The AI Agent Security course equips you to secure autonomous agents end to end: identity, authorization, tool use, payments, and the kill switch. Two days, hands-on, on live agent systems. Mapped to the OWASP Agentic Top 10 and AISVS.
OWASP Agentic Security Top 10, the Agentic Skills Top 10, AISVS C5/C9/C10, and the OWASP cheat sheet on AML and sanctions for AI agent payments, authored by your instructor. Per-action evidence maps to the IETF Agent Audit Trail Internet-Draft, also authored by your instructor.
Classes are custom built from the following learning modules. Instructors select ~16 hours for a 2-day delivery, tailored to the audience. Custom formats from 1 to 4 days available. (Times are approximate.)
Autonomy, tool use, planning and memory. Why agent security is not just LLM security with extra steps.
Mapping every point an adversary can reach: prompt, tools, memory, delegation chains, external APIs, payment rails and data egress.
L0-L4 graduated trust: from untrusted through to critical actions that require human approval. How to decide what level each action deserves.
LangChain, CrewAI, AutoGen, Pydantic AI and custom loops. Common patterns, common gaps and what the frameworks do not do for you.
Agents are not users. Why OAuth, API keys and session tokens fail for autonomous systems. What agent identity actually requires.
Hands on: issue ECDSA P-256 signed agent credentials. Bind name, capability and owner into a verifiable identity document the agent carries.
JWT-SVIDs, trust bundles and JWKS verification. Workload identity across clusters and clouds without shared secrets.
Agent registries, handle reservation, anti-squatting and lookup. DNS for agents.
Proving an agent is who it claims at runtime, not just at registration. Challenge-response flows with signed proofs.
Autonomous procurement, API billing, inter-agent settlement. The use cases that force the question.
Hands on: wire trust-level checks into payment flows. L1 reads, L2 queries, L3 pays, L4 needs human approval. Every threshold enforced in code.
Hands on: screen agent counterparties against live OFAC SDN and UK HMT lists (75,000+ entries) before any financial action proceeds.
Every payment produces a cryptographically signed receipt: who paid, who received, how much, when, and the trust level. Tamper-evident and verifiable.
Agent payment over Lightning Network: sub-second settlement, micropayments and the MCPS wire format for transport-agnostic agent trust.
Why software confirmation is not enough for critical actions. The threat model that demands a physical gate.
Hands on: wire a hardware human-approval device into agent workflows. Critical actions block until a human physically approves. Signed approval receipt returned.
What happens when the approval device is unreachable: the action does not proceed. Designing systems where the default is denial, not bypass.
L0-L2 proceed autonomously. L3 notifies. L4 blocks and waits. Configuring the escalation ladder for your organisation.
Hands on: sign every agent message with MCPS. Nonce, timestamp, ECDSA signature. Replay protection and tamper detection on the wire.
How agents verify each other before sharing data or delegating tasks. Mutual identity verification without a central broker.
Agent A delegates to B, who delegates to C. Scope narrowing, depth limits and revocation. Preventing confused deputy and authority laundering.
TLS, mTLS and transport-agnostic signing. What the transport layer gives you and what it does not.
Every action produces a signed, hash-chained receipt. Building the evidence chain that reconstructs exactly what happened and why.
What normal agent behaviour looks like and how to detect deviation: unusual tool calls, unexpected data access, velocity spikes and scope drift.
Revoking credentials in real time. Killing a running agent. Containing blast radius when an agent is compromised or misbehaving.
Issue agent credentials, register agents, verify identity at runtime and revoke a compromised agent. End to end.
Wire trust-gated payments with sanctions screening. Attempt a payment to a sanctioned entity. Verify it blocks. Verify the receipt.
Connect the hardware approval device. Trigger L4 actions. Watch them block. Approve one. Verify the signed receipt.
Red-team an agent estate: escalate trust, bypass delegation limits, replay signed messages, extract data. Then fix every finding.
Autonomy without a stop button is negligence. You learn the layered kill switch: human approval on irreversible actions, hardware deny, instant trust revocation, and halting a whole agent swarm, with every stop recorded as evidence.
When an agent moves money, the same rules apply, and the evidence has to hold. Grounded in the OWASP cheat sheet on AML and sanctions for AI agent payments, authored by your instructor: sanctions screening, signed receipts, non-repudiation, and a record an auditor and a regulator will accept.
AgentBee is a hardware key that puts a human in control of an AI agent's most critical actions. Plug it in, and an agent cannot move money, delete data, deploy, or take other high-stakes actions until a person physically approves on the device.
Every approval is signed with FIDO-grade crypto (ECDSA P-256): a tamper-evident record of who authorised what. It is the physical kill switch and human-in-the-loop you deploy in this course.
agentbee.co.uk →Agents act, and when something goes wrong you must reconstruct exactly what happened and prove it. This brings real forensic discipline to agent systems, taught by an instructor qualified in cyber-forensics.
What an agent action leaves behind, and how to capture it intact.
Preserving agent evidence so it holds from incident to hearing.
What a court and a regulator will accept, and what they will not.
Rebuilding what an agent did from the tamper-evident trail.
Signed actions and approvals that cannot be denied later.
Containing, investigating and reporting an agent incident.
No setup. You stand up agent systems on real GPUs in the cloud, attack them, apply the controls, and prove they hold.
Ship autonomous agents that pass security review.
Add agent security to your remit with real controls.
Secure the agent and MCP layer across the estate.
Secure agents that move money, AML and sanctions included.
Govern autonomous action with evidence and a kill switch.
Design agent systems you can secure and prove.
Certification is by practical examination. Candidates secure and verify a live agent system, apply the controls and the kill switch, and produce the evidence. On a passing result, the candidate is awarded the credential.
Two days, hands-on, on live agent systems, taught by the former OWASP-AISVS Co-Leader (v1.0) and the author of the OWASP AML and agent-payments cheat sheet. Places are limited.
Corporate & sovereign cohorts, and bespoke on-site delivery, on request.