On 1 May 2026, six national cybersecurity agencies published joint guidance on the deployment of agentic AI systems. The authoring agencies were ASD's Australian Cyber Security Centre, CISA, NSA, NCSC-UK, the Canadian Centre for Cyber Security, and NCSC-NZ. This is not a vendor framework or a conference paper. It is the collective security position of the Five Eyes alliance and their partners, published simultaneously, on the same threat.
The guidance is unambiguous: "Strong governance, explicit accountability, rigorous monitoring and human oversight are not optional safeguards but essential prerequisites."¹
It goes further. Organisations should never grant agentic AI broad or unrestricted access to sensitive data or critical systems. Agentic AI should only be used for low-risk and non-sensitive tasks.¹ Separation of duties must be codified, with defined roles, consensus mechanisms, and delegation expiry.²
Read that again. Six governments, in a single document, have described the architectural requirement for confirmed human authority before agentic AI executes high-consequence actions. They have named the control. They have said it is not optional.
They have not named the product that implements it.
This is the gap GoFirm closes. GoFirm is an out-of-band, biometrically confirmed, deterministic authority control that sits at the execution boundary. Before a high-consequence action executes, whether initiated by a human, an AI agent, or an infrastructure system, a named authority must confirm it on a registered personal device through a separate channel. If confirmation does not arrive, the action does not execute. The audit trail is immutable and permanent.
The agencies also note that existing evaluation methods for agentic AI security are still evolving, and that some attack vectors unique to agentic systems may not be fully captured by current frameworks.³ That is precisely the point. Detection and response tooling was built for a world where humans initiate actions. Agentic systems initiate actions autonomously, at machine speed, and often without the kind of observable signature that triggers an alert. By the time detection fires, the action has already executed.
The execution boundary control does not rely on detection. It does not fire after the fact. It holds before the action executes, regardless of how the instruction arrived, who or what issued it, and whether any upstream control was bypassed.
The guidance says human oversight is a prerequisite. GoFirm is the architecture that makes that prerequisite enforceable rather than procedural.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. ASD ACSC, CISA, NSA, NCSC-UK, CCCS, NCSC-NZ. Careful Adoption of Agentic AI Services. May 2026. https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services
2. Ibid. Separation of duties and delegation expiry guidance.
3. Ibid. Threat intelligence and evaluation methods section.
