Kaspersky has shared guidelines on mitigating risks associated with the use of autonomous AI agents in a corporate infrastructure. The document applies the principles of Cyber Immunity, an approach at the heart of building secure-by-design systems. Drawing on known incidents and existing threat models, the new report examines the risks associated with increasingly autonomous agentic systems and outlines how to build trust in their architecture to minimize the potential impact of errors or compromise.
The document was presented as part of AI Everything Global — a global expo of transformative AI solutions across all industries — taking place in Abu Dhabi from October 6-7. This year, Kaspersky is a sponsor of the conference which gathers AI shapers from 60+ countries.
Today, AI agents are being used across an increasing number of corporate scenarios — from routine business process automation to high-impact use cases like supporting software development tasks or IT security functions. The report, titled “AI agent security through the lens of Cyber Immunity,” analyzes common AI agent use cases, the levels of agentic autonomy, and real-world incidents involving AI agents that led to actual harm to systematize known risks and dissect existing threat models.
To help organizations reduce incident risks, including those related to
malicious exploitation of agents, excessive privileges granted to AI agents,
and data deletion by agents, in the report, Kaspersky sets out Cyber Immunity
principles that can be applied to AI agent design, namely:
- Define security assumptions for AI agents at the design stage: consider LLM and any data entering the system from external sources untrusted by default, and require an explicit human confirmation for any irreversible action;
- Minimize the Trusted Computing Base (TCB): keep the set of components that must be trusted for security as small as possible;
- Isolate components: use sandboxes and virtual machines to isolate the execution environment, separate trusted and untrusted contexts, and isolate individual agents within multi-agent systems.
- Control interactions using a default-deny approach: apply policies to tool calls and their arguments, used by agents to interact with external APIs and resources, control network traffic and prevent the agent from dynamically modifying its supply chain.
The report also includes practical recommendations for CISOs, CIOs and
CTOs, spanning among others inventorying AI agents, developing flexible
isolation and containerization policies, and managing the agentic supply chain
to build secure agentic infrastructures. For more practical advice, please
check the full document here.
“While Cyber Immunity was initially conceived outside the realm of AI, its
core principles map directly onto advanced LLM‑based systems. When developers
work with fundamentally non‑deterministic and untrusted components — which large
language models should be considered by default — they should embed trust into
the solution’s architecture to limit the potential impact of errors or
compromise,” notes Vladislav Tushkanov, the head of Kaspersky AI Technology
Research Center. “A secure architecture should be further reinforced with a
multi‑layered defense strategy underpinned by technologies such as AI Firewall
and modern security layers including sandboxes, EDR, and SIEM to better support
today’s intelligent applications.”
At the AI Everything Global conference, Kaspersky is exhibiting its proprietary technologies and solutions for real-world AI application, in particular for industrial use. Kaspersky’s booth is featuring a cutting-edge AI-powered technology for early anomaly detection in industrial assets (Kaspersky MLAD) and spiking neural network-based Kaspersky Neuromorphic Platform enabling energy-efficient solutions for security of cyber-physical systems. The company also brings Kaspersky Trusted Intelligent Agents for Retrieval and Analysis (TIARA), a technology equipping an organization’s large language model (LLM) with domain-specific knowledge to ensure the accuracy and reliability of responses in real-world industry applications.
At the Kaspersky booth, event participants are able to meet security experts from Kaspersky’s AI Technology Research Center who track AI-driven threats, conduct research on AI algorithm security and embed AI and machine learning into Kaspersky cybersecurity products and services. To learn more about Kaspersky’s AI Technology Research Center, please visit the Kaspersky website.
About AI Technology Research Center
Our experts at the Kaspersky AI Technology Research Center have been working with AI in cybersecurity and Secure AI for almost 20 years to help discover and counter the broadest range of threats. Our team contributes AI expertise, based on their research, to enhance our solutions, from AI-powered threat detection and alert triage to GenAI-powered Threat Intelligence.