KISA AI security guide adds checks for autonomous tools
KISA is revising its AI security guide as companies adopt autonomous agents and physical AI systems with limited human oversight.
Atlas Newsdesk ·

South Korea's KISA is revising last year's AI security guide as autonomous agents move into company systems and connected devices. The state-run agency said the update will address services that can operate with limited human oversight.
The Korea Internet & Security Agency, which operates under South Korea's Ministry of Science and ICT, said Tuesday it is working on a new version of the guide first issued last year. KISA said the revised document will include a checklist for security issues tied to agentic AI services.
KISA widens last year's guide
The update moves the agency's focus from general AI security advice toward systems that can plan, execute and adjust tasks without continuous human approval. KISA described the guide as a broad risk-management tool rather than a response aimed at one class of high-performance models.
The agency said common control measures could also be included for physical AI, a term used for systems that interact with real-world devices and machinery. That would move the review beyond data loss: when AI is connected to equipment, unauthorized instructions can affect physical operations.
Agentic services bring checklist risks
Agentic AI has become a priority for companies deploying tools that can act with fewer direct prompts from workers. Such systems are harder to supervise than conventional software when they can chain actions across company systems.
KISA's planned checklist is expected to focus on the points where autonomy changes the security burden: identity controls, permission limits, logging and human review. The agency did not specify a publication date in the details provided Tuesday, leaving the timing of implementation open.
For companies, the practical issue is accountability: a tool that acts across systems can create records, move data or trigger another service before a person checks the result. A checklist can define where approvals, logs and shutdown options are expected.
Hugging Face case frames concern
The update follows a July breach at Hugging Face, described as involving roughly 700 AI agents rather than a single compromised account. That episode has become part of the industry's debate over how autonomous systems should be governed.
KISA said the revised guide is intended to cover agentic AI risks broadly, not to target high-performance models linked to that episode. The distinction gives the agency room to set baseline practices for a wider market rather than write rules around one breach.
The agency did not say whether the revised guide will be mandatory, voluntary or tied to procurement. That leaves companies without a clear compliance date as internal deployments of autonomous tools spread through corporate technology stacks.
Three paths for agent controls
If companies adopt KISA's checklist as a procurement standard, global firms selling agentic AI into South Korea may face more documentation and audit demands. For KISA, that path would make the guide a market-shaping reference; for the wider industry, it would push security controls earlier into product design.
If adoption remains voluntary and uneven, the macro effect would be limited to risk management within firms rather than a shift in national productivity or regulation. KISA would still set expectations, but vendors and corporate buyers would decide how much oversight to build into agentic services.
If physical AI becomes a larger part of the guide, the main open question is how far software security controls can cover machines and devices. In that scenario, global manufacturers would face more scrutiny on connected systems, KISA would move closer to industrial safety concerns, and AI providers would need clearer limits on what agents can trigger.