
Agentic Artificial Intelligence (AI) systems with growing capabilities have emerged as a major threat to global cybersecurity, and cyber diplomacy has not kept pace. For instance, there is hardly any mention of international governance in the Trump administration’s cybersecurity policy. Additionally, the Diplo Foundation and the law and policy journal Just Security note that the word “norms” appears only once, and that use is tied to technology, not diplomacy.
This retreat from the multilateral governance architecture comes at a moment of profound structural change in the cyber threat landscape. It resulted from the emergence of agentic AI as an instrument of attack, a shift in ‘what’ is attacking rather than ‘who’.
What Makes Agentic AI Structurally Different?
The shift from generative to agentic AI marks a critical turning point in the evolution of the technology. Agentic systems can act on their own rather than simply analysing data or recommending actions like earlier AI tools. They perform tasks, access databases, move files, communicate between platforms, and escalate privileges independently with little human intervention. An AI agent compromised by an unauthorised person or adversarial instructions put within the environment can go through identity, cloud and Software-as-a-Service (SaaS) systems undetected. It can evade security measures and modify its actions at any point in time with no human intervention. This differs from conventional malware, which relies on a human operator to carry out the attack.
The CrowdStrike 2026 Global Threat Report, which compiles information on over 280 named threat actors, reported a surge in such attacks. The 2025 average eCrime breakout time (BOT) fell to 29 minutes, a 65 percent faster attack rate than the previous year. The fastest ever breakout occurred in 27 seconds. During another documented intrusion, data exfiltration commenced four minutes after access. This timeline leaves no room for any defensive human intervention.
Michael Sentonas, President of CrowdStrike, stated during a recent presentation, “Prompts are going to be the new malware”. The above report also highlighted that adversaries are exploiting generative AI (GenAI) systems to send malicious prompts to over 90 organisations to steal credentials and cryptocurrency in what became a classic example of “defensively deployed” systems being used to launch attacks. Teams from Google, Zscaler, and Unit 42 have independently recorded an associated form of indirect prompt injection wherein malicious prompts are not written directly into the AI model, but are hidden in publicly available web content made available to anybody, including any AI agents reading or harvesting that content at a later stage, so that the AI will be manipulated into divulging information or making payment on the attacker’s behalf.
According to Flashpoint’s 2026 Global Threat Intelligence Report, more than 11.1 million machines were compromised with infostealers in 2025, with an inventory of 3.3 billion compromised credentials and cloud tokens. Modern-day attacks circumvent security perimeters by using compromised credentials, sessions, and tokens to get legitimate access. With an increase in ransomware attacks by 53 percent in 2025, the attack surface has extended to browsers, personal devices, SaaS platforms, and external access.
A Governance Architecture Built for a Different Era
The existing norms for responsible state conduct in cyberspace are the product of nearly 20 years of patient multilateral effort. The United Nations Group of Governmental Experts on Information Security (UN GGE) process − operational since 2004 − formulated 11 voluntary, non-binding norms of responsible state behaviour in its 2015 report. It later expanded its membership to all UN member states. The last Open-ended Working Group (OEWG) report (July 2025) called for further norms, but did not include any immediate recommendations. These discussions are now ongoing in the newly established UN Global Mechanism on Cybersecurity, in March 2026 of which the first organisational session took place.
This architectural construct and its norms were developed over time, adopted through consensus, and implemented gradually to function in an environment where operations happen at the pace of humans — with attribution to a known actor-state, and where operations could be traced back with enough certainty for a diplomatic response.
Attributing attacks becomes challenging when they blend into regular traffic. With 82 percent of all detected intrusions being malware-free, forensic evidence is non-existent, as current frameworks depend greatly on the detection of malware artefacts. When attackers operate through stolen credentials and legal tools, they leave no evidence behind.
The Distinctive Opportunity before India
As an entity located between the Global South and the Quad, India is best situated to fill the present governance void. Over 300,000 people participated in the five-day India AI Impact Summit, and at least 92 countries and international organisations endorsed the New Delhi Declaration.
What is missing is a clear doctrinal stance on how current international law should govern AI’s agentic capabilities, i.e., autonomous, persistent, and trans-border.
However, India’s contributions to international debates on agentic AI and cyber norm-building remain underdeveloped. The country has taken an important step toward the next generation of cyber diplomacy: its 2022 proposal for a Global ICT Security Cooperation and Capacity Building Portal was operationalised, with full Indian funding, at the Global Mechanism’s inaugural substantive plenary session. The India AI Impact Summit’s working groups are already in place as an institutional mechanism for safe and trusted AI. What is missing is a clear doctrinal stance on how current international law should govern AI’s agentic capabilities, i.e., autonomous, persistent, and trans-border.
Having proven itself a credible convener of the Global South, India has an excellent opportunity to build a third option, independent of American offensive primacy and the Chinese idea of national sovereignty as a shield against international norms. Translating this advantage into a doctrinal contribution will require India to put forward a substantive proposal within the UN Global Mechanism.
What Does a Fit-for-purpose Framework Require?
The reconstruction of the normative architecture for the agentic era need not start from scratch. It requires adaptation to a world it was never built for: lightning-fast attacks, untraceable perpetrators, and AI that can serve as both attacker and attacked. Three specific adaptations are needed, and each maps onto an existing forum.
First, the existing 11 GGE norms need authoritative guidance on how they apply to AI-powered operations, not a fresh decade-long negotiation of new norms. The UN Global Mechanism is the appropriate forum to initiate this.
Second, existing confidence-building measures must be adapted to machine-speed operations. The framework loses its relevance once attribution and response are measured in days or weeks. A near-real-time protocol for technical exchange between governments and even adversaries is necessary.
Third, the use of “agentic AI” technology in offensive cyberattacks must be addressed explicitly. Any governance framework must rest on a normative definition of the autonomous malicious entity, the one capable of iterating, adapting, and scaling its attacks without human intervention.
There already exists a foundation. ISO/IEC 42001, the first global management system standard for artificial intelligence, sets auditable requirements for organisations on governing AI systems throughout their lifecycle. ISO/IEC 23894 supplements it with guidance on AI-specific risk management. Both standards are practically applicable to agentic deployments and could underpin UN Global Mechanism guidelines.
What remains uncertain is whether the coalition built around the New Delhi Declaration can convert its convening power into a legally binding commitment before the next wave of agentic attacks unfolds.
On the technical side, the National Institute of Standards and Technology’s (NIST) Generative AI Profile and the new AI Agent Standards Initiative establish requirements for the identity, authorisation, and permissions of autonomous agents. OWASP’s Top 10 for Agentic Applications goes further still, identifying specific failure modes such as excessive agency and unregulated permissions that any coding standard would need to monitor. The task at hand, then, is not to draft new codes of conduct but to persuade states to treat this regulation as obligatory rather than voluntary for any government or supplier deploying agentic AI capable of doing harm.
The 92 signatories of the New Delhi Declaration are more than a diplomatic accomplishment; they form a pre-existing coalition of norm entrepreneurs for the age of agentic AI. The UN Global Mechanism remains an initiative, not yet a deliverable, and the governance timeline is lagging behind a threat that operates at machine speed. India, the European Union, and their partners in the Global South have both the capability and the motivation to act. What remains uncertain is whether the coalition built around the New Delhi Declaration can convert its convening power into a legally binding commitment before the next wave of agentic attacks unfolds.
Er. Kritika is an independent researcher specialising in neuro-cybersecurity, AI governance, and cyber diplomacy.
The views expressed above belong to the author(s). ORF research and analyses now available on Telegram! Click here to access our curated content — blogs, longforms and interviews.