Skip to the main content.
Impact

Uncover industry news and insights across End User Computing, Network, Storage and Cloud.

 

Practical insights and outcomes through reports, whitepapers and case studies.

AIoT Use Cases

Don’t guess a ROI, get a ROI

Learn More
AIoT Case Studies
About Us

Learn about our certifications, confirming our commitment to ensuring that our customer data is protected.

 

Experienced technology leaders driving innovation, cybersecurity, cloud, and digital transformation outcomes across Australia.

 

We protect your privacy and handle your personal information with care and security in mind.

 

We protect your privacy and handle your personal information with care and security in mind.

Coming Soon - Exciting stuff is on the way!

5 min read

Does the Essential Eight cover AI agents? What Australian organisations need to do before December 2026

Does the Essential Eight cover AI agents? What Australian organisations need to do before December 2026

The Essential Eight protects your environment, but does it protect you from AI agents? With new Australian AI guidance already here and Privacy Act changes arriving in December 2026, security teams need to start closing the gap between traditional cyber controls and AI risk.

Does the Essential Eight cover AI agents? What Australian organisations need to do before December 2026

The short answer is no. The Essential Eight was last updated in November 2023, and none of its eight strategies address AI agents, prompt injection or an agent acting beyond its intended scope. That is not a criticism of the framework. It was built to stop the attack techniques of its time, and it still does that well.

The longer answer is that Australian guidance for AI agents now exists, a Privacy Act deadline arrives in December, and the Essential Eight itself is being revised. This article sets out what applies today, what the frameworks ask for, and the practical gap they leave for security teams to close.

The Essential Eight is the floor, not the answer 

Patching, application control, multi-factor authentication, restricting administrative privileges and regular backups all apply to the infrastructure your AI runs on and the accounts it uses. If you are at Maturity Level Two, you have a solid foundation.

That foundation does not tell you which AI agents are operating in your environment, what they can access, or whether their actions match what they were deployed to do. An agent that inherits a user's session passes every Essential Eight control that user passes. The framework was never designed to ask the next question.

In June 2026, the Australian Signals Directorate (ASD) opened consultation on evolving the Essential Eight into a broader "Essentials" series with threat-informed guidance for contemporary environments. That work is under way, but it is not yet a standard you can assess against.

The guidance that does cover AI agents

On 1 May 2026, ASD's Australian Cyber Security Centre, together with Five Eyes partner agencies, published Careful adoption of agentic AI services. It is the most relevant Australian reference for anyone deploying or securing AI agents, and it groups the risks into five categories.

Privilege risks. Agents are often granted broad access to reduce friction, then evaluated only at deployment. The guidance's own example describes a procurement agent whose excessive privileges are inherited by an attacker through a compromised low-risk tool.

Design and configuration risks. Poorly bounded objectives, ambiguous instructions and weak enforcement of limits allow agents to exceed their authorised functions.

Behavioural risks. Prompt injection, jailbreaks and goal misalignment can cause an agent to take actions its operator never intended, sometimes by finding a shortcut that technically completes the task.

Structural risks. Agents call other agents and tools, so a compromise in one component propagates through the chain.

Accountability risks. When an agent acts, it is often unclear who approved the action, who owns the outcome, and how it would be reviewed.

The guidance recommends least privilege, strong identity management for agents, human oversight at defined control points, continuous monitoring, and containment that limits the blast radius of unexpected behaviour. It also advises starting with low-risk tasks and expanding autonomy incrementally.

What changes on 10 December 2026

From that date, organisations covered by the Privacy Act must disclose in their privacy policy where a computer program uses personal information to make, or substantially contribute to, a decision that could significantly affect an individual's rights or interests. This is a transparency obligation, not a restriction on using AI. The Office of the Australian Information Commissioner is finalising its guidance, and the small business exemption still applies.

The practical consequence is that an organisation needs to know where automated decision-making is happening before it can disclose it. For many, that is the first time anyone will have tried to produce a complete list of the AI systems and agents in use. It is worth doing that inventory well, because it serves the security programme as much as the privacy one.

