PETALING JAYA: As artificial intelligence (AI) assistants become increasingly capable of acting on behalf of users, Malaysia is moving to add safeguards before these digital agents are given too much power, says the National Cyber Security Agency (Nacsa).
Its chief executive Dr Megat Zuhairy Megat Tajuddin said Nacsa introduced the Artificial Intelligence Systems Cyber Security Framework (AISCF) to help organisations develop and deploy AI systems securely through a risk-based approach.
He said the risks intensify when AI agents are given extensive autonomy, powerful privileges and access to connected services, alongside limited human oversight.
“At machine speed, one compromised agent could turn a single security failure into a chain of damaging actions,” he said when contacted yesterday.
Megat Zuhairy said the threat goes beyond data theft, as compromised AI agents could potentially be used to carry out fraudulent payments, redirect funds, reset passwords, disclose confidential communications, alter digital identity information or gain access to connected systems.
He said organisations must first understand an AI agent’s purpose, access rights and potential impact before allowing it to act on behalf of users.
“A non-human identity is a digital identity used by software, a bot or an AI agent.
“A password is merely a key; an AI agent is a key-holder that can also decide when and how to use that key.
“If manipulated or compromised, it could expose personal data, impersonate the user, send fraudulent messages, change account details or initiate unauthorised transactions before the user realises anything is wrong,” he said.
AI agents, in line with the AISCF, should have a distinct and traceable identity, a clearly responsible owner, minimum and time-limited permissions, continuous monitoring and an immediate shutdown mechanism or “kill switch”, he noted.
He also said high-impact actions, including financial transfers, changes to payment recipients, password resets and modifications to digital identity information, should require explicit human approval.
“AI agents must never be given unlimited authority simply for the sake of convenience,” Megat Zuhairy added.
Datuk Dr Amirudin Abdul Wahab, who is the former chief executive officer of CyberSecurity Malaysia, said organisations should adopt a Zero Trust approach, enforcing least-privilege access, strong identity and phishing-resistant authentication, as well as clear policy guardrails that define what agents are authorised to do.
“High-risk actions should always require human approval while continuous monitoring, audit logging, prompt injection protection and regular red-team testing help detect, prevent and respond to misuse or compromise,” he said.
Red-term testing refers to when ethical hackers act like real attackers to break into an organisation’s software security.
