Tech Kaizen

passion + usefulness = success .. change is the only constant in life

Search this Blog:

Agentic AI Security

Agentic AI Security isn’t just an extension of LLM safety - it’s a fundamentally different and far more dangerous domain. While a plain LLM might hallucinate a wrong answer or leak a prompt, an agentic system can autonomously act on that compromise: send emails, execute code, transfer funds, delete files, or chain tools across your entire tech stack. This “agency” turns theoretical risks into immediate, high-impact breaches.

Why Agentic AI Security is important:
Agency = Real-World Impact LLMs output text. Agents execute actions via tools (APIs, databases, email, code execution). A single successful attack can cause financial loss, regulatory violations, or operational shutdowns - autonomously and at scale.

  1. Massively Expanded Attack Surface
    • Tools & APIs: Agents call external services dynamically.
    • Memory & State: Persistent long-term memory can be poisoned and spread across sessions or multi-agent teams.
    • Multi-Agent Communication: Agents talk to each other (via protocols like MCP or A2A), creating cascading failure risks.
    • Supply Chain: Open-source frameworks (LangChain, CrewAI, AutoGen) and third-party tools are everywhere. Traditional app security (firewalls, IAM) wasn’t built for non-deterministic, goal-driven systems that replan on the fly.

The OWASP(Open Web Application Security Project) Top 10 for Agentic Applications 2026 is a globally peer-reviewed framework that identifies the most critical security risks facing autonomous and agentic AI systems.


1. Top 5 Agentic Security Risks (OWASP 2026):

Risk IDNameThe Threat
ASI-01Agent Goal HijackAn attacker manipulates an agent's multi-step plan (via direct or indirect injection) to pursue a malicious objective, like exfiltrating data instead of summarizing it.
ASI-02Tool MisuseAgents using legitimate tools in unsafe sequences (e.g., a "delete" tool following an unverified "list files" command) or triggering infinite recursive loops that exhaust resources.
ASI-03Identity AbuseExploiting the lack of unique identities for agents. Attackers compromise a single "service account" used by 50 different agents to gain broad lateral access.
ASI-04Supply ChainRisks from third-party "Skills," "Plugins," or open-source MCP (Model Context Protocol) servers that may contain hidden backdoors or malicious code.
ASI-05Memory PoisoningInjecting false information into an agent’s long-term memory or vector store, causing it to make biased or harmful decisions in future sessions.

2. The "Lethal Trifecta":

Security researchers in 2026 frequently cite the Lethal Trifecta, which occurs when an agent has three specific capabilities simultaneously.

  1. Access to Private Data (e.g., CRM, internal docs).

  2. External Communication (e.g., can send emails or hit webhooks).

  3. Processing Untrusted Content (e.g., reading a customer email or a public website).

Note: If an agent has all three, it must be isolated in a strict Sandbox with human-in-the-loop (HITL) gates for any outbound action.


3. Defense-in-Depth for Agents:

To secure agentic workflows, the 2026 architecture focuses on three pillars:

1. Agentic Identity & RBAC:

Treat every agent as a
first-class security principal.

  • Unique IDs: Do not share API keys between agents.

  • Least Privilege: An agent designed to "Read Calendar" should not have "Write" permissions.

  • Short-lived Tokens: Use session-scoped credentials that expire immediately after the task is complete.

2. The Agent Gateway (Policy Enforcement):

Instead of letting the LLM call tools directly, route all tool calls through an Agent Gateway.

  • Validation: The gateway checks the tool call against a hardcoded policy (e.g., "Refunds > $100 require human approval").

  • Sanitization: It strips potential prompt injections from tool outputs before they return to the LLM's context.

3. Behavioral Monitoring (MTP):

Since agents are non-deterministic, you must monitor for Model Task Persistence (MTP).

  • Detect if an agent is "looping" or deviating from its original goal.

  • Log every step: The original prompt, the plan generated, the tool called, and the final result for a full audit trail.

Emerging Standards:

NIST AI Agent Standards (March 2026): Focuses on automated benchmark evaluations and identity authorization.

India IT Amendment Rules 2026: Specifically mandates traceability for agent-generated actions and content (SGI - Synthetically Generated Information).

ISO/IEC 42001: Provides the management framework for AI ethics and transparency.


ref: OWASP GenAI Security Project @ https://genai.owasp.org/

The OWASP Top 10 for Agentic Applications 2026 @ https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
OWASP GenAI Data Security Risks & Mitigations 2026 @ https://genai.owasp.org/resource/owasp-genai-data-security-risks-mitigations-2026/

Posted by Krishna Kishore Koney
Labels: AI (Artificial Intelligence), AI/ML, LATEST TECHNOLOGY

Agentic AI Overview

Large Language Model(LLM) is a "reasoning engine," Agentic AI is a "system of action." In simple terms: an LLM is the brain, but Agentic AI is the brain plus hands, eyes, and a memory. Agentic AI achieves precise actions through hybrid design - probabilistic LLM for flexible planning + deterministic tools + closed feedback loops. It's like giving a creative but unreliable assistant a strict checklist, calculator, and supervisor who checks every step. This is why hybrid human + Agentic systems are still the sweet spot: the AI handles scale and iteration, humans provide the true causal judgment and final oversight.

