Agentic AI is the name for a tool that does not stop at handing you a draft, and the National Cyber Security Centre published interim advice on it on 20 August 2026. A principal security architect at the centre wrote it, short on alarm and long on control, and it opens on the observation that several recent incidents have involved AI systems carrying out unsanctioned or unintended activity.
Read it and you notice who it addresses, being system designers and operators rather than the managing partner of a six-person practice. The centre adds that formal guidance is coming and will replace the blog. Neither point lets your firm off. Most solicitors will meet their first agent inside a product they already pay for, sold as a feature that files, sends or updates without being asked twice, and the advice then works as the questions you put to whoever sells it.
Autonomy is the dial everything turns on
The controls apply in proportion to how much autonomy an agent is given. Some agents suggest and stop there. Others take actions, reach live systems and decide with little human involvement. The greater the autonomy, the centre says, the greater the damage when an agent malfunctions, reaches information it should not, or acts outside its intended scope.
Safeguards built into the model are a baseline rather than an answer. The advice states plainly that they may be bypassed and may not hold in higher-risk settings, so any use where failure lands above your tolerance needs your own controls around it. An agent writing an internal file note sits in a different class from one sending correspondence to an opponent, and both sit a long way from one that touches client money.
Prompting is not a control
The section on instructions repays a second reading. An agent has no common sense and may take a goal in a way nobody expected. Tell it what it must not do as well as what it must, and make the points where it stops for human approval both guaranteed and gated. On longer tasks agents compress their own context to save tokens, so the centre suggests repeating the critical constraints.
The line that matters most follows. Prompting alone is not a defence, and technical and operational limits have to sit behind it. The advice names three patterns of oversight. A human in the loop approves actions before they happen, a human on the loop watches and intervenes, and a human out of the loop leaves the agent running alone. Every agent in your firm belongs to one of the three, and someone should be able to say which.
The questions this puts to your supplier
Several controls turn straight into questions to ask before you switch anything on. Does the agent carry its own identity, in a class that separates it from the people it works for? Which credentials does it hold, and for how long, given that keys, tokens and live sessions are what the advice calls its blast radius? What can it reach across the network, and can that be narrowed to an approved list? Can you read a full record of what it did, reasoning traces and transcripts included, in a form nobody can quietly alter?
The centre also says agent activity should be treated as user activity and pulled into normal security monitoring, which is where a small practice will feel the gap. Nobody is reading logs at three in the morning. The advice offers a way in, being to run the early work in office hours, then extend to overnight running once the controls have earned your confidence. Anyone weighing the same decision on an assistant that sends email in the firm's name will find the permissions question laid out here.
Somebody has to hold the stop switch
The final control is the plainest and the one to settle first. You should always be able to pull the plug and halt an agent immediately. The centre notes this means more than killing a process, because it reaches to network access and the link between the agent and the model behind it. For a firm that means a named person, a route to reach them out of hours, and a supplier who has put in writing how a customer stops an agent mid task.
None of this pulls against what the regulator said a week earlier. The SRA warning notice of 17 August keeps accountability with the solicitor, and the centre puts the same principle in its own terms. A system takes the action while people stay accountable for deploying it, for the access it was granted and for what follows. Before you agree to an agent that acts inside your systems, write down its autonomy level, its identity, its limits and its off switch. A firm that cannot fill in those four lines is not ready to turn it on.
The full advice sits in the NCSC blog on managing the cyber risk of agentic AI, which is open to read and asks nothing of you.
If a supplier is offering your firm an agent and you want those four lines filled in before you sign, that is work we do: bring us the proposal.
