Agentic AI security is the protection of AI systems that act: agents that plan, call tools, use credentials and change things with some autonomy. It covers who an agent is, what it is allowed to reach, whether each action and its inputs and outputs are safe at runtime, and whether a record of what it did holds up afterwards.

Why agents change the problem

A chatbot that only answers can be wrong; an agent with a payments tool can be wrong with money. The risk moves from what a model says to what it does, which brings familiar security questions to a new kind of actor:

  • Identity: each agent needs its own credential, separate from the people who deployed it. See non-human identity.
  • Least privilege: tools and data scoped to the task, not to everything an integration can reach.
  • Runtime control: a decision on consequential actions before they execute, including holds for a person's approval.
  • Input and output inspection: prompt injection arrives through documents, tickets and tool results, not only through what a user types.
  • Evidence: an AI agent audit trail that shows what was attempted and what was decided.

The OWASP Top 10 for Agentic Applications catalogues the attack side, from goal hijacking to rogue agents.

How it differs from LLM security

LLM security focuses on a model's inputs and outputs: jailbreaks, prompt injection, data leaking into responses, harmful content. Agentic AI security includes all of that and adds the action layer: tools, credentials, delegation between agents, and the systems they change. A model whose output is perfectly filtered can still take an action it should never have been allowed to take.

Where to go next

The full treatment is in the guide to agentic AI security. How Praesidia decides on agent actions at runtime is on AI agent runtime security; new policies start in observe mode, which records the decision and lets the call through, until a policy is set to enforce.

Common questions

Is agentic AI security the same as AI agent security?

Yes, the terms are used interchangeably. "Agentic" stresses the autonomy; "AI agent" names the actor.

Where should a team start?

With an inventory of agents and what each one can reach, then a credential per agent, then runtime decisions on the few actions that move money, change production or touch customer data.