They should quarantine it when its behaviour is unclear, its access is broader than intended, or it has touched sensitive systems without a clear rationale. Waiting for a later review may leave no meaningful artefact to assess. Immediate containment should also remove downstream access so investigation is still possible.
When quarantine is the safer move for an AI agent
Quarantine is the right call when an agent’s behaviour cannot be explained confidently, when it has more access than the task justifies, or when it has already touched sensitive systems in a way that may blur the evidence trail. In those cases, a delayed review can be less useful than immediate containment because the first priority is preserving what the agent did and preventing further reach.
That judgment is especially important for autonomous workflows, because a tool-using agent can continue acting, compounding impact, or overwriting the very artefacts a reviewer would need later. The practical question is not whether the agent might eventually be explainable, but whether it is still safe to let it keep operating while you figure that out.
Quarantine also makes sense when downstream access has to be cut before analysis can start. If the agent can still call tools, read data, or trigger side effects, investigation and harm reduction compete with each other. Immediate containment creates a bounded state: preserve the evidence, freeze the action path, and stop any further changes that would expand blast radius.
What quarantine should actually do
Effective quarantine is more than “pause the agent.” It should suspend active execution, revoke or narrow tokens and other access paths, and isolate any state that could continue to be written to or exfiltrated. A good quarantine state still lets responders inspect logs, traces, prompts, approvals, and recent tool calls without giving the agent fresh authority.
That means teams need a clear distinction between containment and deletion. If you delete the agent, reset its context too aggressively, or rotate everything before collecting evidence, you may destroy the clues that explain whether the agent was simply misconfigured or was actively misusing its access. Quarantine is meant to preserve both safety and investigability.
For agents that act on behalf of people or systems, the safest form of quarantine is usually to cut the delegation chain first. Once the agent no longer has standing authority, the investigation can focus on what it touched, what it was allowed to do, and whether any other identities or systems were implicated through its actions.
How to decide between review and immediate containment
Use review when the behaviour is odd but still well bounded, the access is narrowly scoped, and you can validate the action path without exposing production systems to more change. Use quarantine when any of those assumptions fail, especially if the agent can affect data, permissions, money, deployments, or external communications.
A useful rule is this: if the next step could expand impact faster than it improves understanding, quarantine first. If the next step can safely improve understanding without adding reach, review can come first. That decision depends on blast radius, not on whether the behaviour feels merely “suspicious.”
Teams should also treat unexplained access to sensitive systems as a strong quarantine trigger. If an agent touched a privileged system without a clear business justification, the issue is not just one of policy compliance, it is also an evidence preservation problem. The longer you wait, the harder it becomes to tell whether the access was authorized, accidental, or malicious.
Risk and Threat Considerations
When an agent is left running after uncertain or excessive behaviour, the main risk is compounding exposure. The agent may keep invoking tools, modifying data, propagating bad state, or exposing additional secrets before anyone can reconstruct what happened.
Failure mechanism: The agent retains authority longer than intended, so the investigation starts after the evidence has already been altered, consumed, or overwritten.
Impact: Response quality drops, blast radius grows, and teams may lose the ability to distinguish misconfiguration from abuse or compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Agent quarantine decisions hinge on preventing excess authority from persisting. |
| ASI08 — Cascading Failures | Unchecked agent execution can compound impact and amplify downstream failures. | |
| ASI10 — Rogue Agents | Quarantine is a response when an agent’s behaviour is no longer trusted or explainable. | |
| Recommendation — Enforce per-action authorization and remove standing privilege when an agent behaves unexpectedly. Contain the agent quickly when continued actions could cascade into broader system harm. Isolate and disable agents that act outside expected authority or intent. | ||
| NIST SP 800-53 Rev 5 | IR-4 — Incident Handling | Quarantine is an incident-handling action used to limit damage and preserve evidence. |
| AU-11 — Audit Record Retention | The answer stresses preserving logs and traces before evidence is lost. | |
| AC-6 — Least Privilege | The page centres on access that is broader than the task justifies. | |
| Recommendation — Contain the affected agent and preserve evidence before further remediation. Retain the agent’s relevant records before rotating or resetting access. Reduce agent permissions to the minimum needed for the task. | ||
| NIST Zero Trust (SP 800-207) | AC-6 — Least Privilege Access | Quarantine reflects zero-trust containment by narrowing trust and access immediately. |
| UA-5 — Continuous Diagnostics and Mitigation | The decision depends on rapid containment and ongoing verification of agent state. | |
| Recommendation — Treat uncertain agent behaviour as a trigger to re-evaluate and shrink access. Continuously verify agent state and contain it when trust conditions change. | ||
Practitioner Guidance
What to prioritise: Quarantine first when the agent has any path to sensitive systems, production data, or irreversible actions. Your first objective is to stop additional side effects, not to finish root-cause analysis while the agent is still active.
What to verify: Confirm that containment actually removed live authority, not just user interface access. If tokens, service credentials, scheduled jobs, or delegated permissions still work, the agent is not meaningfully quarantined.
Decision rule: If you need the agent’s logs, traces, or recent tool calls to understand the incident, preserve them before taking broad destructive action. If you need the agent to stop acting before anything else, revoke access first and investigate from the frozen state.
Practitioner takeaway: Quarantine is the right default whenever continued execution could deepen harm or erase evidence, because a safe investigation depends on stopping the agent without destroying the trail it left behind.