Kaspersky has shared guidelines for mitigating risks associated with using autonomous AI agents in corporate infrastructure. The document applies the principles of Cyber Immunity, an approach at the heart of building secure-by-design systems. Drawing on known incidents and existing threat models, the new report examines the risks associated with increasingly autonomous agentic systems and outlines how to build trust in their architecture to minimize the potential impact of errors or compromise.
Today, AI agents are being used across an increasing number of corporate scenarios — from routine business process automation to high-impact use cases like supporting software development tasks or IT security functions. The report, titled “AI agent security through the lens of Cyber Immunity,” analyzes common AI agent use cases, the levels of agentic autonomy, and real-world incidents involving AI agents that led to actual harm to systematize known risks and dissect existing threat models.
To help organizations reduce incident risks, including those related to malicious exploitation of agents, excessive privileges granted to AI agents, and data deletion by agents, in the report, Kaspersky sets out Cyber Immunity principles that can be applied to AI agent design, namely:
- Define security assumptions for AI agents at the design stage: consider LLM and any data entering the system from external sources untrusted by default, and require an explicit human confirmation for any irreversible action;
- Minimize the Trusted Computing Base (TCB): keep the set of components that must be trusted for security as small as possible;
- Isolate components: use sandboxes and virtual machines to isolate the execution environment, separate trusted and untrusted contexts, and isolate individual agents within multi-agent systems.
- Control interactions using a default-deny approach: apply policies to tool calls and their arguments, which agents use to interact with external APIs and resources, to control network traffic and prevent agents from dynamically modifying their supply chain.
The report also includes practical recommendations for CISOs, CIOs, and CTOs, including inventorying AI agents, developing flexible isolation and containerization policies, and managing the agentic supply chain to build secure agentic infrastructures.
“While Cyber Immunity was initially conceived outside the realm of AI, its core principles map directly onto advanced LLM‑based systems. When developers work with fundamentally non‑deterministic and untrusted components — which large language models should be considered by default — they should embed trust into the solution’s architecture to limit the potential impact of errors or compromise,” notes Vladislav Tushkanov, the head of Kaspersky AI Technology Research Center. “A secure architecture should be further reinforced with a multi‑layered defense strategy underpinned by technologies such as AI Firewall and modern security layers including sandboxes, EDR, and SIEM to better support today’s intelligent applications.”
