Ant Group Open-Sources SingGuard-NSFA to Boost Security for Autonomous AI Agents

Ant Group has open-sourced SingGuard-NSFA, a security framework built specifically to protect autonomous AI agents from malicious attacks. The release marks a significant step in making agentic AI — systems that can take real-world actions on their own — safer for business use, according to National Post.
The framework intercepts harmful requests and checks AI responses before any autonomous action is carried out. It covers 185 distinct threat scenarios across 7 categories and includes a benchmark test suite spanning 133 languages and nearly 100,000 test samples, The Province reported.
Traditional AI chatbots wait for a human to review their answers. Autonomous AI agents are different — they browse the web, execute code, send emails, and make decisions without human approval. That independence creates a new class of security risks that standard tools were never built to handle, National Post noted.
Ant Group's AI Security Lab built SingGuard-NSFA to sit between the AI agent and the outside world. It acts as a gatekeeper, blocking suspicious inputs before they reach the agent and validating outputs before any action is taken. Think of it as a security guard posted at every door the AI can open.
The framework comes with a detailed map of dangers facing AI agents. Researchers at Ant Group identified 185 operational threat scenarios and grouped them into 7 categories. These cover attacks like prompt injection — where hackers hide malicious instructions inside text the AI reads — as well as data leakage and unauthorized actions, according to Owen Sound Sun Times.
To test how well the system works, Ant Group built a benchmark suite with nearly 100,000 test samples covering 133 languages. That scale makes it one of the broadest security evaluation tools released for AI agents to date, Northern News reported.
SingGuard-NSFA ships in two versions. The smaller model has 0.8 billion parameters, making it lightweight enough to run on limited hardware. The larger variant has 9 billion parameters and is built for situations that demand higher accuracy. Both versions are described as reaching state-of-the-art performance on security benchmarks, according to The Province.
Offering two sizes is a practical choice. Smaller businesses or edge deployments can use the 0.8B model without heavy computing costs. Larger enterprise setups can run the 9B version where the stakes — and the budgets — are higher.
AI agents are moving fast from research labs into real business workflows. Banks, hospitals, and logistics companies are starting to deploy systems that act autonomously. That shift makes security a pressing concern across the entire industry, not just for Ant Group, County Market noted.
By releasing SingGuard-NSFA as open-source, Ant Group is inviting outside developers and researchers to use, test, and improve the framework. The move could help set a shared standard for how the industry approaches agentic AI security — something that does not yet exist in any agreed-upon form.
Publishers
5
Articles
5
Reach
5