An AI assistant answers questions. An AI agent takes actions: it reads email, queries databases, opens tickets, runs code and calls APIs. That difference changes the security model completely. The question is no longer only what the model might say, but what it might do, and on whose authority.
The OWASP Top 10 for Agentic Applications, published in December 2025, catalogues the main risks: goal hijack, tool misuse, identity and privilege abuse, supply-chain weaknesses, unexpected code execution, memory poisoning, insecure inter-agent communication, cascading failures, human-agent trust exploitation and rogue agents. In practice, most of that risk can be surfaced by answering seven questions.
1. What can the agent actually do?
List every tool, function and integration the agent can invoke, and the permissions behind each one. Agents tend to accumulate capabilities during development. Anything not required for the use case should be removed, and destructive or irreversible actions should be separated from read-only ones.
2. Whose identity does it act with?
An agent that uses a shared service account with broad access can do far more than the user who triggered it. Prefer delegated, scoped and short-lived credentials, and make sure the user's own permissions are enforced at every downstream system.
3. Which content is untrusted?
Anything the agent reads can contain instructions: a web page, a shared document, an email, a calendar invite, a tool response. This is indirect prompt injection, and no filter removes it completely. Design for it: mark untrusted content, limit what an agent can do after reading it, and never let untrusted content alone trigger sensitive actions.
4. Where does a human approve?
Define which actions require explicit human confirmation, such as payments, external communication, data deletion, permission changes and code deployment. Approval screens must show what will actually happen, not the agent's summary of it.
5. Which MCP servers and plugins are trusted, and why?
The Model Context Protocol makes it easy to connect agents to tools. Each MCP server is software with its own permissions, update channel and maintainers. Maintain an approved inventory, review tool descriptions and parameters, pin versions, and run servers with the least privilege possible.
6. What is logged?
Without logs of prompts, retrieved content, tool calls and results, an AI incident cannot be investigated. Decide what is captured, where it is stored, how sensitive data is protected in the logs, and how alerts reach your security operations team.
7. What happens when it goes wrong?
Agree in advance how to disable an agent, revoke its credentials, roll back its actions and preserve evidence. Add AI scenarios to your incident response playbooks and exercise them.
Where to start
Begin with an inventory of agents and integrations already in use, including those adopted by individual teams. Then threat model the two or three with the most authority. That focused effort usually reveals the controls that matter most across all of them.
SecureTech's AI security practice helps organizations answer these questions through threat modeling, AI red teaming and agent permission reviews, alongside identity and zero trust work for the credentials agents use.