Agentic AI Security All-in-One by Kai London
An agent is not a chatbot. It holds credentials, calls tools, takes actions and keeps going after you stop watching. This handbook treats autonomy as what it is — a privilege decision — and sets out how to grant it, bound it, observe it and revoke it across single-agent and multi-agent systems.
Available on Amazon.
What is inside
The agent threat model
Goal hijacking, indirect prompt injection, memory poisoning and confused-deputy failures, traced end to end.
Tool calling and MCP
Scoping what an agent can invoke, validating what comes back, and the blast radius of a single over-permissive tool.
Identity, secrets and delegation
Short-lived credentials, on-behalf-of flows, and keeping an audit trail that names the human behind the action.
Multi-agent systems
Trust between agents, orchestration boundaries, and containing failures that cascade across a fleet.
Red teaming agents
Adversarial testing of goals, tools, memory and retrieval — with results that drive control changes.
Governance and human control
Approval gates, kill switches, observability and the evidence an auditor will ask for.
Who it is for: security architects and AI engineering leads deploying agents in production, CISOs approving autonomy, and risk and audit teams reviewing agentic systems.
Autonomy is a privilege you grant, bound, observe and revoke — not a capability you switch on.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.