Government Advisory

Agentic AI in Cyber Defence: Promising but Requires Caution

ACSC · 24 July 2026
Key Takeaway If your business uses or is considering AI-driven security tools, keep a human reviewing and approving critical decisions rather than letting the AI act fully unsupervised.

Agentic AI—artificial intelligence systems capable of making decisions and taking actions with limited human input—is rapidly advancing, and cybersecurity authorities are taking notice. Recent developments highlight how these tools are becoming more capable, offering potential benefits for defenders but also introducing new risks if deployed without adequate controls.

Because agentic AI can act autonomously, mistakes or manipulation of these systems can have outsized consequences compared to traditional software. Authorities are recommending that any organisation considering these tools do so cautiously, ensuring strong security safeguards, continuous monitoring, and human oversight remain in place to catch errors or malicious misuse before they cause harm.

For small and medium businesses, this guidance is a timely reminder that new AI-powered security tools should not be treated as 'set and forget' solutions. Even as vendors market agentic AI as a way to automate threat detection and response, businesses should ensure a human remains in the loop to validate the AI's decisions, particularly for anything involving sensitive data or critical systems.

Putting a number on risk like this? How to run an ISO 31000 risk assessment ->

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.