The shift from syntax (the rules and structure of language) to semantics (the meaning and intent behind language) is the defining characteristic of the transition from "Old AI" to Modern Generative AI. It means, We are moving from a world where we had to be precise with our instructions to a world where we only need to be clear with our intentions.

A Large Language Model (LLM) is a neural network (like GPT, Claude, Grok, or Llama) trained on massive amounts of text data. Its core strength is next-token prediction: it generates coherent, human-like text based on patterns learned during training.

What is Agentic AI? Agentic AI (or AI agents / agentic systems) refers to AI setups that exhibit agency - the ability to pursue goals independently, make decisions, plan, use tools, maintain memory, and adapt based on outcomes.

An agent typically uses one or more LLMs as its "brain" for reasoning, but adds extra components:

  • Planning/reasoning loops (e.g., ReAct, Chain-of-Thought, or more advanced frameworks).
  • Tool use: Calling APIs, web search, code execution, databases, or other software.
  • Memory: Short-term (conversation) + long-term (past actions, user preferences).
  • Autonomy: The system can break down a high-level goal into steps, execute them, observe results, and iterate until the goal is achieved (or fails gracefully).

LLM vs Agentic AI:
  • Almost all modern agentic systems rely on LLMs as the core reasoning engine.
  • An AI Agent is often an LLM wrapped with tool-calling and a control loop.
  • Agentic AI sometimes refers to more advanced, multi-agent, highly autonomous systems (a "team" of agents collaborating).
  • Progression: LLM → LLM + Tools (basic agent) → Full agentic system with planning, memory, and adaptation.

Practical examples of LLM & Agentic AI:
  • Customer Support:

    • LLM: Drafts a polite response to a customer complaining about a late shipment.

    • Agentic AI: Detects the complaint, checks the logistics DB, sees the delay, issues a 10% refund, updates the CRM, and emails the customer with the new tracking number.

  • Software Development:

    • LLM: Suggests a code snippet for a bug.

    • Agentic AI: Reads the error log, identifies the file, writes the fix, runs the unit tests, and submits a Pull Request if the tests pass.

How Agentic AI peform ACTIONS?:

Agentic AI (as of 2026) is not just a smarter LLM - it's an iterative system built on top of one. The LLM acts as the "planner/thinker," but the real precision comes from structured loops and tools that ground it in reality.

The dominant pattern is ReAct (Reason + Act + Observe - introduced 2023 and still foundational in 2026):

  • Observe (perceive environment or tool result).
  • Reason (LLM generates a thought/plan in natural language).
  • Act (LLM decides on and calls a tool—e.g., "run this Python code", "search the web", "send an email", "execute a database query").
  • Observe the real result → feed it back → repeat until goal is met.

Other patterns like Plan-and-Execute (make full plan first, then run steps) or Reflexion (self-critique and retry) add extra layers, but the core is the same: break the probabilistic LLM output into small, verifiable, tool-backed steps.

Why this feels "precise":

  • The tools themselves are deterministic. Once the LLM says "call the code_execution tool with this exact script," the tool runs the code exactly as written (no probability involved). Same for APIs, file writes, browser actions, etc.
  • The feedback loop corrects the LLM's mistakes in real time. If the action fails or produces wrong output, the LLM sees the error and adjusts its next reasoning step.
  • Memory and reflection keep state consistent across steps (unlike one-shot prompts).

Real-world example:

  • You ask an Agentic AI: "Write and test a new C++ program for X that wasn't in training data."
  • LLM (probabilistically) reasons: "First, plan the structure… then write the code… now compile and test."
  • It calls a deterministic tool (code compiler/runner) → gets exact output/errors → reasons again: "Bug here because of Y → fix with this change."
  • Result: It can produce and iterate on novel code reliably because the tools enforce correctness, not because the LLM "understood" C++ causally.

In finance, An agent might predict a probability, then use tools to run causal simulations, fetch live data, or execute a trade - making the overall workflow precise even if the initial "why" was statistical.



ref:

Agentic AI @
    1. https://mitsloan.mit.edu/ideas-made-to-matter/agentic-ai-explained

    2. https://www.ibm.com/think/topics/agentic-ai

    3. https://cloud.google.com/discover/what-is-agentic-ai

    4. https://aws.amazon.com/what-is/agentic-ai/

Posted by Krishna Kishore Koney
Labels: AI (Artificial Intelligence), AI/ML, LATEST TECHNOLOGY
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

The Verge - YOUTUBE

Loading...

