NCSC agentic AI guidance: the security controls expected of UK data controllers
In short: The NCSC agentic AI guidance, published on 15 May 2026, describes the security controls expected of organisations deploying AI agents: least privilege, limited scope, temporary credentials, monitoring, threat modelling and incident plans, with named individuals accountable. For UK data controllers it helps determine what UK GDPR Article 32 requires of them, and it…
