bg
Cybersecurity
08:49, 28 August 2026
views
4

Sberbank Experts Outline Security Rules for Self-Evolving AI Agents

The recommendations include several key measures designed to prevent harmful behavior.

The use of artificial intelligence in the enterprise sector continues to grow. On the one hand, AI can make many processes faster and less expensive. Yet the advance of intelligent technologies is creating new challenges for information security professionals.

What Makes Self-Evolving Agents Dangerous?

At the OFFZONE 2026 conference, Sberbank experts presented their own research on AI use and cybersecurity. They noted that self-evolving AI agents are becoming increasingly popular. As a result, security matters not only when using basic language models but also when deploying agentic systems. Government agencies and private organizations that fail to give the issue adequate attention risk facing cybersecurity problems in the near future. The experts based their conclusions on an updated version of Sberbank’s AI cybersecurity threat model, which systematizes 37 threats and 51 ways they can be carried out, including risks associated with GenAI, AI agents and multi-agent systems.

The experts noted that today’s self-evolving AI agents can independently update their memory, skills and code, using their own tools to accomplish assigned goals. Humans need to continuously oversee these processes, distinguishing potentially useful changes from harmful ones. To achieve this, Sberbank recommends following several rules.

Strict Isolation Is Essential

First, agents need to be strictly isolated. This means implementing local memory services, dedicated and delegated access tokens, and separate execution environments for each agent and its user.

Second, development and production environments need to be separated. Self-evolution should be completely disabled in the production environment because it may provide access to sensitive data. Self-evolution can be allowed in the development environment, but the agent should have read-only access to information and no ability to access the network independently. Moving a solution into production should require standard cybersecurity checks.

Independent Security Systems

Independent security systems are also necessary. Protective mechanisms should sit outside the boundary of the agent’s executable code. A centralized system collects and processes telemetry and metrics, while guardrails block anomalies in real time. Sberbank also recommends creating an enterprise skills registry with mandatory tool verification and running generated code in a sandbox with restrictions on execution time, network access, CPU, memory and the file system.

Seeking New Tools

These recommendations draw on Sberbank’s extensive experience using agentic AI systems. Such systems are actively used in software development, while the Kiberanalitik (Cyber Analyst) multi-agent system independently resolves up to 70% of the bank’s cybersecurity incidents.

Back in April 2025, Sberbank developed Russia’s first comprehensive threat model for AI systems. At the time, the document covered 70 different risks across various stages of the lifecycle – from data preparation and training to model deployment and operation.

At the end of 2025, Russia’s Federal Service for Technical and Export Control (FSTEC) added artificial intelligence-related risks to its information security threat database for the first time. The listed targets and scenarios included machine-learning models, datasets, RAG, model adapters, modifications to system prompts and agent configurations. AI security thus began moving beyond corporate research and into the realm of government information security regulation.

Russia may soon see the emergence of a distinct market segment focused on securing agentic AI systems. An entire suite of specialized tools could be developed for this purpose. Even then, ultimate oversight should remain with humans.

The integration of artificial intelligence technologies into business processes brings major cybersecurity challenges. Organizations using AI face new risks that can affect system resilience and data confidentiality. These threats span every stage of the AI lifecycle, requiring new solutions to anticipate and neutralize them
quote
like
heart
fun
wow
sad
angry
Latest news
Important
Recommended
previous
next