The book — launching July 15, 2026

Agentic AI Security.

Threats, Controls, and Governance for Autonomous Systems.

A practitioner’s field guide for the security leaders who decide how much autonomy to grant and the engineers who build the guardrails. Grounded in the standards that matter — OWASP’s Agentic Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001 and the EU AI Act — and in the real incidents that made these risks concrete. Every code listing is runnable; every chapter ends with a checklist you can lift into a design review.

See the contents

Free with the newsletter — launch news lands there too

Agentic AI Security book cover

What’s inside

Eight parts. Twenty-four chapters.

Foundations and the threat landscape, then the controls that contain each risk: the agent core, tools and MCP, identity and access, detection and response, and the governance that keeps humans in authority over autonomous action. Closing with a full end-to-end reference build.

Part I

Foundations of Agentic AI Security

  • 01

    From Chatbots to Agents: What Actually Changed

  • 02

    A Reference Architecture for Agentic Systems

  • 03

    Why Traditional Security Falls Short

Part II

The Threat Landscape

  • 04

    Threat Modeling Agentic Systems (MAESTRO & Friends)

  • 05

    The OWASP Top 10 for Agentic Applications (ASI01–ASI10)

  • 06

    Attacker's View: MITRE ATLAS and the Agentic Kill Chain

Part III

Securing the Agent Core

  • 07

    Prompt Injection and Instruction Hijacking

  • 08

    Securing the Model Layer

  • 09

    Memory, Context, and Knowledge (RAG) Security

Part IV

Securing Tools, Actions, and Integrations

  • 10

    Tool Use and Function Calling Security

  • 11

    Securing the Model Context Protocol (MCP) and Tool Supply Chain

  • 12

    Code Execution and Sandboxing

Part V

Identity, Access, and Multi-Agent Systems

  • 13

    Identity and Authentication for Agents

  • 14

    Authorization, Least Privilege, and Policy Enforcement

  • 15

    Securing Multi-Agent Systems

Part VI

Detection, Monitoring, and Response

  • 16

    Observability and Auditing for Agents

  • 17

    Runtime Guardrails and Defense in Depth

  • 18

    Red Teaming and Security Testing of Agents

  • 19

    Incident Response for Agentic Systems

Part VII

Governance, Risk, and Compliance

  • 20

    Governing Agentic AI: NIST AI RMF and ISO/IEC 42001

  • 21

    Regulation and Compliance: the EU AI Act and Beyond

  • 22

    Building a Secure Agent SDLC

Part VIII

Putting It All Together

  • 23

    Reference Build: Securing a Real Agent End to End

  • 24

    The Road Ahead

Tom Mooney

About the author

Tom Mooney is the author of Agentic AI Security. He has spent 15+ years securing complex systems at global scale — across financial services, cloud platforms and government — with a focus on the execution layer of AI security: the permissions, controls and governance that decide what autonomous systems are allowed to do.

His career spans national-security architecture for the UK government, global cloud transformation, and board-level security leadership in financial services. He holds an Executive MBA from the University of Cambridge.

The newsletter

One brief.
Every week.

News, new attacks, and practical guidance for defending AI agents — written for security leaders and the engineers shipping them. Free, and the first three chapters of Agentic AI Security (draft) land in your inbox when you confirm your email.

NO SPAM. UNSUBSCRIBE ANYTIME.

  • First 3 chapters of the book, free
  • New threats & incidents
  • Defensive patterns & checklists
  • Tooling and research worth your time