies
This joint Five Eyes advisory provides security guidance for organizations deploying agentic AI systems that operate with significant autonomy. It applies to any enterprise or public-sector body using AI agents capable of taking independent actions, accessing systems, or interacting with other automated agents. The guidance requires organizations to restrict agentic AI to low-risk tasks, enforce least-privilege access controls, and integrate autonomous agents into existing security governance structures.
Applies To
Overview
Published in April 2026 by CISA alongside partner cybersecurity agencies from the United Kingdom, Canada, Australia, and New Zealand, this advisory addresses the distinct security risks posed by agentic AI systems that plan, act, and coordinate without continuous human direction. The guidance establishes principles for scoping agent permissions, managing inter-agent trust boundaries, and ensuring human accountability for autonomous decisions. Key provisions cover zero trust architecture requirements for agent-to-system interactions, unified logging standards for agent activity, and explicit limits on the sensitivity of tasks that may be delegated to autonomous agents. Enforcement is advisory in nature, meaning the document carries no direct penalty mechanism, but it signals regulatory expectations that may inform future binding rules across Five Eyes member states. Organizations in critical infrastructure sectors should treat conformance as a baseline expectation given the agencies involved and the reputational weight of joint Five Eyes publications.
Key Requirements
- •Restrict agentic AI to low-risk, non-sensitive tasks until organizational maturity and security controls are verified
- •Apply least-privilege access principles to all AI agents, limiting permissions to only what each agent requires to complete its designated function
- •Establish and enforce trust boundaries between agents in multi-agent architectures, preventing unauthorized lateral movement or privilege escalation
- •Implement unified, tamper-evident logging of all agent actions to support auditability and incident response
- •Assign clear human accountability for the outcomes of autonomous agent actions, including defined escalation paths when agents exceed expected behavior
- •Integrate agentic AI systems into existing security governance frameworks, including risk assessments, vendor management, and incident response plans
What Your Organization Must Do
- →Audit all deployed and planned agentic AI systems to identify those operating beyond low-risk, non-sensitive task boundaries and remediate or restrict them accordingly
- →Map each AI agent's current permissions against a least-privilege baseline and revoke any access that exceeds operational necessity
- →Design or redesign multi-agent architectures to include explicit trust boundary controls, ensuring agents cannot impersonate one another or inherit unintended privileges
- →Extend your organization's security information and event management (SIEM) infrastructure to capture structured logs of agent actions, decisions, and system interactions
- →Assign named accountability owners for each agentic AI deployment and document escalation procedures for anomalous or out-of-scope agent behavior
- →Update AI procurement and vendor due diligence processes to require evidence that third-party agentic AI services meet least-privilege and logging standards outlined in this advisory
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Is the Five Eyes agentic AI guidance legally binding on US organizations?
- No, CAAAS-2026 is advisory in nature and carries no direct penalty mechanism. However, given the reputational weight of joint Five Eyes publications and the agencies involved, critical infrastructure operators should treat conformance as a baseline regulatory expectation that may inform future binding rules.
- Which types of AI systems fall within the scope of the Five Eyes agentic AI advisory?
- The guidance applies to any AI system capable of planning, acting, or coordinating without continuous human direction, including systems that access enterprise infrastructure, execute multi-step tasks, or interact with other automated agents. Single-prompt AI tools with no autonomous action capability are generally outside its scope.
- What does the Five Eyes guidance require for multi-agent architectures specifically?
- Organizations must establish explicit trust boundaries between agents to prevent unauthorized lateral movement, privilege escalation, or agent impersonation. Zero trust architecture principles must govern all agent-to-system interactions, and each agent's permissions should be scoped strictly to its designated function.
- How does the Five Eyes agentic AI advisory treat logging and auditability requirements?
- The guidance requires unified, tamper-evident logging of all agent actions, decisions, and system interactions. Organizations are expected to extend existing SIEM infrastructure to capture structured agent activity logs that support both incident response and post-incident auditability reviews.
- Does the Five Eyes agentic AI guidance apply to third-party or vendor-supplied AI agents?
- Yes. The advisory explicitly requires organizations to update AI procurement and vendor due diligence processes to confirm that third-party agentic AI services meet least-privilege and logging standards. Compliance accountability remains with the deploying organization, not the vendor.
- How does CAAAS-2026 compare to the EU AI Act for organizations deploying autonomous AI agents?
- The EU AI Act establishes binding obligations with enforcement penalties tied to risk classification, while CAAAS-2026 is a non-binding advisory focused specifically on cybersecurity controls for agentic systems. Organizations subject to both should use the Five Eyes guidance to strengthen security practices that complement, but do not substitute for, EU AI Act conformity obligations.