Hard Fork Podcast

Loading...

Dwarkesh Patel Podcast

Loading...

SemiAnalysis Podcast (Dylan Patel)

Loading...

Andrej Karpathy Youtube Channel

Loading...

Microsoft Research

Loading...

Hugging Face - Blog

Loading...

AI at Wharton

Loading...

Stanford Online

Loading...

MIT OpenCourseWare - YOUTUBE

Loading...

NPTEL IISC BANGALORE - YOUTUBE

Loading...

HackerRank - YOUTUBE

Loading...

FREE CODE CAMP - YOUTUBE

Loading...

BYTE BYTE GO - YOUTBUE

Loading...

GAURAV SEN INTERVIEWS - YOUTUBE

Loading...

Tanay Pratap - YOUTUBE

Loading...

Ashish Pratap Singh - YOUTUBE

Loading...

Kantan Coding - YOUTUBE

Loading...

SUCCESS IN TECH INTERVIEWS - YOUTUBE

Loading...

IGotAnOffer: Engineering - YOUTUBE

Loading...

DEEPLEARNING AI - YOUTUBE

Loading...

MIT News - Artificial intelligence

Loading...
My photo
Krishna Kishore Koney
View my complete profile
" It is not the strongest of the species that survives nor the most intelligent that survives, It is the one that is the most adaptable to change "

View krishna kishore koney's profile on LinkedIn


Failure is not falling down, it is not getting up again. Success is the ability to go from failure to failure without losing your enthusiasm.

Where there's a Will, there's a Way. Keep on doing what fear you, that is the quickest and surest way to to conquer it.

Vision is the art of seeing what is invisible to others. For success, attitude is equally as important as ability.

Monthly Blog Archives

  • ▼  2026 (7)
    • ▼  July (2)
      • REST vs GraphQL
      • Nautobot: Opensource Network Source of Truth (NSoT...
    • ►  May (1)
    • ►  April (1)
    • ►  March (3)
  • ►  2025 (4)
    • ►  October (1)
    • ►  August (1)
    • ►  May (1)
    • ►  April (1)
  • ►  2024 (18)
    • ►  December (1)
    • ►  October (2)
    • ►  September (5)
    • ►  August (10)
  • ►  2022 (2)
    • ►  December (2)
  • ►  2021 (2)
    • ►  April (2)
  • ►  2020 (18)
    • ►  November (1)
    • ►  September (8)
    • ►  August (1)
    • ►  June (8)
  • ►  2019 (18)
    • ►  December (1)
    • ►  November (2)
    • ►  September (3)
    • ►  May (8)
    • ►  February (1)
    • ►  January (3)
  • ►  2018 (3)
    • ►  November (1)
    • ►  October (1)
    • ►  January (1)
  • ►  2017 (2)
    • ►  November (1)
    • ►  March (1)
  • ►  2016 (5)
    • ►  December (1)
    • ►  April (3)
    • ►  February (1)
  • ►  2015 (15)
    • ►  December (1)
    • ►  October (1)
    • ►  August (2)
    • ►  July (4)
    • ►  June (2)
    • ►  May (3)
    • ►  January (2)
  • ►  2014 (13)
    • ►  December (1)
    • ►  November (2)
    • ►  October (4)
    • ►  August (5)
    • ►  January (1)
  • ►  2013 (5)
    • ►  September (2)
    • ►  May (1)
    • ►  February (1)
    • ►  January (1)
  • ►  2012 (19)
    • ►  November (1)
    • ►  October (2)
    • ►  September (1)
    • ►  July (1)
    • ►  June (6)
    • ►  May (1)
    • ►  April (2)
    • ►  February (3)
    • ►  January (2)
  • ►  2011 (20)
    • ►  December (5)
    • ►  August (2)
    • ►  June (6)
    • ►  May (4)
    • ►  April (2)
    • ►  January (1)
  • ►  2010 (41)
    • ►  December (2)
    • ►  November (1)
    • ►  September (5)
    • ►  August (2)
    • ►  July (1)
    • ►  June (1)
    • ►  May (8)
    • ►  April (2)
    • ►  March (3)
    • ►  February (5)
    • ►  January (11)
  • ►  2009 (113)
    • ►  December (2)
    • ►  November (5)
    • ►  October (11)
    • ►  September (1)
    • ►  August (14)
    • ►  July (5)
    • ►  June (10)
    • ►  May (4)
    • ►  April (7)
    • ►  March (11)
    • ►  February (15)
    • ►  January (28)
  • ►  2008 (61)
    • ►  December (7)
    • ►  September (6)
    • ►  August (1)
    • ►  July (17)
    • ►  June (6)
    • ►  May (24)
  • ►  2006 (7)
    • ►  October (7)

