The book — launching July 15, 2026
Agentic AI Security.
Threats, Controls, and Governance for Autonomous Systems.
A practitioner’s field guide for the security leaders who decide how much autonomy to grant and the engineers who build the guardrails. Grounded in the standards that matter — OWASP’s Agentic Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001 and the EU AI Act — and in the real incidents that made these risks concrete. Every code listing is runnable; every chapter ends with a checklist you can lift into a design review.
Free with the newsletter — launch news lands there too

What’s inside
Eight parts. Twenty-four chapters.
Foundations and the threat landscape, then the controls that contain each risk: the agent core, tools and MCP, identity and access, detection and response, and the governance that keeps humans in authority over autonomous action. Closing with a full end-to-end reference build.
Part I
Foundations of Agentic AI Security
- 01
From Chatbots to Agents: What Actually Changed
- 02
A Reference Architecture for Agentic Systems
- 03
Why Traditional Security Falls Short
Part II
The Threat Landscape
- 04
Threat Modeling Agentic Systems (MAESTRO & Friends)
- 05
The OWASP Top 10 for Agentic Applications (ASI01–ASI10)
- 06
Attacker's View: MITRE ATLAS and the Agentic Kill Chain
Part III
Securing the Agent Core
- 07
Prompt Injection and Instruction Hijacking
- 08
Securing the Model Layer
- 09
Memory, Context, and Knowledge (RAG) Security
Part IV
Securing Tools, Actions, and Integrations
- 10
Tool Use and Function Calling Security
- 11
Securing the Model Context Protocol (MCP) and Tool Supply Chain
- 12
Code Execution and Sandboxing
Part V
Identity, Access, and Multi-Agent Systems
- 13
Identity and Authentication for Agents
- 14
Authorization, Least Privilege, and Policy Enforcement
- 15
Securing Multi-Agent Systems
Part VI
Detection, Monitoring, and Response
- 16
Observability and Auditing for Agents
- 17
Runtime Guardrails and Defense in Depth
- 18
Red Teaming and Security Testing of Agents
- 19
Incident Response for Agentic Systems
Part VII
Governance, Risk, and Compliance
- 20
Governing Agentic AI: NIST AI RMF and ISO/IEC 42001
- 21
Regulation and Compliance: the EU AI Act and Beyond
- 22
Building a Secure Agent SDLC
Part VIII
Putting It All Together
- 23
Reference Build: Securing a Real Agent End to End
- 24
The Road Ahead

About the author
Tom Mooney is the author of Agentic AI Security. He has spent 15+ years securing complex systems at global scale — across financial services, cloud platforms and government — with a focus on the execution layer of AI security: the permissions, controls and governance that decide what autonomous systems are allowed to do.
His career spans national-security architecture for the UK government, global cloud transformation, and board-level security leadership in financial services. He holds an Executive MBA from the University of Cambridge.
The newsletter
One brief.
Every week.
News, new attacks, and practical guidance for defending AI agents — written for security leaders and the engineers shipping them. Free, and the first three chapters of Agentic AI Security (draft) land in your inbox when you confirm your email.
- First 3 chapters of the book, free
- New threats & incidents
- Defensive patterns & checklists
- Tooling and research worth your time