The new attack surface

Agentic AI security, before it becomes your incident

AI agents are already inside your business, reading mail, moving files, raising tickets, writing code, under permissions somebody granted in an afternoon. Agentic AI security is the discipline of finding those agents, constraining what they can do and proving it, before one of them is turned against you.

The definition

What agentic AI security means

Agentic AI security is the practice of assessing, constraining and monitoring AI agents: systems that do not just answer questions but take actions, sending mail, changing files, calling tools and spending money under delegated permissions. It covers what each agent can do, what it should do, and how you would know the difference.

This is why agents deserve their own discipline. A chatbot that fails gives a bad answer; an agent that fails does something, with real credentials, on real systems, at machine speed. The blast radius of a manipulated agent is the blast radius of its permissions, and most agents hold far more permission than their task requires.

The risk surface

Where agent deployments go wrong

Five failure patterns recur across agent deployments, and none of them requires the underlying model to be broken.

Over-permissioning

Agents get granted broad scopes because narrow ones are fiddly: full mailbox access to send one class of email, write access everywhere to update one folder. Every excess permission is standing attack surface.

Prompt-injected actions

An agent that reads external content can be steered by it. A crafted email or document does not just skew an answer, it can trigger the agent's tools: forwarding data, changing records, initiating payments.

Tool misuse

Legitimate tools chained into illegitimate outcomes: a search tool plus a send tool becomes exfiltration; a code tool becomes execution. Individual tool reviews miss what combinations can do.

Cascading autonomy

Agents that call other agents or schedule their own work compound errors at machine speed. A wrong decision upstream becomes a hundred confident actions downstream before anyone looks.

Audit gaps

Many agent platforms log the conversation but not the actions, or the actions but not the reasoning. When something goes wrong, you need to reconstruct what the agent did and why, and often you cannot.

Assessing agents

How an agent deployment gets assessed

Four stages, each producing evidence you keep. Constraint testing draws on the same techniques as the AI penetration test, pointed at what the agent is allowed to do rather than what it says.

1

Inventory

What agents exist, including the unofficial ones: platform assistants, workflow bots, browser agents staff have granted access to. Most estates are larger than the owner's list.

2

Permission review

Each agent's effective permissions mapped against what its task genuinely needs, across identities, API scopes, delegated access and the service accounts underneath.

3

Constraint testing

The guardrails attacked directly: can injected content trigger tools, can instructions be overridden, do rate and value limits hold, does the agent stop where its designers intended?

4

Monitoring review

Whether the logging that exists would actually answer an investigator's questions: what the agent did, on whose authority, triggered by what input, and who was alerted.

Governing agents

Governance that keeps assessed agents safe

An assessment is a snapshot; governance keeps it true as agents multiply. Three controls carry most of the weight, and where behavioural assurance is needed on top, AI red teaming exercises agents against realistic misuse scenarios.

Policy before permissions

Which tasks may be delegated to agents at all, what data classes they may touch and which actions always stay human. These rules belong in your AI governance policy, agreed before the next agent ships rather than after.

Human-in-the-loop thresholds

Defined lines above which an agent proposes and a person approves: payment values, external communications, destructive changes, anything customer-visible. The threshold is a governance decision, not a developer default.

Logging that survives scrutiny

Action-level records tied to inputs and identity, retained long enough to investigate, and reviewed on a schedule. If an agent's actions cannot be reconstructed afterwards, its autonomy was never really governed.

The service

The fixed-price agent security assessment

All four assessment stages, run against one agent deployment, priced from £13,500 and fixed once scope is agreed. You receive the permission map, the constraint testing evidence, a prioritised remediation plan and the governance recommendations, written so both the engineering owner and the risk owner can act on them.

Multiple agents assess in the same engagement at a published per-deployment rate, detailed alongside the testing bands on the pricing page. Where the assessment exposes gaps in the rules themselves, the AI governance policy service closes them.

Quick answers

Agent security questions, answered

How do you secure AI agents?

Four disciplines: know what agents you run, cut their permissions to what the task needs, test their constraints adversarially before attackers do, and log their actions well enough to reconstruct any incident. Then govern the rest: written policy on what may be delegated, and human approval above defined thresholds.

Do agents need their own policy?

They need their own section, not a separate document. An agent acts on the organisation's behalf, so your AI governance policy should state which tasks can be delegated, what data agents may touch, which actions require human approval and who owns each deployment. Most AI policies were written for chatbots and say none of this.

The AI governance policy

What permissions should an AI agent have?

The least that lets it complete its task, granted to its own identity rather than a shared or human account, scoped to the specific resources involved and time-limited where the platform allows. If listing what an agent can reach takes effort, that is the finding: effective permissions should be knowable at a glance.

Rocket launching above the AI Governance UK call to action

Count your agents first

Scope an agent security assessment

A free scoping call inventories what agents you run, confirms the per-deployment price and books the assessment. Most organisations discover the inventory alone was worth the call.