AI All-in-One series · Autonomous systems

Agentic AI Security All-in-One by Kai London

An agent is not a chatbot. It holds credentials, calls tools, takes actions and keeps going after you stop watching. This handbook treats autonomy as what it is — a privilege decision — and sets out how to grant it, bound it, observe it and revoke it across single-agent and multi-agent systems.

Available on Amazon.

What is inside

The agent threat model

Goal hijacking, indirect prompt injection, memory poisoning and confused-deputy failures, traced end to end.

Tool calling and MCP

Scoping what an agent can invoke, validating what comes back, and the blast radius of a single over-permissive tool.

Identity, secrets and delegation

Short-lived credentials, on-behalf-of flows, and keeping an audit trail that names the human behind the action.

Multi-agent systems

Trust between agents, orchestration boundaries, and containing failures that cascade across a fleet.

Red teaming agents

Adversarial testing of goals, tools, memory and retrieval — with results that drive control changes.

Governance and human control

Approval gates, kill switches, observability and the evidence an auditor will ask for.

Who it is for: security architects and AI engineering leads deploying agents in production, CISOs approving autonomy, and risk and audit teams reviewing agentic systems.

NIST AI RMFISO/IEC 42001EU AI ActOWASP Top 10 for LLMsZero Trust

Autonomy is a privilege you grant, bound, observe and revoke — not a capability you switch on.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.