Stanford sets new security rules for autonomous AI agents #AI


Stanford University has developed a new security framework for AI systems used across research, teaching, healthcare and administration, with a particular focus on a growing challenge for institutions: AI that can do things, not simply generate answers.

The Stanford AI Security Framework (AISF) assesses systems according to factors including data sensitivity, autonomy, access to tools and the potential consequences of an action. It combines AIUC-1 with established approaches including ISO 42001, the NIST AI Risk Management Framework, the EU AI Act and OWASP’s AI Vulnerability Scoring System.

For universities, the problem is becoming more complex as AI capabilities appear inside both new tools and existing software. Some systems may only summarize information. Others can modify records, send communications or take actions through connected systems.

Amy Steagall, Chief Information Security Officer at Stanford University, says the aim is to let people use AI without turning the security process itself into an obstacle:

“The genie is out of the bottle, AI has a critical role to play in our research and education now, and in the future. My goal was to make the easy path the safest path focusing our deepest reviews on the systems that really need it.”

From reading data to taking action

Stanford divides AI systems into low, moderate and high-risk tiers.

A low-risk system is informational, handles no sensitive data, makes no tool calls and can be easily reversed. A moderate-risk system may analyze internal data and use tools within defined workflows.

High-risk systems include those handling sensitive or regulated information while also taking actions that affect systems of record, such as financial, HR or student records. In those cases, an AI error could result in a change that is difficult to reverse.

Bhavya Gupta, Information Security Officer at Stanford University, explains the thinking behind the model: “Data classification told us what an agent could see. AIUC-1 helped us ask what it could do, and that’s where the real risk in agentic systems lives.”

Stanford also assesses where an AI agent operates and who may be affected by it. An internal assistant used by one employee, for example, is treated differently from an agent automating a wider institutional process or interacting with people outside the university.

Where AI agents interact with other agents, the combined system inherits the controls attached to the highest deployment category involved.

How AIUC-1 fits into Stanford’s model

Rather than replacing existing AI governance and security standards, Stanford gives each one a defined role.

ISO 42001 provides the management structure for AI governance, while the NIST AI Risk Management Framework contributes to identifying risk across the lifecycle of a system. The EU AI Act informs regulatory and transparency requirements, and OWASP AIVSS provides guidance for security and vulnerability scoring.

AIUC-1 provides the operational classification used to connect those approaches. Its controls are designed around AI agents that can use tools and act with different levels of autonomy, including risks such as prompt injection, unauthorized actions and unsafe tool calls.

The AIUC-1 standard is updated quarterly and crosswalked with frameworks including NIST AI RMF, ISO 42001 and the EU AI Act. The organization says the standard is shaped by more than 250 CISO and security leaders.

Stanford puts responsibility on the people deploying AI

Under the AISF, responsibility does not sit solely with Stanford’s central security team.

The person or team deploying an AI system is the first line of accountability. For self-service deployments, users complete a checklist that acts as an auditable form of self-certification.

Responsibility is also distributed across roles including the CIO, CISO, data owners, business and service owners, the University Privacy Office and Stanford’s Information Security Office.

Stanford describes the AISF as a framework rather than a university-wide mandate. Individual units retain authority over their own areas while using common principles and risk criteria.

The framework will be reviewed annually and updated as regulation, security threats and AI capabilities change. Stanford is already examining issues including agent-to-agent identity, authorization between agents and third-party systems, and how institutions should control increasingly autonomous AI.

The university has also shared the framework with the Ivy+ CISO network, where it says other institutions are beginning to adopt elements of the approach.

Gupta puts the challenge more simply: “We built this to work at Stanford, but the problem isn’t unique to us. Every institution is trying to say yes to AI without losing sight of what its agents can do.”



Click Here For The Original Source.

——————————————————–

..........

.

.