<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Standards &amp; guidance · Agentic Cyber Explorer</title>
<link>https://agentic-cyber-explorer.pages.dev/topics/standards-and-guidance/</link>
<atom:link href="https://agentic-cyber-explorer.pages.dev/topics/standards-and-guidance/feed.xml" rel="self" type="application/rss+xml"/>
<description>New records, findings, and answers on standards &amp; guidance, from Fide AI's Agentic Cyber Explorer.</description>
<language>en</language>
<copyright>Fide AI. Data licensed CC BY 4.0.</copyright>
<lastBuildDate>Sat, 26 Sep 2026 12:00:00 GMT</lastBuildDate>
<item>
<title>Australia's ASD issues guidance on securing agentic AI harnesses, the layer around the model</title>
<link>https://agentic-cyber-explorer.pages.dev/events/asd-agentic-ai-harnesses-guidance-2026/</link>
<guid isPermaLink="false">event:asd-agentic-ai-harnesses-guidance-2026</guid>
<pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The Australian Signals Directorate's ACSC published guidance on agentic AI harnesses, the software layer that connects a model with organisational data, tools and systems and manages context, memory, tool access and execution privileges. According to coverage, it says some risks, including prompt injection, cannot be addressed within the model alone, that no harness is inherently secure, and recommends least privilege, human oversight for high-impact actions, audit logging and validating agent outputs before execution. It moves government guidance from model behavior to the tool, memory and permission layer where most agent compromises occur.</description>
</item>
<item>
<title>MITRE ATLAS adds autonomous attack techniques and case studies of agent-driven intrusions</title>
<link>https://agentic-cyber-explorer.pages.dev/events/mitre-atlas-2026-08-autonomous-attack-techniques/</link>
<guid isPermaLink="false">event:mitre-atlas-2026-08-autonomous-attack-techniques</guid>
<pubDate>Mon, 31 Aug 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>MITRE's August 2026 ATLAS release added techniques describing AI agents acting as attackers, including autonomous reconnaissance, attack-path adaptation, attack orchestration and autonomous exploit development. It also added agent-control mitigations and case studies including the GTG-1002 Claude Code espionage campaign and autonomous OpenAI evaluation agents compromising Hugging Face infrastructure. It extends ATLAS from attacks on AI systems to attacks carried out by AI agents, giving defenders shared identifiers for autonomous intrusion behavior.</description>
</item>
<item>
<title>OWASP releases 2026 edition of the GenAI LLM Top 10 mapped to the agentic list and ATLAS</title>
<link>https://agentic-cyber-explorer.pages.dev/events/owasp-genai-llm-top-10-2026-edition/</link>
<guid isPermaLink="false">event:owasp-genai-llm-top-10-2026-edition</guid>
<pubDate>Mon, 03 Aug 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The OWASP GenAI Security Project released the 2026 edition of its LLM Top 10, which it says updates rankings and expands threat coverage based on real-world incidents. OWASP says the edition maps risks to NIST, MITRE ATLAS, CWE and the OWASP Top 10 for Agentic Applications, and it was followed in September 2026 by an industry framework crosswalk and an Agent Control Standard. It aligns the main LLM application checklist with the agent-specific list, which affects how audits scope agent risk.</description>
</item>
<item>
<title>Anthropic proposes Cyber Jailbreak Severity scale with Glasswing partners</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-cyber-jailbreak-severity-framework-2026/</link>
<guid isPermaLink="false">event:anthropic-cyber-jailbreak-severity-framework-2026</guid>
<pubDate>Thu, 02 Jul 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>Anthropic published an early-draft Cyber Jailbreak Severity framework, developed with Project Glasswing partners, to score cyber jailbreaks on capability gain, breadth, ease of weaponization and discoverability, mapped to five levels from CJS-0 to CJS-4. It also described Fable 5's cyber classifier tiers, which block prohibited and high-risk dual-use requests such as exploit development while allowing defensive work like patching and incident response. A shared severity scale for safeguard bypasses is a precondition for proportionate government and industry responses like the June 2026 suspension.</description>
</item>
<item>
