
As public agencies roll out AI assistants and autonomous agents, Microsoft has a message: the model is only one piece of the security puzzle. In its 2026 Digital Defense Report, the company sets out advice for governments centred on strict data controls, testing of whole systems rather than single models, and shared security operations that still keep each agency’s information separate.
Security depends on everything around the model

Terrell Cox, a Microsoft deputy CISO, put it plainly: a model’s safety also depends on the data it can reach, the tools it can use, the permissions involved and the services around it. So Microsoft recommends evaluating AI inside the real environment where it will run, looking at how models, tools, data and users interact, and continuing to monitor after launch.
Give every agent an identity and a short leash
The report treats agents like staff who need accounts. Each one should have an auditable identity that records who built it, what it does and which named human is responsible. Their access should be narrow and temporary: credentials should expire on a schedule, cover only the job at hand and be reviewed whenever the agent’s role changes. Microsoft goes as far as suggesting credentials valid for a single tool call, authentication between agents, and tracking how fast access can be pulled after a compromise.

Sensitive information also lives in less obvious places. Prompts, query logs, agent memory and generated text can all contain confidential records, so access rules should follow data classification everywhere, including tools staff use without approval.
Memory is a new attack surface
Microsoft’s red team found that instructions hidden in outside content, often email, can end up stored in an agent’s memory and later treated as trusted. The recommended fix is to separate write paths so material from outside cannot change the store that holds verified system rules. The team also saw agents mistake saved user habits for commands and use conflicting memory entries to talk their way past confirmation pop-ups. Rather than depend on someone clicking “approve”, Microsoft advises hard policy gates that stop an action until a reviewer has seen the command together with its raw context.
Shared security centres, separate data
For operations, Microsoft proposes multi-tenant security operations centres where one team of analysts and automated agents watches several public bodies. Each agency would keep its own cloud tenant, data location rules and zero-trust boundary. Central staff would use short-lived, minimum-privilege accounts, and logs would remain in each agency’s own systems. Pooling, Microsoft argues, cuts duplicate licences and gives small agencies access to specialists, though the report offers no data confirming real savings in government.
Automation would handle routine work such as gathering alert context and summarising threats, which Microsoft says it does for 75 percent of its own internal security incidents without a human dispatch. Anything that could disrupt live services, such as locking accounts, would wait for administrator approval, and official breach notices stay entirely in human hands.
Training people and rehearsing crises
The report also looks at the skills gap. It points to partnerships with community colleges, apprenticeships and university-run operations centres, plus mutual-aid agreements pooling staff from local governments, national cyber agencies and volunteer responders. Microsoft says it has piloted similar arrangements with Kenya’s national cybercrime coordination body and has run incident-response drills with Mexican agencies before the FIFA World Cup.
Source: reporting by AI News (artificialintelligence-news.com), 2 October 2026, based on Microsoft’s 2026 Digital Defense Report.
