Agents act now. Someone has to prove they are under control.
AI Agent Security is a specialist practice for enterprise AI agents: which agents exist, under which identity, with which permissions, on which data, through which tools, what they actually do, and the evidence that proves it.
The risk moved from the model to the plumbing.
Agents no longer only answer questions. They read mailboxes and documents, call MCP servers and APIs, run code and change cloud resources. Most incidents now come through that plumbing: an instruction hidden in content the agent reads, a tool that changes behind its back, a token that reaches far more than the task needs.
Licences give you the switches. Someone still has to set them for each agent, test them against real attacks, and leave evidence an auditor or a customer can check. That is the work we do.
Achraf Hachimi
Senior security engineer, CISSP, graduate of IMT Nord Europe (Mines-Télécom). Eight years in critical environments, now focused on AI agents.
- 01Airbus: data loss prevention for 147,000 users, ITAR and NATO data, security networkDLP
- 02La Banque Postale Asset Management: lead security engineer, securing Microsoft 365 Copilot and Fabric, SOC and identityAI · IAM
- 03E.Leclerc: SOC level 3, EDR across 7,000 endpoints, PKI and WAFSOC
- 04DecathlonSECURITY