<title>Five Eyes cyber agency heads tell leaders AI is shifting cyber risk on a timescale of months</title>
<link>https://agentic-cyber-explorer.pages.dev/events/five-eyes-ai-shift-in-cyber-risk-statement-2026/</link>
<guid isPermaLink="false">event:five-eyes-ai-shift-in-cyber-risk-statement-2026</guid>
<pubDate>Mon, 22 Jun 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The heads of the Five Eyes cyber agencies issued a joint statement that AI is rapidly transforming cyber risk and that organizations must act within months, not years. They ask leaders to reduce attack surface, accelerate patching as exploitation windows shorten, replace unsupported legacy systems, strengthen identity controls, and prepare for incidents. It is the highest-level joint government signal that frontier AI vulnerability discovery changes patching expectations.</description>
</item>
<item>
<title>Anthropic maps 832 banned accounts onto MITRE ATT&amp;CK and finds AI use moving deeper into attacks</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-mapping-ai-cyber-threats-attack-2026/</link>
<guid isPermaLink="false">event:anthropic-mapping-ai-cyber-threats-attack-2026</guid>
<pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Anthropic analyzed 832 accounts it banned for malicious cyber activity between March 2025 and March 2026 and mapped their use of Claude onto MITRE ATT&amp;CK. It reports that the most common AI use was preparation such as writing malware, that use shifted toward activity after initial compromise, and that the share of actors its system rated medium risk or higher rose from 33% to 56% between the two six-month halves. A year of provider data suggests attackers apply AI later in the attack lifecycle, which weakens traditional ways of ranking threat actors by skill.</description>
</item>
<item>
<title>Frontier Model Forum issue brief catalogs emerging security practices for AI agents</title>
<link>https://agentic-cyber-explorer.pages.dev/events/fmf-emerging-security-practices-ai-agents-2026/</link>
<guid isPermaLink="false">event:fmf-emerging-security-practices-ai-agents-2026</guid>
<pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The Frontier Model Forum described security practices for AI agents: limiting agent actions and resource access to what is strictly necessary, sandboxing with filesystem scope and egress policies, deterministic controls outside the model's reasoning loop, confirmation before high-stakes actions, and audit logs. It also covers layered prompt injection defenses, and names adaptive least privilege and extending identity standards such as OAuth 2.0 to agents as promising or developing areas. It documents what frontier developers say they actually do to contain their own agents.</description>
</item>
<item>
<title>NSA AI Security Center publishes security design considerations for Model Context Protocol deployments</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nsa-mcp-security-design-considerations-2026/</link>
<guid isPermaLink="false">event:nsa-mcp-security-design-considerations-2026</guid>
<pubDate>Wed, 20 May 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The NSA's Artificial Intelligence Security Center released a cybersecurity information sheet on the Model Context Protocol, warning that adoption has outpaced safeguards. It recommends vetting MCP tools, least-privilege access and isolation, validating outputs where one model's output feeds another, and detailed logging integrated with security monitoring, and it lists poor approval workflows among the risks. It is signals-intelligence agency guidance specific to the protocol many agents use to reach tools and data.</description>
</item>
<item>
<title>UK NCSC advises incremental agentic AI adoption with minimal, expiring permissions</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-thinking-carefully-agentic-ai-2026/</link>
<guid isPermaLink="false">event:ncsc-thinking-carefully-agentic-ai-2026</guid>
<pubDate>Fri, 15 May 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>NCSC authors advise deploying agentic AI incrementally through tightly bounded pilots, granting agents only the minimum permissions with temporary credentials, and defining in advance who approves access, monitors behavior and can halt the agent. They recommend incident response plans for agent failure and loss-of-control scenarios. It turns joint international agentic AI guidance co-authored by the NCSC into concrete operating rules, including temporary credentials and a named owner who can stop the agent.</description>
