Agentic security, decoded

AI agents stopped talking and started acting.

Autonomous agents now read your data, call your tools, and take real actions on your behalf — a new attack surface most security programs haven’t caught up with. This is where you learn to secure them.

NO SPAM. UNSUBSCRIBE ANYTIME.

Tom Mooney

Curated by Tom Mooney — author of Agentic AI Security

01 / The threat model

Why agents change the security game.

01

An agent acts — it doesn’t just answer.

A manipulated chatbot writes a bad sentence. A manipulated agent executes a bad action — at machine speed, with real credentials. Autonomy is blast radius.

02

It’s a new attack surface.

Agents can be hijacked by instructions hidden in the data they read — an email, a doc, a ticket. No breach, no alert, no CVE.

03

Your existing stack wasn’t built for it.

Firewalls inspect traffic, IAM governs access, pentests check code. None of them ask what an autonomous actor will do under adversarial pressure.

02 / The evidence

We ran the attacks so you don’t find out in production.

We tested the 20 most-used models on OpenRouter against prompt injection. 12 of 20 were breached undefended — and a few sentences of defensive system prompt cut attack success to zero.

12/20

Models breached

37%

Attack success, undefended

0%

With a hardened prompt

Attack success by model — undefended (up to 15 attacks each)

Model A
100%
Model B
93%
Model C
73%
Model D
73%
Model E
67%
Model F
64%
Model G
60%
Model H
60%
Model I
47%
Model J
33%
Model K
33%
Model L
27%
Model M
0%
Model N
0%
Model O
0%
Model P
0%
Model Q
0%
Model R
0%
Model S
0%

7 models withstood this battery — a floor, not immunity; no model is safe from prompt injection. What reliably changed the outcome was the defence: a hardened system prompt cut success to 0/278, a deterministic context-firewall to 1/279.

Agentic AI Security book cover

03 / The book — launching July 15, 2026

The playbook, in print.

Agentic AI Security — threats, controls, and governance for autonomous systems. Written for both security leaders and the engineers shipping agents.

OWASP Agentic Top 10 · MITRE ATLAS · NIST AI RMF · ISO 42001 · EU AI Act

Free with the newsletter — launch news lands there too

Tom Mooney

04 / The author

Fifteen years at the sharp end of cloud, data & AI security.

Tom Mooney leads cloud, data and AI security for a global financial services group, after national-security architecture for the UK government and global cloud transformation at a leading technology firm. Executive MBA, University of Cambridge.

This site and Agentic AI Security are where that experience meets the new problem: controlling what autonomous systems are allowed to do.

The newsletter

One brief.
Every week.

News, new attacks, and practical guidance for defending AI agents — written for security leaders and the engineers shipping them. Free, and the first three chapters of Agentic AI Security (draft) land in your inbox when you confirm your email.

NO SPAM. UNSUBSCRIBE ANYTIME.

  • First 3 chapters of the book, free
  • New threats & incidents
  • Defensive patterns & checklists
  • Tooling and research worth your time