South Korea wants to make sure autonomous software cannot pull the digital trigger without human sign-off.
The Korea Internet & Security Agency, which operates under South Korea’s Ministry of Science and ICT, told Reuters it is developing version 2.0 of its “AI Security Guide.” The update will address autonomous AI agents operating across software, networks, and physical systems.
For IT leaders, the proposal underscores a growing security concern: AI agents can receive credentials, use external tools, modify systems, and initiate actions with limited supervision. Organizations deploying them may therefore need tighter access controls, stronger audit trails, and human approval for consequential actions.
In a statement, KISA said the revised guide would focus on security issues that could arise as companies deploy agentic AI services and offer a checklist to manage those risks. The agency added that the manual could include common control measures applicable to “physical AI” systems capable of interacting with real-world devices and machinery.
According to Reuters, the proposed guide would divide security responsibilities across the AI deployment pipeline:
- Developers would restrict agents’ access to tools and maintain tamper-resistant decision logs.
- Service providers would implement real-time shutdown controls and incident-tracking mechanisms.
- Enterprise users would configure operating privileges and require human approval for high-risk actions.
The delegation dilemma
The risk extends beyond familiar concerns involving generative AI, such as proprietary-data exposure and inaccurate outputs. Agentic systems can also act within company environments, making permission controls and oversight more consequential.
Granular controls could reduce the risk of an AI agent taking an unauthorized or harmful action, but they may also introduce friction for enterprise adopters.
Companies deploy agents to automate work such as resolving support tickets, adjusting machinery, and executing financial transactions. Approval requirements and strict permission limits could slow that automation, but they would give organizations more control over high-consequence actions.
South Korea has not yet finalized the guide, so its exact requirements and enforcement status remain unclear. Enterprise security teams do not need to wait, however, to inventory deployed agents, restrict their permissions, preserve audit logs, and require human approval before software can make consequential financial, operational, or physical changes.
Read more: OpenAI’s GPT-6 Astra cybersecurity assessment explores how increasingly capable AI systems are changing the threat landscape for enterprise security teams.