</item>
<item>
<title>UK NCSC issues ten questions for organizations using AI models to find vulnerabilities</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-ten-questions-ai-vulnerability-discovery-2026/</link>
<guid isPermaLink="false">event:ncsc-ten-questions-ai-vulnerability-discovery-2026</guid>
<pubDate>Mon, 11 May 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The head of the NCSC's Vulnerability Management Group published ten questions for organizations considering AI-driven vulnerability discovery. The questions stress having a process to triage and fix findings, prioritizing exploitable issues, weighing data, permission, legal and jurisdiction risks of the chosen model, starting with the external attack surface, and planning for future models. It is government guidance on the operational side effects of defensive AI vulnerability discovery, such as unmanageable finding volume.</description>
</item>
<item>
<title>CoSAI publishes Agentic Identity and Access Management and agentic security outlook papers</title>
<link>https://agentic-cyber-explorer.pages.dev/events/cosai-agentic-identity-access-management-2026/</link>
<guid isPermaLink="false">event:cosai-agentic-identity-access-management-2026</guid>
<pubDate>Wed, 06 May 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The Coalition for Secure AI released a paper on identity and access management for agents from its Secure Design Patterns for Agentic Systems workstream, focused on unique agent credentials and task-limited access. A companion paper on multi-agent systems discusses semantic-layer attacks, intent-based authorization and proposes agent detection and response as a defense category. Agent identity and scoped credentials are a core open problem named in NIST, CISA and OWASP work, and this is an industry design pattern for it.</description>
</item>
<item>
<title>CISA, ASD's ACSC and international partners publish joint guidance on careful adoption of agentic AI</title>
<link>https://agentic-cyber-explorer.pages.dev/events/five-eyes-careful-adoption-agentic-ai-2026/</link>
<guid isPermaLink="false">event:five-eyes-careful-adoption-agentic-ai-2026</guid>
<pubDate>Fri, 01 May 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>CISA and the Australian Signals Directorate, with US and international partners, published guidance on the cybersecurity risks of agentic AI services and recommended mitigations. CISA highlights expanded attack surface, privilege creep, behavioral misalignment and obscure event records as risks, and recommends avoiding broad access, starting with low-risk use cases, and folding agent security into existing risk models. It is coordinated multi-government guidance written specifically for organizations deploying agents.</description>
</item>
<item>
<title>UK NCSC and AISI warn defenders that frontier AI is rapidly improving at simulated enterprise attacks</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-frontier-ai-defenders-readiness-2026/</link>
<guid isPermaLink="false">event:ncsc-frontier-ai-defenders-readiness-2026</guid>
<pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>An NCSC technical director and an AI Security Institute researcher wrote that leading models went in about 18 months from barely progressing on a simulated enterprise attack range to completing over half of a 32-step scenario. They urge defenders to prioritize fundamentals such as asset inventory, access control, secure configuration and logging, and to adopt AI carefully for defense. NCSC CEO Richard Horne followed on April 15, 2026, warning that AI will make discovering and exploiting weaknesses easier, faster and cheaper. It pairs government capability measurements with concrete defender priorities at the moment frontier cyber capability became a policy issue.</description>
</item>
<item>
<title>NIST CAISI launches AI Agent Standards Initiative on interoperability, security and identity</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nist-ai-agent-standards-initiative-2026/</link>
<guid isPermaLink="false">event:nist-ai-agent-standards-initiative-2026</guid>
<pubDate>Tue, 17 Feb 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>CAISI, with NIST's Information Technology Laboratory, launched an initiative to support industry-led standards and open protocols for AI agents and research on agent security and identity. Announced deliverables included the agent security RFI, an AI agent identity and authorization concept paper with comments due April 2, 2026, and sector listening sessions from April 2026. It is the main US government program for agent identity, authorization and security standards.</description>
