AI Agent Security Guides
Practical guides on AI agent security, agent discovery, access posture, least-privilege enforcement, and compliance for teams deploying autonomous agents.
Deep dives into AI agent security, MCP, authorization patterns, and the tools that power modern agentic systems.
Latest posts
- Agentic AI Security: The Complete Guide for 2026
The definitive guide to agentic AI security. Covers runtime authorization, credential management, tool-use governance, data-flow controls, attack paths, and the full security stack for autonomous AI agents.
- MCP Security: Risks, Best Practices, and Runtime Controls
Complete guide to MCP security. Covers the Model Context Protocol threat model, tool abuse, credential exposure, transport security, supply chain risk, and best practices for securing MCP servers in production.
- AI Agent Security: A CISO's Practical Guide for 2026
A practical AI agent security guide for CISOs and security leaders. Covers agent discovery, runtime authorization, credential management, compliance, MCP security, incident response, and vendor evaluation for 2026.
- What Are Guardian Agents? A Practical Guide for Security Teams
Learn what guardian agents are, how Gartner defines the 2026 market, what they should discover and enforce, and where they fit in AI agent security stacks.
- How to Fix the TanStack Supply Chain Attack
Learn how to fix the TanStack supply chain attack with clean version pins, credential rotation, package release cooldowns, split publish workflows, and runtime authorization.
- How Do I Enforce Least Privilege for AI Agents Using External Tools?
Learn how to enforce least privilege for AI agents using external tools with runtime authorization, scoped credentials, MCP gateways, Kontext, and audit trails.
- AI Agent Compliance for Security Teams: Identity, Authorization & Audit Trails in 2026
AI agents take autonomous actions — but can you prove which policy allowed each one? The 2026 playbook for agent identity, runtime authorization, and audit trails.
- Secure AI Tools for 2026: Compliance and Risk Management
Discover the best secure AI tools for 2026, focusing on government compliance, risk management, and cybersecurity solutions to protect sensitive data.
- Authentication vs Authorization: What's the Difference?
Authentication verifies identity. Authorization decides what that identity can do. For AI agents, both controls must happen at runtime, not only at login.
- Top 10 AI Attack Path Defenses for 2026
A practical 2026 guide to defending AI agent attack paths with runtime authorization, scoped credentials, prompt-injection isolation, tool controls, audit logs, and automated response.
- AI Agent Tool Permissions: What Is a Tool Invocation Privilege Boundary?
A tool invocation privilege boundary controls which tools an AI agent can call, which actions it can take, and which scoped credentials it can receive at runtime.
- What Is Excessive Agency Vulnerability
Excessive agency vulnerability is the risk that an AI agent has more tools, permissions, or autonomy than its current task requires, creating avoidable blast radius.
- The 10 Best AI Cybersecurity Tools In 2026
A ranked 2026 guide to AI cybersecurity tools across runtime authorization, identity protection, model security, XDR, and cloud security.
- Securing LLM Tool Use With Runtime Policies
How runtime policies secure LLM tool use by checking agent identity, intent, tool, resource, parameters, and risk before each action executes.
- NIST AI RMF for AI Agents
How to apply NIST AI RMF to AI agents using Govern, Map, Measure, and Manage with practical evidence and controls.
- How to Implement AI Agent Runtime Authorization
A six-phase implementation guide for AI agent runtime authorization: inventory the action surface, observe before enforcing, write the first ten policies, close bypass paths, enforce with fail-closed writes, and verify with denial tests.
- AI Agent Runtime Authorization and Access Control
How runtime authorization decides each AI agent action at execution time: the decision inputs, the enforcement point, worked policy and code examples, and where OAuth and RBAC stop being enough.
- Credential Brokering for AI Agents: A Security Pattern
Credential brokering is a security pattern that limits standing authority by issuing scoped, short-lived access after policy approval. Learn its benefits, limits, and role alongside runtime controls.
- Stop losing your research in chat logs 🧠
I got tired of doing unpaid archaeology on my own work every week, so I built a local-first wiki that actually remembers. Here's oamc.
- Our Response to the NIST Call for Comment on Agent Identity and Authorization
We submitted comments to NIST NCCoE urging runtime, intent-aware authorization for agentic systems. This post publishes the response in full.