Case Study 04 Strategic Intelligence Federal / DoD

The Five Eyes published their AI security guidance. We published the ten controls it left out.

When the intelligence alliance of five nations sets guidance, it becomes the floor everyone aligns to. We ran a gap analysis against it and documented ten controls the guidance doesn't cover — the ones an adversary would reach for first.

10
controls documented that the alliance guidance omits
5
nations' combined guidance analyzed as the baseline
Public
published in the open — source and date on the record
The Situation

When the Five Eyes speak, programs treat it as the standard of care.

Joint guidance from the US, UK, Canada, Australia, and New Zealand carries the weight of the entire alliance. Contractors align to it, auditors reference it, and "we followed the guidance" becomes the definition of due diligence. Which is exactly why its gaps matter so much.

The Trigger

Aligning to a standard is not the same as being secure.

01 / CONSENSUS LAG

Multi-nation guidance moves at the speed of consensus.

Agreement across five governments is slow by design. The threat landscape for AI agents is not. The gap between them is where risk lives.

02 / FALSE FLOOR

Programs mistake the floor for the ceiling.

Guidance is a minimum bar. Treated as the complete list, it caps a program's security at exactly the coverage the guidance happened to include.

03 / KNOWN OMISSIONS

Adversaries read the same guidance you do.

What a public standard doesn't require is a map of where defenders are unlikely to be looking. The omissions are the plan.

What We Published

Ten controls the alliance guidance leaves to chance.

A representative view of the gap analysis. Each maps to an adversary technique against AI agents that the baseline guidance does not require you to address.

C-01
Agent identity & attribution
C-02
Tool-call authorization scope
C-03
Prompt-injection containment
C-04
Memory & context poisoning
C-05
Autonomous action rollback
C-06
Inter-agent trust boundaries
C-07
Model supply-chain provenance
C-08
Runtime capability revocation
C-09
Decision audit & forensics
C-10
Fail-closed autonomy limits
Evidence inventory
Published gap analysis (10 controls)PUBLISH READY
Source guidance citation & versionPUBLISH READY
Per-control adversary technique mappingPUBLISH READY
Publication timestampPUBLISH READY
The Implication
If your program's AI security ends where the Five Eyes guidance ends, you have ten known gaps — and so does your adversary.

Stop Threats Before They Execute

Your free Kernel-Level Defense Buyer’s Guide is ready to download.

By providing my email address, I consent to receive emails and text messages—including newsletters and marketing communications—from creators of Warden Secure, Cyber Strategy Institute, our flagship zero-trust platform for ransomware prevention, and agree to the Terms and Privacy Policy. You may unsubscribe at any time.