</item>
<item>
<title>NIST CAISI requests public input on security considerations for AI agent systems</title>
<link>https://agentic-cyber-explorer.pages.dev/events/caisi-rfi-security-ai-agents-2026/</link>
<guid isPermaLink="false">event:caisi-rfi-security-ai-agents-2026</guid>
<pubDate>Thu, 08 Jan 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>CAISI published a Federal Register request for information on practices for measuring and improving the security of AI agent systems, citing hijacking, backdoors and indirect prompt injection. It asks about model-level, system-level and human-oversight controls, assessment methods, and ways to limit, modify and monitor deployment environments. It is a US government solicitation focused specifically on agent security controls and how to measure them.</description>
</item>
<item>
<title>NIST releases preliminary draft Cyber AI Profile (IR 8596) under CSF 2.0</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nist-cyber-ai-profile-preliminary-draft-2025/</link>
<guid isPermaLink="false">event:nist-cyber-ai-profile-preliminary-draft-2025</guid>
<pubDate>Tue, 16 Dec 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>NIST published a preliminary draft Cybersecurity Framework Profile for Artificial Intelligence, aligned with CSF 2.0. It is organized around three focus areas: securing AI systems, using AI for cyber defense, and thwarting AI-enabled cyberattacks, with comments due January 30, 2026. It is the vehicle through which NIST intends to fold AI-enabled attack and defense, including agents, into the CSF outcomes organizations already report against.</description>
</item>
<item>
<title>OWASP publishes Top 10 for Agentic Applications (ASI01-ASI10)</title>
<link>https://agentic-cyber-explorer.pages.dev/events/owasp-top-10-agentic-applications-2025/</link>
<guid isPermaLink="false">event:owasp-top-10-agentic-applications-2025</guid>
<pubDate>Tue, 09 Dec 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The OWASP GenAI Security Project released its Top 10 for Agentic Applications, a list of ten risk categories specific to agents that plan, hold memory, call tools and act with delegated authority. The release came with an updated Agentic Threats and Mitigations taxonomy (v1.1) and a capture-the-flag practice platform. It is OWASP's agent-specific risk list, complementing its Top 10 for LLM applications.</description>
</item>
<item>
<title>UK NCSC says prompt injection may never be fully mitigated and urges impact reduction</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-prompt-injection-not-sql-injection-2025/</link>
<guid isPermaLink="false">event:ncsc-prompt-injection-not-sql-injection-2025</guid>
<pubDate>Mon, 08 Dec 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>An NCSC technical director argued that prompt injection differs from SQL injection because LLMs do not separate data from instructions, so it should be treated as a residual confused-deputy risk rather than a patchable bug. The NCSC recommends deterministic safeguards that constrain system actions, dropping an LLM's privileges to those of the party whose content it is processing, and logging full inputs, outputs and tool calls. A national cyber agency stating that prompt injection is inherent shifts agent security from filtering toward privilege and blast-radius design.</description>
</item>
<item>
<title>CISA, ASD and partners issue principles for securely integrating AI, including agents, into OT</title>
<link>https://agentic-cyber-explorer.pages.dev/events/cisa-principles-ai-in-operational-technology-2025/</link>
<guid isPermaLink="false">event:cisa-principles-ai-in-operational-technology-2025</guid>
<pubDate>Wed, 03 Dec 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>CISA and the Australian Signals Directorate, with NSA, FBI and national cyber agencies of Canada, Germany, the Netherlands, New Zealand and the UK, published four principles for integrating AI into operational technology. The guidance explicitly covers machine learning, LLM-based AI and AI agents because of the security and safety challenges they pose in industrial environments. It is multinational guidance that addresses AI, including agents, acting in safety-critical industrial control environments.</description>
</item>
<item>
