Five magenta stations on a dark rail, Five Eyes agentic AI guidance for a small business, Amelia S. Gagne
Cybersecurity • Updated • 8 min read

Five Eyes Agentic AI Guidance for a Small Business

On 1 May 2026 CISA and allies published agentic AI guidance. For a small business: one low-risk job, its own login, tiny permissions, a person on pay and deletes, and a kill switch.

On 1 May 2026, CISA published Careful Adoption of Agentic AI Services with NSA and the cyber centres of Australia, Canada, the United Kingdom, and New Zealand. Five Eyes agentic AI guidance for a small business comes down to this: give the agent a small first job, its own login, limited access, a person on anything you cannot undo, and a way to turn it off.

Those six agencies are the cyber teams for the Five Eyes countries. The US signed twice, CISA and NSA. New Zealand's NCSC lists every co-author on one page. CISA's news release from that day is three asks in plain language. You do not need their org chart. You do need those three asks.

I run Kief Studio with Brian, from Shrewsbury, Massachusetts. We put AI into real workflows, not just demos. The usual failure is a person, not a model: someone watched a polished walkthrough, shared a password, and later the log blamed whoever was at lunch. The paper is that story, written for software that can take actions on its own.

Five magenta stations on a dark rail, Five Eyes agentic AI guidance for a small business
One job at a time. The allied paper is long. What a small team can do this month is a smaller first task and a named login for the software.

What the paper actually said

Agentic AI is software that can do a chain of work, not only write a paragraph. It can look something up, call a tool, send a message, move money, or change a record. Treat it like a new hire who can reach your inbox and your bank, stays logged in overnight, and will not stop to ask whether the last click was a good idea.

CISA's 1 May 2026 release asked for three things. Do not give the agent open access to sensitive data or critical systems. Start with jobs that are low risk and not sensitive. Put the agent into the security process you already use for vendors and contractors. The same release named what goes wrong when you skip that: a bigger attack surface, permissions that grow over time, the software drifting off the job you meant, and logs that do not tell you what happened.

That last one is the one shops skip. They buy a chatbot, paste an API key, and call it a project. The paper is asking you to treat the agent like staff. Staff get an account, a manager, and a last day. The agent should too.

On 27 August 2026, Bill Fisher and Ryan Galluzzo at NIST said the same thing in login language: the agent needs its own identifier, its own credentials, and its own permissions. Do not share a person's password with it. If it uses your login, the log says you did the work. I wrote the office version of that as what a non-human identity for an AI agent is.

Why a polished demo is easy to over-trust

The walkthrough is built to look finished. The answers come back fast, the sentences are clean, and the screen looks like a product you could turn on tomorrow. After ten minutes of that, people hand it a real job. Looking good in a meeting is not the same as being ready to refund a customer's card.

The other trap is a shared yes. If five of you can approve a refund, nobody feels like the owner when one goes wrong. Agents make that worse when they share a person's login, because the log still names a human. After an outage you will not know who to call. CISA's note called that out as records that are too vague to use. NIST said the same thing about shared passwords: you cannot prove who acted.

So start with work where a mistake is easy to fix. Have it draft an internal FAQ, or summarize last week's tickets for the team. Leave the public site, payroll, and vendor payments alone until that smaller job is boring.

Five-step flowchart of low-risk task, identity, least privilege, human gate, and logs for Five Eyes agentic AI guidance
Do these in order. If the agent does not have its own login, the rest is decoration. If you cannot turn it off, you have a demo you cannot stop.

Five moves a small business can actually run

Write the job in one sentence. CISA asked you to begin with low-risk, non-sensitive work. If you need and also to describe it, the job is still too big. Draft answers to our five most common support questions and leave them in a folder for a person to publish is a job. Help with operations is a wish. If we were on a call right now, I would ask you to say the sentence out loud. If you hedge, we cut until you can say it without a comma.

Give it its own login: a unique username, a named person who owns it, an expiry date, and a way to shut that login off without firing anyone. That is a non-human identity, which means a login for the software, not a copy of yours. NIST warned that shared passwords make it impossible to prove who did what. If every line in the log says Amelia, you cannot. You would not onboard a contractor onto the founder's Gmail. Do not onboard software that way either.

Give it only the access the job needs. Least privilege means the agent can do that one job and nothing extra. Do not leave it with leftover admin, and do not give it a just-in-case terminal. CISA said avoid broad or unrestricted access. Microsoft Incident Response's 30 June 2026 note on MCP walked through a finance example: someone changed the tool's hidden description, the agent attached extra invoice data, and every click still looked allowed. MCP is the plug that lets an agent use tools. Pin which tools it can call, and read the descriptions when they change. I unpacked that in MCP security for a small business.

