Kaspersky Issues Guidelines on Securing AI Agents with Cyber Immunity Approach
Kaspersky has shared guidelines on mitigating risks associated with the use of autonomous AI agents in corporate infrastructure. The document applies the principles of Cyber Immunity, an approach focused on building secure-by-design systems.
Drawing on known incidents and existing threat models, the report examines risks associated with increasingly autonomous agentic systems and outlines approaches to building trust into their architecture to minimize the potential impact of errors or compromise.
The document was presented as part of AI Everything Global, a global expo focused on transformative AI solutions across industries, taking place in Abu Dhabi from October 6-7. Kaspersky is a sponsor of this year's conference, which brings together AI shapers from more than 60 countries.
Today, AI agents are being used across an increasing number of corporate scenarios, ranging from routine business process automation to high-impact applications such as software development and IT security functions.
The report, titled “AI agent security through the lens of Cyber Immunity,” analyzes common AI agent use cases, levels of agentic autonomy, and real-world incidents involving AI agents that resulted in actual harm. It aims to systematize known risks and examine existing threat models.
Kaspersky Outlines Cyber Immunity Principles for AI Agents
To help organizations reduce incident risks, including malicious exploitation of agents, excessive privileges granted to AI agents, and data deletion by agents, Kaspersky outlines several Cyber Immunity principles that can be applied to AI agent design:
- Define security assumptions at the design stage: Treat the LLM and any data entering the system from external sources as untrusted by default, while requiring explicit human confirmation for irreversible actions.
- Minimize the Trusted Computing Base (TCB): Keep the set of components that must be trusted for security as small as possible.
- Isolate components: Use sandboxes and virtual machines to isolate execution environments, separate trusted and untrusted contexts, and isolate individual agents within multi-agent systems.
- Control interactions using a default-deny approach: Apply policies to tool calls and their arguments used by agents to interact with external APIs and resources, control network traffic, and prevent agents from dynamically modifying their supply chain.
The report also provides practical recommendations for CISOs, CIOs and CTOs, including inventorying AI agents, developing flexible isolation and containerization policies, and managing the agentic supply chain to build secure agentic infrastructures.
“While Cyber Immunity was initially conceived outside the realm of AI, its core principles map directly onto advanced LLM-based systems. When developers work with fundamentally non-deterministic and untrusted components — which large language models should be considered by default — they should embed trust into the solution’s architecture to limit the potential impact of errors or compromise,” said Vladislav Tushkanov, Head of Kaspersky AI Technology Research Center.
He added, “A secure architecture should be further reinforced with a multi-layered defense strategy underpinned by technologies such as AI Firewall and modern security layers including sandboxes, EDR, and SIEM to better support today’s intelligent applications.”
Kaspersky Showcases AI Technologies at AI Everything Global
At AI Everything Global, Kaspersky is exhibiting its proprietary technologies and solutions for real-world AI applications, particularly for industrial use.
The company's booth features Kaspersky MLAD, an AI-powered technology for early anomaly detection in industrial assets, and the Kaspersky Neuromorphic Platform, which uses spiking neural network-based technology to enable energy-efficient security solutions for cyber-physical systems.
Kaspersky is also showcasing Kaspersky Trusted Intelligent Agents for Retrieval and Analysis (TIARA), a technology designed to equip an organization's large language model with domain-specific knowledge to improve the accuracy and reliability of responses in real-world industry applications.
Event participants can also meet security experts from Kaspersky's AI Technology Research Center, which tracks AI-driven threats, conducts research into AI algorithm security, and incorporates AI and machine learning into Kaspersky cybersecurity products and services.
About Kaspersky AI Technology Research Center
Experts at the Kaspersky AI Technology Research Center have been working with AI in cybersecurity and Secure AI for almost 20 years to help discover and counter a broad range of threats. The team contributes AI expertise based on its research to enhance Kaspersky solutions, including AI-powered threat detection and alert triage and GenAI-powered Threat Intelligence.