<title>MITRE ATLAS 5.0 adds AI agent techniques such as context poisoning and exfiltration via tool invocation</title>
<link>https://agentic-cyber-explorer.pages.dev/events/mitre-atlas-v5-agent-techniques-2025/</link>
<guid isPermaLink="false">event:mitre-atlas-v5-agent-techniques-2025</guid>
<pubDate>Tue, 30 Sep 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>MITRE ATLAS version 5.0.0 added a set of techniques for attacks on AI agents, including agent context poisoning of memory and threads, modifying agent configuration, credential theft from agent configuration, and exfiltration via agent tool invocation, and renamed LLM Plugin Compromise to AI Agent Tool Invocation. Version 5.1.0 (November 6, 2025) added agent-specific mitigations such as tool permission configuration and human-in-the-loop for agent actions. ATLAS is the ATT&amp;CK-style reference defenders use to map detections, and these versions made agent compromise a first-class part of it.</description>
</item>
<item>
<title>NIST proposes SP 800-53 control overlays for securing AI, including single- and multi-agent systems</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nist-cosais-control-overlays-concept-2025/</link>
<guid isPermaLink="false">event:nist-cosais-control-overlays-concept-2025</guid>
<pubDate>Thu, 14 Aug 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>NIST released a concept paper for Control Overlays for Securing AI Systems (COSAiS), which would tailor SP 800-53 security controls to AI use cases. The planned use cases include generative AI assistants, predictive AI, single-agent systems, multi-agent systems and controls for AI developers, informed by the AI 100-2 E2025 taxonomy. As of the project page, only an annotated outline for the predictive AI overlay (January 8, 2026) had followed; agent overlays had not been published. Agent-specific SP 800-53 overlays would give federal agencies and contractors auditable control baselines for agents; their absence is a notable gap.</description>
</item>
<item>
<title>Coalition for Secure AI publishes Principles for Secure-by-Design Agentic Systems</title>
<link>https://agentic-cyber-explorer.pages.dev/events/cosai-secure-by-design-agentic-principles-2025/</link>
<guid isPermaLink="false">event:cosai-secure-by-design-agentic-principles-2025</guid>
<pubDate>Wed, 16 Jul 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The Coalition for Secure AI, an OASIS Open Project, published three principles for agentic systems. The principles call for agents that are human-governed and accountable, bounded and resilient with strict, purpose-specific entitlements, and transparent and verifiable through secure AI supply chain controls and telemetry that supports monitoring and forensics. It is an industry consensus statement that bounded entitlements and forensic telemetry are baseline requirements for agents.</description>
</item>
<item>
<title>MCP specification revision classifies servers as OAuth resource servers and adds security best practices</title>
<link>https://agentic-cyber-explorer.pages.dev/events/mcp-spec-authorization-update-2025/</link>
<guid isPermaLink="false">event:mcp-spec-authorization-update-2025</guid>
<pubDate>Wed, 18 Jun 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The 2025-06-18 revision of the Model Context Protocol specification classifies MCP servers as OAuth resource servers with protected resource metadata, and requires clients to implement RFC 8707 resource indicators so malicious servers cannot obtain tokens meant for others. It also clarifies authorization security considerations and adds a security best practices page. It is the main protocol-level change addressing token misuse between MCP clients and servers.</description>
</item>
<item>
<title>NSA, CISA and FBI with allies publish AI Data Security best practices</title>
<link>https://agentic-cyber-explorer.pages.dev/events/five-eyes-ai-data-security-2025/</link>
<guid isPermaLink="false">event:five-eyes-ai-data-security-2025</guid>
<pubDate>Thu, 22 May 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The NSA AI Security Center, CISA, the FBI and international partners released a cybersecurity information sheet on securing data used to train and operate AI systems across the lifecycle. It recommends robust data protection, proactive risk management and stronger monitoring and threat detection, and is aimed at defense industrial base, national security system, federal and critical infrastructure operators. Data poisoning and tampering of retrieval and training data are upstream routes to compromising agents that read that data.</description>