For APRA-regulated entities, CPS 234 already requires information security controls proportionate to the threat, and an agent with broad access to regulated data is squarely within that expectation.

The gap between guidance and evidence

Each of these frameworks describes what good looks like. None of them provides a way to confirm, on an ordinary Tuesday, that a specific agent is behaving within its scope.

That gap exists for a structural reason. Detection has traditionally worked by spotting deviation from a baseline. Agents have no behavioural history, and their normal activity is fast and wide-ranging. Reading a thousand files may be the task or it may be exfiltration, and volume alone will not distinguish them. What does is lineage: the chain from prompt to identity to tool call to system action. Reconstructing that chain, in real time, is what allows a team to say whether an action was in scope and, if not, what else the agent has already done.

This is the capability the guidance's "continuous monitoring" and "containment" recommendations depend on, and it is where AI Detection and Response sits. We covered how it relates to existing MDR and EDR in AIDR vs MDR: what AI Detection and Response adds to the security stack you already run.

Where to Start

Begin with discovery. Establish which AI tools and agents are running, who deployed them, what identities they use and what they can reach. This is the first step in every framework above, and it is the one most organisations have not yet completed.

Then apply the ACSC's controls in order of exposure: tighten agent privileges, define human control points for consequential trainingactions, and make sure agent activity is monitored with enough context to reconstruct what happened.

Most Australian security teams are lean and already rely on managed services for around-the-clock coverage. Extending that coverage to agent activity, through the same sensor and the same Australian SOC that already monitors endpoints and identities, is a more realistic path than standing up a separate capability.

If you would like a clear picture of the AI agents already operating in your environment, talk to Secure Agility's MDR team.

Frequently asked questions

 

1. Does the Essential Eight cover AI?
No. None of the eight strategies address AI agents, prompt injection or agent scope. They remain the baseline for the infrastructure and accounts AI relies on.

2. What Australian guidance exists for AI agents?
ASD's ACSC published Careful adoption of agentic AI services with Five Eyes partners on 1 May 2026. It defines five risk categories and recommends least privilege, identity management, human oversight, continuous monitoring and containment.

3. What changes under the Privacy Act in December 2026?
From 10 December 2026, covered entities must disclose qualifying automated decision-making in their privacy policies. It is a transparency requirement, and the OAIC's final guidance is pending.

4. What is shadow AI and how do I find it?
Shadow AI is AI use that has not been approved or governed. It is often embedded in licensed products and developer tools. Finding it requires discovery across endpoints, browsers and SaaS platforms rather than a policy survey.

5. Do APRA-regulated entities need to secure AI agents?
CPS 234 requires controls proportionate to the threat. An agent with access to regulated data falls within that obligation, even though the standard does not mention AI.

Around 1,090 words including FAQs. One thing to flag: the OAIC guidance was expected in September and may have landed in the last few days - worth a check before publication so the "pending" wording can be updated if needed.

Around 1,090 words including FAQs. One thing to flag: the OAIC guidance was expected in September and may have landed in the last few days - worth a check before publication so the "pending" wording can be updated if needed.

Secure Agility can help you identify the AI agents operating in your environment, assess where your current security coverage has gaps, and decide which controls to prioritise. Talk to Secure Agility →

AIDR vs MDR: What AI Detection and Response adds to the security stack you already run

1 min read

AIDR vs MDR: What AI Detection and Response adds to the security stack you already run

AI agents can access data, call tools and take action across your environment. Learn what AI Detection and Response (AIDR) adds to EDR and MDR, and...

Read More
How AI Agents Get Compromised: Prompt Injection Explained

1 min read

How AI Agents Get Compromised: Prompt Injection Explained

AI agents can be turned against the organisation that deployed them without malware or an exploit. Learn how indirect prompt injection, the lethal...

Read More
Managed IT or Cloud Services: What’s the Difference?

1 min read

Managed IT or Cloud Services: What’s the Difference?

Your IT budget has a line item called “cloud” and another called “managed services,” and nobody on the finance team can quite tell you why you need...

Read More