{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/ncsc-thinking-carefully-agentic-ai-2026/",
 "asOf": "2026-09-26",
 "id": "ncsc-thinking-carefully-agentic-ai-2026",
 "date": "2026-05-15",
 "datePrecision": "day",
 "title": "UK NCSC advises incremental agentic AI adoption with minimal, expiring permissions",
 "lane": "policy",
 "kind": "guidance",
 "summary": "NCSC authors advise deploying agentic AI incrementally through tightly bounded pilots, granting agents only the minimum permissions with temporary credentials, and defining in advance who approves access, monitors behavior and can halt the agent. They recommend incident response plans for agent failure and loss-of-control scenarios.",
 "whyItMatters": "It turns joint international agentic AI guidance co-authored by the NCSC into concrete operating rules, including temporary credentials and a named owner who can stop the agent.",
 "actors": [
  "ncsc-uk"
 ],
 "topics": [
  "standards-and-guidance",
  "monitoring-and-control"
 ],
 "atlas": [
  "credentials",
  "human-approver",
  "monitor"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.ncsc.gov.uk/blogs/thinking-carefully-before-adopting-agentic-ai",
   "publisher": "UK National Cyber Security Centre",
   "title": "Thinking carefully before adopting agentic AI",
   "date": "2026-05-15",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Recommends minimum task-specific permissions using temporary credentials that expire when work completes.",
   "locator": "Restrict permissions section"
  },
  {
   "fact": "States an agent is not ready for deployment if its actions cannot be understood, monitored or contained.",
   "locator": "Human control section"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "ai-monitoring",
  "credential-overreach",
  "human-approval"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}