What is AI agent security?
GUIDE · 3 MIN READ
AI agent security is the set of controls that let an organization see which AI agents are running, decide what each one may do, stop actions that break policy, and keep a record of who did what.
UNIVERSITY · SEPTEMBER 2026
The verdict
A reference shelf for teams new to AI agent security: a glossary of 46 terms and twelve lessons and guides in three tracks. Start with Basics (what agents do and where controls sit), move to Buying (how to read claims and scores), then Running it (EDR, managed settings and the activity record).
Start here if you are new to AI agents and MCP.
GUIDE · 3 MIN READ
AI agent security is the set of controls that let an organization see which AI agents are running, decide what each one may do, stop actions that break policy, and keep a record of who did what.
LESSON · 3 MIN READ
How an agent finds and calls an MCP tool, and where a control can step in.
LESSON · 2 MIN READ
The four places a control can sit, and what each one sees.
LESSON · 3 MIN READ
How hidden instructions in content become agent actions, and where a control can stop them.
GUIDE · 3 MIN READ
MCP security means knowing which MCP servers your agents connect to, limiting what each one can do, and checking tool calls before they run.
GUIDE · 2 MIN READ
Shadow AI is any AI tool, agent, extension or MCP server that employees use without the organization's approval or visibility.
For teams building a shortlist.
LESSON · 2 MIN READ
What vendor-stated and Not published mean, and how to test a claim.
LESSON · 2 MIN READ
What the seven criteria measure, how weights and ties work, and how to re-weight them.
GUIDE · 3 MIN READ
Ask every vendor to show, on your own devices, the four checkpoints: what it sees, how it decides before an action runs, what it can do besides block, and what it logs.
For teams rolling out and operating agent controls.
GUIDE · 2 MIN READ
EDR and AI agent security do different jobs, and most organizations will run both.
LESSON · 3 MIN READ
Controlling coding agents from the inside with managed settings, hooks and MCP allow lists.
LESSON · 3 MIN READ
What to log for every agent action, and how to separate agent actions from human ones.
46 terms used across this site, from agent hooks to token passthrough. Where a term comes from a standard, such as the MCP specification or the OWASP GenAI Security Project, the entry links to it.
46 TERMS
Want the whole picture first? Read the rankings, the FAQ, or our notes.