9.5 C
Munich
星期六, 4 4 月, 2026

From guardrails to governance: A CEO’s guide for securing agentic systems

Must read

Coleen Rooney's 40th birthday party underway at mansion as helicopter lands

Coleen Rooney's 40th birthday party is well underway and a helicopter was recently seen landing in the grounds of her Cheshire home today as...

Save up to $1,070 with $900 guaranteed with Motorola’s latest deal on the 1TB Razr Ultra (2025)

The phone is a steal at its current price, so save while you can! #Save #guaranteed #Motorolas #latest #deal #1TB #Razr #Ultra

‘Structural collapse’ at football stadium leaves 60 people injured in Peru

At least 60 people have been injured after a 'structural collapse' at a football stadium in Peru, with hospitals on high alert following the...

T-Mobile is destroying itself as insiders dump the stock and customers get ready to leave

T-Mobile’s days as the Un-carrier are over as ridiculous changes are ruining the wireless provider's image. #TMobile #destroying #insiders #dump #stock #customers #ready #leave

3. Permissions by design: Bind tools to tasks, not to models

A common anti-pattern is to give the model a long-lived credential and hope prompts keep it polite. SAIF and NIST argue the opposite: credentials and scopes should be bound to tools and tasks, rotated regularly, and auditable. Agents then request narrowly scoped capabilities through those tools.

In practice, that looks like: “finance-ops-agent may read, but not write, certain ledgers without CFO approval.”

The CEO question: Can we revoke a specific capability from an agent without re-architecting the whole system?

Control data and behavior

These steps gate inputs, outputs, and constrain behavior.

4. Inputs, memory, and RAG: Treat external content as hostile until proven otherwise

Most agent incidents start with sneaky data: a poisoned web page, PDF, email, or repository that smuggles adversarial instructions into the system. OWASP’s prompt-injection cheat sheet and OpenAI’s own guidance both insist on strict separation of system instructions from user content and on treating unvetted retrieval sources as untrusted.

Operationally, gate before anything enters retrieval or long-term memory: new sources are reviewed, tagged, and onboarded; persistent memory is disabled when untrusted context is present; provenance is attached to each chunk.

The CEO question: Can we enumerate every external content source our agents learn from, and who approved them?

5. Output handling and rendering: Nothing executes “just because the model said so”

In the Anthropic case, AI-generated exploit code and credential dumps flowed straight into action. Any output that can cause a side effect needs a validator between the agent and the real world. OWASP’s insecure output handling category is explicit on this point, as are browser security best practices around origin boundaries.

#guardrails #governance #CEOs #guide #securing #agentic #systems

- Advertisement -

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisement -

Latest article

Coleen Rooney's 40th birthday party underway at mansion as helicopter lands

Coleen Rooney's 40th birthday party is well underway and a helicopter was recently seen landing in the grounds of her Cheshire home today as...

Save up to $1,070 with $900 guaranteed with Motorola’s latest deal on the 1TB Razr Ultra (2025)

The phone is a steal at its current price, so save while you can! #Save #guaranteed #Motorolas #latest #deal #1TB #Razr #Ultra

‘Structural collapse’ at football stadium leaves 60 people injured in Peru

At least 60 people have been injured after a 'structural collapse' at a football stadium in Peru, with hospitals on high alert following the...

T-Mobile is destroying itself as insiders dump the stock and customers get ready to leave

T-Mobile’s days as the Un-carrier are over as ridiculous changes are ruining the wireless provider's image. #TMobile #destroying #insiders #dump #stock #customers #ready #leave

Legendary musician dies after ‘serious health issues’ as famous pals pay tribute

Legendary R&B session drummer James Gadson has sadly died and tributes have been pouring in, including a heartfelt message from Ghostbusters star Ray Parker...