Securing Agentic AI for Critical Infrastructure

Syam Sathyan George | Technology Strategist • September 29, 2026

Share this article

A control model for systems that can reason act and change operational state

Agentic AI changes the security conversation. An agent can select tools, retrieve data, initiate a workflow and continue working toward a goal. In critical infrastructure, those actions can affect safety, continuity and public trust.


The central leadership question is straightforward: what authority does the agent receive, and what evidence supports that decision? A capable model wrapped in broad credentials and weak tool controls is not ready for production.


Start with a written operating boundary. Identify the approved objective, data, tools, prohibited actions and conditions that require human approval. Introduce autonomy in stages. Let the agent observe first, then recommend. Permit bounded execution only after the team has measured performance, tested failure modes and confirmed recovery.


Give the agent a distinct identity and owner. Use short-lived credentials and least-privilege permissions. Record what the agent requested, what a tool executed and what a person approved. Shared accounts make that chain difficult to reconstruct.


Control tools as carefully as users. Every connector expands the agent's practical power. A policy layer should validate identity, purpose and parameters before execution. Read access and write access need different controls, and sensitive actions should require a second verification step.


Assume the agent will encounter hostile input. Retrieved documents, web content and external data can contain instructions designed to redirect the system or expose information. Separate trusted instructions from untrusted content, validate inputs and outputs, restrict retrieval sources and keep secrets outside prompts.


Build observability for decisions and actions. Teams need records of goals, tool selections, approvals, policy decisions and resulting state changes. Logging should support investigation while following classification, privacy and retention requirements.


Keep human control operational. Reviewers need time, context and authority. Approval interfaces should show the proposed action, affected system, supporting evidence and a clear way to reject it. For operational technology, AI services should never bypass deterministic safety controls.


Finally, engineer containment and recovery. Use rate limits, transaction caps, segmentation and isolated execution. Test credential revocation, service shutdown, rollback and safe manual operation before production.


The leadership standard is evidence. If a team cannot explain permissions, reconstruct an action, stop the service and recover safely, the next step is better engineering, not broader autonomy.

Recent Posts

By Gregory Brown “Mr. IoT” | CEO Perspective • September 29, 2026
How policy accountability and controls become a scalable delivery capability
By Gregory Brown “Mr. IoT” | CEO Perspective • September 12, 2026
Most intelligent-infrastructure programs begin in a sensible place. A team connects an asset, collects its data and gives operators a dashboard. That creates visibility, but it does not settle the operating questions.
AI for Defense and National Security - Image on Desk
By Syam Sathyan George | Technology Strategist • September 9, 2026
The global competition over artificial intelligence is often described as a race for the most capable model. For national security, that is the wrong finish line. A model can perform impressively in a laboratory and still fail in real world.