7 tried-and-true controls for agentic AI
Logs, least privilege, and other security basics that apply to AI.
• 4 min read
AI agents are starting to do more than access systems. They can invoke tools, execute workflows, and take action across business applications. As that autonomy grows, IT needs visibility into what each agent is allowed to do, what it actually did, who owns it, and how to revoke access when needed. Learn how JumpCloud helps govern AI agents alongside human and device identities.
Making sure an AI agent behaves takes a combination of rules and monitoring.
On Sept. 28, chipmaker Nvidia announced its Open Agent Safety Platform, an open-source approach to agentic defenses, combining functions like agent monitoring, restricted workspaces, and zero-trust access enforcement.
Despite these robust AI defenses coming online, many security pros are recommending tried-and-true practices to defend against unexpected AI behavior.
“You have to think about [safeguards] in terms of multiple layers of controls, and that would include, at a very basic level, the same types of best practices and controls that we think about for securing enterprise systems generally,” Andrew Tannenbaum, partner and global cohead of cybersecurity at law firm A&O Shearman, told IT Brew.
Whether you’re trying to keep an agent from exposing sensitive data, deleting that data, escaping its boundaries, or being co-opted by tactics like prompt-injection, here’s a look at the basics that still apply to AI:
- Logs. Today’s security tools monitor for signs of agentic behavior that might require a second look, like unexpectedly heavy compute usage, Tannenbaum said. For traceability purposes, Shanti Greene, head of data science and AI innovation at enterprise AI solutions company AnswerRocket, suggested earlier this year that IT pros configure their agents or orchestration platforms to create a plaintext or markdown file of their outputs as they move through stages of a task.
- Least privilege. Give each agent only the data and system access it needs to do its job, and enforce those limits through the permissions and roles of the user account it runs under, suggested Aaron Beardslee, manager of threat research at cybersecurity company Securonix. Beardslee deploys subagents that run with a user account and are given specific access through the MCP server that a user can access; this server acts as a controlled doorway between an AI agent and a business system.
- Sandboxes. Meghan Hollis, senior principal analyst for AI and cybersecurity at Gartner, recommends testing agents in an isolated virtual environment, where executed code doesn’t adversely impact production-environment assets or allow agents to leave contained environments causing harm to other environments.
A sandbox doesn’t necessarily require a dedicated product, according to Hollis. Organizations can configure one using familiar security controls, such as network segmentation and firewall rules, to isolate the agent from production systems and public internet access. “We’ve been doing this for decades,” Hollis said. (Just check for open ports or backdoors that could let it reach outside the sandbox, she added, or even consider a full, completely isolated air-gapped system.)
Beardslee told us he restricts network access for his agents and allows them to communicate only on “very specific ports to a very specific target,” not the full internet.
- Monitoring. Hollis also sees value in a “guardian agent,” a monitoring and governance tool that uses AI-based and deterministic evaluations to watch AI agents and their interactions with tools, data, APIs, and humans. The defense aims to oversee an AI agent’s compliance with enterprise boundaries and cybersecurity policies.
- Inventory. Part of AI security tooling should include a discovery of all agents in an environment at any point in time, Hollis said.
Deepen Desai, chief security officer at cybersecurity Zscaler, agrees on the importance of having visibility of all AI usage (agents and applications), allowing only a sanctioned list with proper security controls.
- Accountability. Hollis’s top recommendation includes clearly defining who takes responsibility for AI safety and security. Ben Beath, chief AI officer at Microsoft services partner Avanade, has an internal rule: An agent should not go live without a clearly identified person to contact if it breaks. “You’ll be surprised at how often for people in my position that that’s a question that has no real answer,” Beath told us.
- Slow rollouts. Start with lower-risk uses, monitor how controls work, and then expand gradually with stronger oversight as risk increases, Tannenbaum recommended: “As you get into more actions that involve taking more risk, have more human oversight and make sure good monitoring is in place.”
About the author
Billy Hurley
Billy Hurley has been a reporter with IT Brew since 2022. He writes stories about cybersecurity threats, AI developments, and IT strategies.
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
