Read First · 01Managing the Cyber Risk of Agentic AI
UK NATIONAL CYBER SECURITY CENTRE · 20 AUGUST 2026
What changed. NCSC issued implementable interim guidance for autonomous agents: controls scale with autonomy; agents receive unique identities and short-lived credentials; execution is sandboxed; network access is allowlisted; telemetry is immutable; consequential activity retains human oversight; and an emergency shutdown remains independently enforceable.
Why it matters. This treats the agent’s reachable environment—not just its model—as the security boundary. It is a practical blueprint for converting “responsible AI” into architecture and operating controls.
Decision implication. Establish four authorization tiers: advisory; draft and recommend; execute with approval; bounded autonomous execution. Production agents need named owners, nonhuman identities, task-scoped credentials, controlled egress, protected audit trails, and a kill switch. Keep high-impact public-sector agents in tiers 1–2 until evidence supports expansion.
Read the NCSC guidance →
Read First · 02NIST SP 1353: Using AI for CSF 2.0 Analysis and Reporting
NIST · INITIAL PUBLIC DRAFT · 19 AUGUST 2026
What changed. NIST supplied structured prompts, fictional evidence, and worked examples for using generative AI to review governance documentation and draft CSF 2.0 Current and Target State Profiles. Comments are due October 15, 2026.
Why it matters. NIST has moved from conceptual AI governance to demonstrating AI-assisted cybersecurity governance work—while explicitly preserving the boundary between analysis and assurance.
Decision implication. Pilot this against a bounded evidence set. Require every mapping to cite its source artifact, record assumptions, distinguish missing evidence from a failed control, and receive human validation. AI may accelerate RMF and CSF work; it may not issue an authorization decision.
Read NIST SP 1353 →
Read First · 03Logging Reference Architecture
CISA · 20 AUGUST 2026
What changed. CISA released the reference architecture supporting revised federal logging, visibility, and operational standards. The emphasis is risk-prioritized, operationally useful telemetry—not indiscriminate collection.
Why it matters. Agencies routinely increase logging spend without improving detection because collection is disconnected from mission-relevant investigation and recovery questions.
Decision implication. Design telemetry backward from critical attack paths. Prioritize identity, administrative activity, cloud control planes, AI-agent actions, data exports, document repositories, privileged databases, OT/GIS connections, and backup administration. Test incident queries, not merely log forwarding.
Read the CISA architecture →