Five Eyes Cybersecurity Agencies’ Careful Agentic AI Adoption Guidance, Operationalized By AEGIS
As of 2026-10-06
What is Five Eyes Cybersecurity Agencies’ Careful Agentic AI Adoption Guidance, Operationalized By AEGIS?
Agentic use cases need two tracks from day one — read-only informational agents and gated actionable agents — or the audit team rebuilds the design under pressure by month six.
What it is
Forrester analyst Janet Worthington summarises the Five Eyes cybersecurity agencies' joint guidance on cautious agentic-AI adoption and shows how Forrester's AEGIS framework operationalises it. For SAP analytics consultants, this matters the moment a client says "let's let Joule agents act on our data, not just answer questions about it."
The Five Eyes (US, UK, Canada, Australia, New Zealand) guidance, taken verbatim, asks for: explicit human-in-the-loop checkpoints on irreversible actions, complete audit trails of agent decisions, least-privilege credentials per agent task, and adversarial testing before production. AEGIS maps these to a four-pillar control set the consultant can hand to a CISO without a translation step. In an SAP context, the relevant Joule + Build Process Automation combination touches GL postings, purchase requisitions, and master-data updates — all irreversible in audit terms. None of those should fire without the checkpoints the Five Eyes pattern requires.
The practical consequence for SAP delivery: agentic use cases need a two-track design from day one — an "informational" track (read-only Joule answers) and an "actionable" track (gated approvals, signed audit logs, role-scoped tokens). Most pilots that skip this two-track design rebuild it under audit pressure in month 6.
Why it matters
- The Five Eyes guidance requires human-in-the-loop checkpoints on irreversible actions, complete audit trails, least-privilege credentials, and adversarial testing before production.
- In SAP, Joule plus Build Process Automation touches GL postings, purchase requisitions, and master-data updates — all irreversible in audit terms, so none should fire without those checkpoints.
- AEGIS maps the Five Eyes guidance to a four-pillar control set a consultant can hand a CISO directly, without translation.
Key points
- Five Eyes requires: human checkpoints, complete audit trails, least-privilege per task, adversarial testing
- AEGIS = Forrester's operational mapping of the Five Eyes guidance
- Design Joule pilots as two-track from day one: informational + actionable
- GL postings, purchase requisitions, master-data updates are 'irreversible' in audit terms
- SAP AI Agent Hub (launched in LeanIX Nov 2025, AI Governance Assistant added Sep 2026) is the concrete inventory/governance artefact for the least-privilege and audit-trail pillars
- NVIDIA OpenShell answers 'can this action safely execute'; Joule Studio's runtime governance layer answers 'should this action happen at all' — keep the two distinct
- Register each track (informational/actionable) as a separate agent identity with its own credential scope — a shared service-account credential silently collapses the two-track design
- Credential revocation still depends on Cloud Identity Services propagating to in-flight sessions — AI Agent Hub can flag an ungoverned agent but does not itself guarantee mid-session revocation
Terms used on this page
- Five Eyes
- Intelligence alliance (US, UK, Canada, Australia, New Zealand) issuing joint AI safety guidance via CISA, NSA, ASD, CSE and NCSC/UK.
- AEGIS
- Forrester's framework operationalising the Five Eyes agentic-AI guidance into an enterprise control set.
- Two-track design
- Splitting agent capabilities into a read-only informational track and a gated, audit-logged actionable track.
- SAP AI Agent Hub
- Cross-vendor inventory and governance layer for agents, LLMs and MCP servers, launched in SAP LeanIX in November 2025; carries verification badges and, since September 2026, an AI Governance Assistant that classifies EU AI Act/NIST exposure.
- NVIDIA OpenShell
- Open-source runtime co-developed by SAP and NVIDIA that sandboxes what an agent's action can technically execute — the 'can this happen safely' layer, distinct from business-policy governance.
- Adversarial testing (agentic)
- Deliberately attempting prompt injection, privilege-escalation and policy-bypass against an agent before production and on an ongoing cadence, as the Five Eyes guidance requires.
Sources
- Forrester — Five Eyes Cybersecurity Agencies’ Careful Agentic AI Adoption Guidance, Operationalized By AEGIS (Janet Worthington)
- SAP Help — Joule security and access control
- NCSC UK — Guidelines for secure AI system development
- CISA — Artificial Intelligence
- CISA — Secure by Design
- NIST — AI Risk Management Framework
- SAP News Center — Autonomous Enterprise: Business Transformation Management Solutions, SAP AI Agents Work at Scale (AI Governance Assistant, 2026-09-22)
- SAP News Center — Secure AI Agents: How SAP and NVIDIA Co-Define Enterprise-Grade Agent Execution (NVIDIA OpenShell, 2026-05-12)
- LeanIX — SAP LeanIX Announces Launch of AI Agent Hub and Key Industry Partnerships (2025-11-04)
- SAP Help Portal — SAP Build Process Automation overview
- SAP Community — Step-by-Step Guide: SAP-Managed Joule Setup
- European Commission — Regulatory framework proposal on artificial intelligence (EU AI Act policy page)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.