Rejuvenate IT Logo

Before you let an AI tool act on your behalf, answer these five questions

On 4 August the National Cyber Security Centre issued a statement about recent incidents in which advanced AI models carried out actions nobody had sanctioned, and in some cases behaved deceptively on the open internet.

Ollie Whitehouse, the NCSC’s chief technology officer, called it a serious reminder of the risks these capabilities pose, and made a point that applies well beyond the laboratories: noticing a problem after it happens is not enough. These systems need safeguards, oversight while they are running, and a plan for when something unexpected occurs.

That sounds like a warning for AI companies, and partly it is. But the NCSC also points businesses to its guidance on adopting agentic AI – the tools that do not merely answer questions but go off and act: booking things, sending messages, moving files, signing in to other systems on your behalf.

Who this affects

Any business being sold an AI assistant that does more than talk. That is now most of them, and the pitch is usually the same: connect it to your email, your calendar and your files, and it will handle the admin.

The NCSC’s assessment is reassuring in one way and pointed in another. Most of the risk is not new – access control, monitoring, knowing who is accountable. What changes is reach and predictability. An agent can be given access to systems and data in ways ordinary software never was, and it can interpret an instruction in a way no reasonable person would have expected. Give something broad access and unpredictable judgement at the same time, and small mistakes travel a long way.

The five questions to settle first

The NCSC’s advice is to start small, keep agents to low-risk work at first, and apply the security habits you already have rather than inventing new ones. Before connecting anything to real systems or real data, it says to be clear on all of the following:

  • Who owns it? Not which company sold it – which person here is answerable for it.
  • Who approves what it can reach? Every mailbox, folder and system it can touch should be a decision somebody made, not a default it arrived with.
  • Who watches what it does? Oversight while it runs, not a report afterwards.
  • Who reviews it when something goes wrong? Decide before it does.
  • Who can stop it? Somebody must be able to switch it off quickly, and know how.

Not a reason to avoid it

None of this says do not use AI. These tools genuinely save time, and the businesses using them sensibly are getting real value. It says decide what it may touch before you connect it, rather than after – which is exactly what we would say about any new system with the keys to your email.

If you are weighing one up and want a straight opinion on what it should and should not be allowed to reach, that is a conversation our managed IT services and cyber security teams have most weeks now. We will tell you if we think it is fine, too – you will hear back in about 15 minutes on average.

Call us on 01202 237 273 or book a call.