Resources

AI Agent Security Guides, Insights & Examples

Use these guides and examples to prepare requirements, tests and review evidence.

The knowledge collectionEvidence you can inspect.

Explore the collection

Ideas for the
work ahead.

Find a practical perspective on the controls, questions and evidence that matter to your deployment.

11 resources

Guides

OWASP Agentic Top 10 Security Review Guide

Turn OWASP agentic risk categories into scoped control questions and review evidence. Use the taxonomy as a starting point, not a certification or full test suite.

Read the perspective
Guides

AI Agent Security Review Readiness Checklist

Prepare system ownership, agent inventories, control tests and evidence before a buyer or internal security review. Record gaps, owners and acceptance tests.

Read the perspective
Insights

AI Agent Guardrails at the Action Boundary

Understand why model intent is not authorisation. Enforce tool permissions, resource limits and approval conditions at the AI agent's execution boundary.

Read the perspective
Insights

EU AI Act Article 15: Technical Evidence Planning

Establish AI Act applicability before selecting Article 15 technical evidence. Link cybersecurity controls, test scope and results to the system under review.

Read the perspective
Insights

Human Approvals for AI Agents Without Fatigue

Design useful human approval requests for AI agents with action, target and consequence context. Test changes, expiry and exceptions before rollout.

Read the perspective
Insights

MCP Tool Pinning, Changes & the Rug-Pull Risk

Review MCP tool owners, versions and permissions when behaviour changes. Understand the limits of pinning and rerun relevant access and action tests.

Read the perspective
Insights

Third-Party AI Agent Risk: Review the Deployment

Review supplier AI agents against the actions and access enabled in your deployment. General supplier security evidence may not cover those permissions.

Read the perspective
Insights

AI Guardrail Benchmarks: Read the Test Design

Interpret AI guardrail results using test design, scenario coverage and observed outcomes. Avoid treating one headline score as a readiness prediction.

Read the perspective
Threat briefs

AI-Assisted Cyber Operations: Control Scenario

Explore how AI-assisted reconnaissance and tool use can connect attack attempts. Use this generalised scenario to review permissions and monitoring boundaries.

Read the perspective
Threat briefs

MCP Tool Poisoning: Threat Scenario & Controls

Understand how malicious MCP tool descriptions or output can influence an agent. Review tool trust, change detection and execution boundary controls.

Read the perspective
Threat briefs

Prompt Injection & Private Data Leakage Risks

Review how untrusted content can redirect agent retrieval and exports. Test data boundaries, permitted destinations and action controls with synthetic data.

Read the perspective

Turn security challenges into a clear plan

Tell us what you need to protect, improve or achieve. We will help you identify the control gaps, prioritise the work and define practical steps towards your goal.