</item>
<item>
<title>NIST AI 100-2 E2025 taxonomy adds a dedicated section on security of AI agents</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nist-ai-100-2-e2025-security-of-agents-2025/</link>
<guid isPermaLink="false">event:nist-ai-100-2-e2025-security-of-agents-2025</guid>
<pubDate>Mon, 24 Mar 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>NIST released the 2025 edition of its adversarial machine learning taxonomy, co-authored with the UK AI Security Institute and US AI Safety Institute staff. Unlike the 2023 edition, it includes a section on the security of agents, noting that tool-using agents are exposed to direct and indirect prompt injection and that hijacking can lead to arbitrary code execution or data exfiltration. It is the reference US government taxonomy that COSAiS overlays and CAISI agent work build on.</description>
</item>
<item>
<title>OWASP Agentic Security Initiative releases Agentic AI Threats and Mitigations v1.0</title>
<link>https://agentic-cyber-explorer.pages.dev/events/owasp-agentic-ai-threats-and-mitigations-2025/</link>
<guid isPermaLink="false">event:owasp-agentic-ai-threats-and-mitigations-2025</guid>
<pubDate>Mon, 17 Feb 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>OWASP's Agentic Security Initiative published a threat-model-based reference of emerging threats to LLM-powered autonomous agents and corresponding mitigations. It became the taxonomy underpinning the later OWASP Top 10 for Agentic Applications, which shipped with an updated v1.1 of this guide. It is a community taxonomy built specifically for agents rather than chat applications.</description>
</item>
<item>
<title>Cloud Security Alliance publishes MAESTRO seven-layer threat modeling framework for agentic AI</title>
<link>https://agentic-cyber-explorer.pages.dev/events/csa-maestro-agentic-threat-modeling-2025/</link>
<guid isPermaLink="false">event:csa-maestro-agentic-threat-modeling-2025</guid>
<pubDate>Thu, 06 Feb 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The Cloud Security Alliance published MAESTRO (Multi-Agent Environment, Security, Threat, Risk, and Outcome), a threat modeling framework for agentic AI authored by Ken Huang. It organizes analysis into seven layers from foundation models to the agent ecosystem and highlights agent-specific threats such as goal manipulation, agent impersonation and collusion between agents. It is a practitioner method for threat modeling multi-agent systems, aimed at gaps its authors see in STRIDE-style frameworks.</description>
</item>
<item>
<title>UK publishes AI Cyber Security Code of Practice with 13 principles, later standardized as ETSI TS 104 223</title>
<link>https://agentic-cyber-explorer.pages.dev/events/uk-ai-cyber-security-code-of-practice-2025/</link>
<guid isPermaLink="false">event:uk-ai-cyber-security-code-of-practice-2025</guid>
<pubDate>Fri, 31 Jan 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The UK government published a voluntary Code of Practice for the Cyber Security of AI setting 13 principles across five lifecycle phases for developers, system operators and data custodians. It names indirect prompt injection as a distinct AI risk and includes provisions on audit trails, least-privilege access and monitoring system behaviour. ETSI published the content as Technical Specification TS 104 223 in April 2025. It is a government baseline whose provisions (least privilege, behaviour monitoring, prompt audit trails) map directly onto agent deployments.</description>
</item>
<item>
<title>NIST second draft of AI 800-1 on dual-use foundation model misuse adds cybersecurity appendix</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nist-ai-800-1-second-draft-cyber-misuse-2025/</link>
<guid isPermaLink="false">event:nist-ai-800-1-second-draft-cyber-misuse-2025</guid>
<pubDate>Wed, 15 Jan 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>NIST's AI Safety Institute released a second public draft of NIST AI 800-1, voluntary guidelines for managing misuse risk from dual-use foundation models across the lifecycle. NIST says the draft adds detailed evaluation approaches, a marginal-risk framework, and an extensive appendix on cybersecurity misuse risk, and covers both closed and open model developers. It was the main US government draft practice for measuring and mitigating cyber misuse of frontier models before the 2025 policy shift.</description>
