A new practical framework for securing AI agents in corporate environments has been published by Kaspersky, applying its Cyber Immunity approach to autonomous software systems. The document addresses vulnerabilities in autonomous agentic architectures and provides mitigation steps based on documented threats. The report was formally presented during the AI Everything Global exhibition in Abu Dhabi.
Core Principles for Securing AI Agents
Organizations are increasingly deploying autonomous agents for tasks ranging from routine workflow automation to complex IT operations. Consequently, the research report, titled “AI agent security through the lens of Cyber Immunity,” establishes several core requirements for securing AI agents safely. These design rules focus on minimizing exposure to malicious inputs and unexpected system actions in modern software environments.
- Define security assumptions at design time by treating large language models and external data as untrusted by default, requiring explicit human approval for irreversible actions.
- Minimize the Trusted Computing Base (TCB) to limit the critical components required for baseline system security.
- Isolate system components using sandboxes and virtual machines, while segregating multi-agent workflows.
- Apply default-deny policies to tool calls, network traffic, and supply chain modifications.
Practical Guidance for Enterprise Leaders
Security executives, including CISOs, CIOs, and CTOs, face growing challenges as autonomous systems expand across the corporate network. The guide recommends maintaining a full inventory of active agents, configuring flexible containerization policies, and actively auditing external tool integrations. These practices help technical teams manage risks such as excessive privilege assignment, accidental data deletion, and malicious tool manipulation.
“When developers work with fundamentally non-deterministic and untrusted components, which large language models should be considered by default, they should embed trust into the solution’s architecture to limit the potential impact of errors or compromise.”
Vladislav Tushkanov, Head of Kaspersky AI Technology Research Center
Tushkanov added that secure architectures require multi-layered defenses, including firewalls, sandboxes, and modern endpoint detection tools.
Industrial Technology Demonstrations in Abu Dhabi
Beyond securing AI agents in standard IT setups, Kaspersky presented industrial-grade security tools at its conference booth. Highlights included the Kaspersky MLAD system for anomaly detection in physical plants and the Kaspersky Neuromorphic Platform, which provides energy-efficient defense for cyber-physical setups. The company also presented its TIARA technology, which connects corporate language models to domain-specific knowledge bases.
Protecting Corporate AI Deployments
As digital transformation accelerates across global enterprises, establishing structured defense mechanisms remains vital. Integrating disciplined security protocols ensures that advanced automation does not introduce unmanaged vulnerabilities into critical business processes. Research teams continue to monitor emerging algorithmic risks to safeguard modern corporate architectures.