Microsoft is calling for stronger security controls as government agencies expand their use of artificial intelligence, emphasizing the need to protect sensitive data while maintaining human oversight.
The recommendations focus on several areas, including data access controls, system-level AI testing, shared security operations, agent permissions, and workforce development. The approach is designed to allow agencies to benefit from AI while keeping control over sensitive information and critical decisions.
Securing AI Deployments
Microsoft argues that securing an AI model involves more than protecting the model itself. Security also depends on the information the system can access, the tools it can interact with, the identities using those tools, and the underlying infrastructure.
The company recommends evaluating AI systems within their actual deployment environments. This includes examining how models interact with users, data, external tools, and other services. Monitoring should also continue after an AI system has been deployed rather than ending once initial testing is complete.
Protecting Data and AI Memory
Government agencies would need to maintain controls over both approved and unauthorized AI tools, with permissions determined by the sensitivity of the underlying information.
Microsoft notes that AI prompts, query logs, agent memories, and generated responses can all contain confidential information. As a result, these components need to be treated as part of the organization’s overall data-security framework.
AI agents that interact with APIs or multiple applications should also have auditable identities. These records should identify who created the agent, what it is designed to do, and which human is responsible for it.
Permissions should remain narrowly scoped. Credentials should expire regularly, provide access only for the required task, and be reviewed whenever an agent’s responsibilities change.
Microsoft also recommends limiting individual tool calls through short-lived credentials and requiring authentication between agents. Organizations should additionally measure how quickly an agent’s access can be revoked if it is compromised.
Controlling Persistent Memory
Persistent AI memory presents another security challenge.
Microsoft’s security testing found that instructions contained within external content, including email, could influence information later stored in an agent’s memory. That information could subsequently be retrieved as trusted context.
To reduce this risk, Microsoft recommends separating external data from trusted instruction stores. Information obtained from outside sources should not be able to directly modify memory containing verified system instructions.
The company also found that AI agents can have difficulty distinguishing between stored user preferences and higher-priority instructions governing security policies.
Microsoft therefore recommends relying on technical policy controls rather than simply asking users to approve potentially conflicting instructions. Systems should be capable of blocking an operation until a reviewer has examined the command and the underlying operational context.
Shared Security Operations
Microsoft also proposes using shared security operations centers across government agencies.
Under this approach, centralized security teams could use both human analysts and autonomous AI agents to monitor multiple government organizations. Individual agencies would nevertheless retain their own cloud environments, data residency requirements, and zero-trust boundaries.
Central security personnel could receive temporary accounts with only the minimum permissions necessary to perform their duties. Security logs would remain within each agency’s own environment.
Microsoft argues that sharing security resources could reduce duplicated technology investments and give smaller agencies access to specialized cybersecurity expertise. However, the report does not provide data demonstrating that the approach would actually reduce government security costs.
Keeping Humans in Control
AI agents could be used to collect information surrounding security alerts and generate threat summaries.
Microsoft says this type of automated handling is already used for a large portion of its internal security incidents. More disruptive actions, however, would continue to require human approval.
For example, actions that could interrupt live services, such as locking user accounts, would remain subject to administrator approval.
Major decisions such as official breach notifications would also remain under executive control. Audit records should document the information used by an AI system, its confidence level, and any notes from human supervisors who reviewed its actions.
Building the Cybersecurity Workforce
Microsoft’s recommendations also extend beyond technology.
The company points to partnerships with community colleges, technical apprenticeship programs, and university-operated security facilities as ways to expand the cybersecurity workforce.
It also recommends mutual-aid agreements that allow cybersecurity personnel from government agencies, universities, and volunteer organizations to work together during major incidents.
Microsoft has tested similar cross-agency response structures internationally. These initiatives have included cybersecurity exercises involving government agencies, technical teams, and industry regulators, with the goal of improving coordination and operational handoffs during major incidents.
Balancing AI With Agency Control
The broader approach is built around a balance between shared resources and individual agency control.
Government organizations could share cybersecurity personnel, AI tools, and operational capabilities while maintaining control over their own data environments, access policies, AI memory protections, and final incident-response decisions.
As AI agents become increasingly capable of interacting with sensitive systems, Microsoft’s recommendations highlight a central security challenge: organizations need to give AI enough access to perform useful work without giving it more authority than necessary.
For government agencies handling sensitive information, that means treating AI permissions, memory, identities, and automated actions as core components of cybersecurity rather than as separate AI-specific concerns.