</item>
<item>
<title>Frontier Model Forum issue brief maps defensive uses of frontier AI in cybersecurity</title>
<link>https://agentic-cyber-explorer.pages.dev/events/fmf-issue-brief-ai-for-cyber-defense-2024/</link>
<guid isPermaLink="false">event:fmf-issue-brief-ai-for-cyber-defense-2024</guid>
<pubDate>Fri, 22 Nov 2024 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The Frontier Model Forum, an industry body of frontier labs, published an issue brief on using frontier AI for cyber defense. It lists use cases including process automation for incident response, natural-language querying and analysis, vulnerability discovery and fixing, open-source intelligence and training, and recommends designing for human-AI collaboration rather than full automation. It records the lab consortium's stated position on defensive agent use before autonomous defense became a policy priority in 2026.</description>
</item>
<item>
<title>OWASP releases 2025 Top 10 for LLM Applications with prompt injection first and Excessive Agency</title>
<link>https://agentic-cyber-explorer.pages.dev/events/owasp-llm-top-10-2025-edition-2024/</link>
<guid isPermaLink="false">event:owasp-llm-top-10-2025-edition-2024</guid>
<pubDate>Sun, 17 Nov 2024 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The OWASP GenAI Security Project released the 2025 edition of its Top 10 for LLM Applications. Prompt injection remains the top risk, and the list includes Excessive Agency (LLM06) covering systems granted the ability to call functions and take actions, along with system prompt leakage and vector and embedding weaknesses. It is OWASP's practitioner checklist for LLM application risk and the direct predecessor of its agent-specific lists.</description>
</item>
<item>
<title>NSA-led Five Eyes guidance on deploying externally developed AI systems securely</title>
<link>https://agentic-cyber-explorer.pages.dev/events/five-eyes-deploying-ai-systems-securely-2024/</link>
<guid isPermaLink="false">event:five-eyes-deploying-ai-systems-securely-2024</guid>
<pubDate>Mon, 15 Apr 2024 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The NSA's Artificial Intelligence Security Center led joint guidance with CISA, the FBI and the national cyber centres of Australia, Canada, New Zealand and the UK on deploying and operating externally developed AI systems. It sets objectives to improve the confidentiality, integrity and availability of AI systems and to mitigate known vulnerabilities, organized around protecting, detecting malicious activity against, and responding to incidents involving AI systems. It is joint government guidance aimed at organizations deploying AI rather than building it, the population that deploys agents.</description>
</item>
<item>
<title>NIST publishes adversarial machine learning taxonomy covering direct and indirect prompt injection</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nist-ai-100-2-e2023-aml-taxonomy-2024/</link>
<guid isPermaLink="false">event:nist-ai-100-2-e2023-aml-taxonomy-2024</guid>
<pubDate>Thu, 04 Jan 2024 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>NIST released the final NIST AI 100-2 E2023 report, a taxonomy and terminology of attacks on and mitigations for machine learning systems. Its generative AI chapter includes separate sections on direct prompt injection and indirect prompt injection, but no dedicated section on agents. It established the US government vocabulary for prompt injection that later agent security guidance and evaluations reuse.</description>
</item>
<item>
<title>UK NCSC and US CISA publish multinational Guidelines for Secure AI System Development</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-cisa-guidelines-secure-ai-system-development-2023/</link>
<guid isPermaLink="false">event:ncsc-cisa-guidelines-secure-ai-system-development-2023</guid>
<pubDate>Mon, 27 Nov 2023 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The UK NCSC published guidelines for providers of AI systems, developed with CISA and endorsed by agencies from 18 countries. The guidance is organized around four lifecycle areas: secure design, secure development, secure deployment, and secure operation and maintenance, and takes a secure-by-default approach. It is the baseline multinational government guidance that later AI and agent security documents (the UK Code of Practice, ETSI TS 104 223, the 2026 agentic guidance) build on.</description>
</item>
</channel>
</rss>