Blog Archives Categories

  • .NET DEVELOPMENT (38)
  • 5G (5)
  • AI (Artificial Intelligence) (16)
  • AI/ML (10)
  • ANDROID DEVELOPMENT (7)
  • BIG DATA ANALYTICS (6)
  • C PROGRAMMING (7)
  • C++ PROGRAMMING (24)
  • CAREER MANAGEMENT (6)
  • CHROME DEVELOPMENT (2)
  • CLOUD COMPUTING (47)
  • CODE REVIEWS (3)
  • CYBERSECURITY (12)
  • DATA SCIENCE (4)
  • DATABASE (14)
  • DESIGN PATTERNS (9)
  • DEVICE DRIVERS (5)
  • DIY (3)
  • DOMAIN KNOWLEDGE (14)
  • EDGE COMPUTING (4)
  • EMBEDDED SYSTEMS (9)
  • ENTERPRISE ARCHITECTURE (10)
  • IMAGE PROCESSING (3)
  • INTERNET OF THINGS (2)
  • J2EE PROGRAMMING (10)
  • KERNEL DEVELOPMENT (6)
  • KUBERNETES (20)
  • LATEST TECHNOLOGY (25)
  • LINUX (9)
  • MAC OPERATING SYSTEM (2)
  • MOBILE APPLICATION DEVELOPMENT (14)
  • PORTING (4)
  • PYTHON PROGRAMMING (6)
  • RESEARCH AND DEVELOPMENT (1)
  • SCRIPTING LANGUAGES (8)
  • SERVICE ORIENTED ARCHITECTURE (SOA) (10)
  • SOFTWARE DESIGN (13)
  • SOFTWARE QUALITY (5)
  • SOFTWARE SECURITY (24)
  • SYSTEM and NETWORK ADMINISTRATION (4)
  • SYSTEM PROGRAMMING (4)
  • TECHNICAL MISCELLANEOUS (32)
  • TECHNOLOGY INTEGRATION (5)
  • TEST AUTOMATION (5)
  • UNIX OPERATING SYSTEM (4)
  • VC++ PROGRAMMING (44)
  • VIRTUALIZATION (8)
  • WEB PROGRAMMING (8)
  • WINDOWS OPERATING SYSTEM (13)
  • WIRELESS DEVELOPMENT (5)
  • XML (3)

Popular Posts

  • REST vs GraphQL
  • Service Discovery Protocols
  • REST vs SOAP
  • Uninstall Kubernetes on CentOS Shell Script

My Other Blogs/Channels

  • Career Management: Invest in Yourself
  • A la carte: Color your Career
  • Attitude is everything(Telugu language)
  • "Invest in Yourself" Youtube Channel (Telugu language)
WINNING vs LOSING

Hanging on, persevering, WINNING
Letting go, giving up easily, LOSING

Accepting responsibility for your actions, WINNING
Always having an excuse for your actions, LOSING

Taking the initiative, WINNING
Waiting to be told what to do, LOSING

Knowing what you want and setting goals to achieve it, WINNING
Wishing for things, but taking no action, LOSING

Seeing the big picture, and setting your goals accordingly, WINNING
Seeing only where you are today, LOSING

Being determined, unwilling to give up WINNING
Gives up easily, LOSING

Having focus, staying on track, WINNING
Allowing minor distractions to side track them, LOSING

Having a positive attitude, WINNING
having a "poor me" attitude, LOSING

Adopt a WINNING attitude!

Total Pageviews

Who am I

My photo
Krishna Kishore Koney

Blogging is about ideas, self-discovery, and growth. This is a small effort to grow outside my comfort zone.

Most important , A Special Thanks to my parents(Sri Ramachandra Rao & Srimathi Nagamani), my wife(Roja), my lovely daughter (Hansini) and son (Harshil) for their inspiration and continuous support in developing this Blog.

... "Things will never be the same again. An old dream is dead and a new one is being born, as a flower that pushes through the solid earth. A new vision is coming into being and a greater consciousness is being unfolded" ... from Jiddu Krishnamurti's Teachings.

Now on disclaimer :
1. Please note that my blog posts reflect my perception of the subject matter and do not reflect the perception of my Employer.

2. Most of the times the content of the blog post is aggregated from Internet articles and other blogs which inspired me. Due respect is given by mentioning the referenced URLs below each post.

Have a great time

My LinkedIn Profile
View my complete profile

Aryaka Insights

Loading...

Reid Hoffman - YOUTUBE

Loading...

Martin Fowler's Bliki - BLOG

Loading...

The Pragmatic Engineer

Loading...

AI Workshop

Loading...

CYBER SECURITY - YOUTUBE

Loading...

CYBER SECURITY FUNDAMENTALS PROF MESSER - YOUTUBE

Loading...