Kaspersky has shared guidelines on mitigating risks associated with the use of autonomous AI agents in a corporate infrastructure. The document applies the principles of Cyber Immunity, an approach at the heart of building secure-by-design systems.

Drawing on known incidents and existing threat models, the new report examines the risks associated with increasingly autonomous agentic systems and outlines how to build trust in their architecture to minimise the potential impact of errors or compromise.

Today, AI agents are being used across an increasing number of corporate scenarios — from routine business process automation to high-impact use cases like supporting software development tasks or IT security functions. The report, titled “AI agent security through the lens of Cyber Immunity,” analyses common AI agent use cases, the levels of agentic autonomy, and real-world incidents involving AI agents that led to actual harm to systematise known risks and dissect existing threat models.

To help organisations reduce incident risks, including those related to malicious exploitation of agents, excessive privileges granted to AI agents, and data deletion by agents, in the report, Kaspersky sets out Cyber Immunity principles that can be applied to AI agent design, namely:

  • Define security assumptions for AI agents at the design stage: Consider LLM and any data entering the system from external sources untrusted by default, and require an explicit human confirmation for any irreversible action;
  • Minimise the Trusted Computing Base (TCB): Keep the set of components that must be trusted for security as small as possible;
  • Isolate components: Use sandboxes and virtual machines to isolate the execution environment, separate trusted and untrusted contexts, and isolate individual agents within multi-agent systems.
  • Control interactions using a default-deny approach: Apply policies to tool calls and their arguments, used by agents to interact with external APIs and resources, control network traffic and prevent the agent from dynamically modifying its supply chain.

The report also includes practical recommendations for CISOs, CIOs and CTOs, spanning among others inventorying AI agents, developing flexible isolation and containerisation policies, and managing the agentic supply chain to build secure agentic infrastructures. For more practical advice, the full document can be viewed here.

“While Cyber Immunity was initially conceived outside the realm of AI, its core principles map directly onto advanced LLM‑based systems. When developers work with fundamentally non‑deterministic and untrusted components — which large language models should be considered by default — they should embed trust into the solution’s architecture to limit the potential impact of errors or compromise,” notes Vladislav Tushkanov, the head of Kaspersky AI Technology Research Center. “A secure architecture should be further reinforced with a multi‑layered defence strategy underpinned by technologies such as AI Firewall and modern security layers including sandboxes, EDR, and SIEM to better support today’s intelligent applications.”