Put a person on anything you cannot undo. Paying someone, sending a message to a customer, deleting a record, or pushing to the live site should wait for a human. Looking things up can run on its own. NIST also warned that if you make a person click allow on every tiny step, they get tired and click through. That is the same fatigue you get from too many phone prompts on a login. Watch the whole path, not only each click. Five refunds that each look fine can still empty the drawer. That is checking the sequence, not each click.

Keep logs that name the agent, and keep an off switch. If the log cannot name the agent, you will investigate a ghost. If you cannot disable the agent without deleting a person's account, you do not have an off switch. Practice turning it off once on a quiet afternoon, before you need to. Confirm the night job did not run. Turn it back on on purpose. Write two sentences about who is on call if it misbehaves over the weekend.

NIST's AI Risk Management Framework 1.0 came out on 26 January 2023. It is voluntary. A lot of buyers still recognize the four steps: Govern, Map, Measure, Manage. Put agents on the Map so you know what exists, and in Manage so you know how you stop them. The Five Eyes sheet is about adopting this class of tool. You can use both. You do not have to rename one as the other on a slide.

What that looks like in a week

On Monday, write the one sentence. If it takes a paragraph, cut the job until a stranger on this call could repeat it. If you cannot name the folder the drafts land in, you do not have a job yet. You have a wish with a model brand attached.

On Tuesday, create the agent login with an owner, an expiry date, and no personal password. Put the secret in the password manager, not in Slack. If the only copy of that secret is in a founder's notes app, you have not created a login. You have created another shared password with extra steps.

On Wednesday, strip tools until only that job remains. If a tool can send email or hit the live site, it is not on this agent yet. People skip this day because the demo used six tools and looked clever. Clever is how privilege creeps. Boring is how a first job stays a first job.

On Thursday, put pay, send, delete, and live deploys behind a person. Leave search and list open so the agent can still be useful. The human is not there to rubber-stamp every file open. The human is there for the irreversible step.

On Friday, confirm the log line names the agent. Turn it off. Turn it back on. Write two sentences about who is on call if it misbehaves over the weekend. If both of you are the company, one of you is still the owner, and the other is the backup who can flip the switch. The company is not a name. We will watch it is not a calendar.

That is CISA's request to put agentic AI in your security model, without a new binder. It sits next to work you may already do: the first five security moves, questions for vendors, where data governance starts, and how to evaluate AI tools without getting sold. If the demo was pretty and production never started, that stall has its own article: why AI pilots stall before production.

Logs only help if you can actually open them. That is why we keep engineering notes on kief.dev. If you want someone else to hold the night shift, that is what we built LTFI for: a hired department, not a box you install. I explained that split in what LTFI is. Brian's architecture write-up lives on briansgagne.com when the question is how the control is built. What I want you to take off this call is simpler: start small, name the actor, and keep a hand on the off switch.

Related reading

Frequently Asked Questions

What is the Five Eyes agentic AI guidance in one sentence?

On 1 May 2026, CISA, NSA, and the cyber centres of Australia, Canada, the UK, and New Zealand published Careful Adoption of Agentic AI Services: start on a low-risk job, limit access, and treat agents the way you already treat people and vendors.

Does a small business have to follow it?

It is guidance, not a law. It is still the clearest public allied baseline. The five moves above are the part a shop without a security team can actually run.

What is agentic AI?

Software that can take a sequence of actions, not only write a paragraph. If it can send, pay, delete, or change a record, it is an agent, and it needs a login and an off switch.

Is this the same as the NIST AI Risk Management Framework?

No. NIST AI RMF 1.0 from January 2023 is a voluntary US process: Govern, Map, Measure, Manage. The Five Eyes paper is about adopting agentic services. You can use both. You do not have to treat them as the same document.

Where should we start this week?

Write one sentence for one internal job where a mistake is easy to undo. Give that job its own login. Do not point it at payments, the public site, or anyone else's password.

AI Getting Started Aug 19, 2026 8 min

Why AI Pilots Stall Before Production

AI pilots stall before production for boring reasons: no owner, no definition of done, no data path, no kill switch. CISA 1 May 2026: start low-risk. NIST AI RMF: Govern, Map, Measure, Manage.

Work With Us

Need help building this into your operations?

Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.

Newsletter

New writing, straight to your inbox.

Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.

Subscribe