Buried in the reporting on ASD's plans to retire the Essential Eight is a smaller detail worth its own explanation: a possible future Essentials chapter covering agentic AI. That's notable, because most security frameworks haven't formally addressed this yet. Here's what it actually means.
What Makes AI "Agentic"
Most businesses are familiar with AI as a chat-style tool, like asking Copilot to draft an email or summarise a document. Agentic AI is a step beyond that: instead of responding once to a prompt, an agent can plan and carry out a sequence of actions on its own, such as searching for information, calling other software, updating records, or sending communications, with limited human review at each step along the way.
That extra autonomy is exactly what makes agentic AI useful for automating real work, and exactly what creates new security questions that simple chat tools don't raise.
Why It Needs Its Own Security Thinking
Non-Person Entities
An AI agent acting inside your systems starts to look less like a tool and more like an account: it holds permissions, takes actions, and leaves an audit trail, but there's no single human directly behind every individual action it takes. Security frameworks are only beginning to address how to apply access controls, the principle of least privilege, and monitoring to these "non-person entities" the same way they already apply to staff accounts.
Prompt Injection
This is the genuinely new risk. If an AI agent reads content from outside sources - a webpage, an email, a document - as part of doing its job, an attacker can hide instructions inside that content, attempting to manipulate the agent into taking actions it wasn't meant to take. There's no direct equivalent to this in traditional software security, which is part of why it's drawing fresh attention from security agencies rather than being treated as a variant of an existing problem.
Should Your Business Be Doing Anything About This Now?
If your AI use is limited to chat-style tools that answer questions and don't take independent action, the risk profile is closer to existing AI usage policy concerns - data handling, accuracy, and confidentiality - rather than anything agent-specific.
If you're adopting tools that act on your behalf across email, files, or business systems, it's worth treating that agent's access the way you'd treat a new staff member's: understand exactly what it can see and do, apply the same restricted-privilege thinking you'd apply to a human account, and review its activity logs periodically.
Where This Sits in the Bigger Picture
A dedicated agentic AI chapter isn't confirmed yet, it's been reported as something ASD is considering for a later stage of the Essentials series. Either way, it's a useful early signal that agentic AI security is becoming its own category, distinct from general AI and cybersecurity guidance, rather than a footnote within it.
Frequently Asked Questions
What is agentic AI?
Agentic AI refers to AI systems that don't just respond to a single prompt, but can take multi-step actions on their own, such as browsing the web, calling other software, reading and sending emails, or making decisions across a sequence of tasks with limited human oversight at each step.
What is a non-person entity, in this context?
It's a way of describing an AI agent that holds its own identity and permissions within a system, similar to a user account, but without a human directly behind every action. Securing it means applying access controls and monitoring to the agent itself, not just to the humans who set it up.
What is prompt injection?
Prompt injection is when malicious instructions are hidden inside content an AI agent processes, such as a webpage, email, or document, in an attempt to make the agent take unintended actions. It's a risk specific to AI systems and doesn't have a direct equivalent in traditional software security.
Do small businesses need to worry about agentic AI security yet?
If you're using AI tools that only answer questions (like a chatbot), the risk is limited. If you're adopting AI agents that take actions on your systems, such as automating tasks across email, files, or business applications, it's worth understanding the access those agents have and reviewing it the same way you would a new staff account.
Before rolling out AI agents, it's worth checking your broader AI governance first - try our free 2-minute AI readiness self-assessment.
We help Perth businesses think through the security side of adopting AI tools, including ones that take action on your behalf.
Cybersecurity Services →Rolling out AI agents in your business?
Call 0433 087 091 for a free, no-obligation conversation about what access and oversight to put in place.
Book a Free ConsultationFor related reading, see How AI Is Changing Cybersecurity for Perth Businesses and AI Usage Policy for Staff.
This article is based on industry media reporting of ASD's stated plans at the time of writing, and is general information only, not formal compliance or legal advice. A dedicated agentic AI chapter has been reported as a possibility, not a confirmed inclusion - refer to ASD's own publications at cyber.gov.au for authoritative guidance as it develops.