Enterprise Reference

Your agent will be told what to do by people who are not you.

recon inject escalate pivot persist exfiltrate detect contain

Three properties make an agent a different security problem from the application it replaces: it reads attacker-controlled text inside the loop that decides what to do next, it holds real authority over systems and money, and it acts autonomously between the points where a human looks. Everything else follows from that combination. The hostile instruction does not arrive as a payload in a field — it arrives as a sentence in a document, a row in a record, a description on a borrowed tool, or a line written into memory months earlier. This guide covers the threat model and the trust boundaries, the full attack surface, prompt injection and why it is not solved, excessive agency, the supply chain, data exfiltration, execution and persistence, multi-agent and human-directed attacks, availability and economic abuse, detection, red teaming, incident response, and the operating model that holds it together. Five lenses per concept: what it requires, how to architect it for a bank, a flow diagram, a plain-English reading, and what it hands off next.