The controls Five Eyes guidance implies but does not specify.
Allied cyber guidance on AI systems names the risks but stops short of implementable controls. This brief closes that gap: eight controls mapped to the guidance’s stated concerns, deployable today.
Maintain a verifiable chain of custody for what your models learn from and what your agents read at runtime.
Detect poisoning of agent memory and retrieval stores before it steers behavior — checksums, source pinning, and anomaly review.
Every model, system prompt, and policy version pinned, diffable, and reversible.
Every autonomous system carries its own verifiable identity so actions are attributable across organizational boundaries.
Agent permissions expire and are re-granted — standing authority is the exception, not the default.
Untrusted actions are blocked before they execute, not detected after — prevention over response.
Tamper-evident logs from provisioning to retirement, sufficient to reconstruct any incident.
When agents span vendors or agencies, accountability for their actions is contractually and technically assigned in advance.