
Threat Modeling for Agentic AI: Stop Treating Agents Like APIs
Keywords
Summary
187 words
Critical Evaluation
Value of the Information & Strength of the Argument
The value of the information lies in its practical, step-by-step approach to threat modeling agentic AI systems, using a relatable case study. The argumentation is solid, grounded in established frameworks like STRIDE and MITRE ATLAS, and emphasizes the need for business context and stakeholder engagement. The discussion effectively highlights the shift from API-centric security to considering natural language prompts as attack vectors, and provides concrete examples of threats such as prompt injection and unauthorized refund requests. The reasoning is coherent and well-structured, though it relies on anecdotal evidence rather than empirical data, which limits its scientific rigor.
Scientific Rigor, Source Quality, Title Accuracy
The scientific rigor is moderate: the discussion references well-known frameworks (STRIDE, MITRE ATLAS, OWASP LLM Top 10) and practical experience, but lacks formal citations or references to specific research. The sources cited in the description include a GitHub PDF and a LinkedIn profile, which are relevant but not peer-reviewed. The title accurately reflects the content, emphasizing the need to treat agentic AI differently from APIs. The adéquation between title and content is strong, as the episode consistently addresses the unique threat modeling requirements of agentic AI systems.
199 words
Title / Content Match
The title accurately reflects the core message: agentic AI systems require a threat modeling approach distinct from traditional API-centric security.
Quality & Reliability
8/10
The discussion is grounded in established threat modeling frameworks (STRIDE, MITRE ATLAS, OWASP LLM Top 10) and practical experience, but relies on anecdotal examples and lacks formal citations or empirical validation.
Chapters
- 00:42 – Highlights
- 02:58 - Introduction, Guest welcome, his credentials and Agenda
- 04:55 - Agentic AI, Threat Modeling and its practical approach
- 07:49 - Traditional Appsec vs Agentic AI Systems
- 13:48 - Agentic AI System: Architecture
- 14:51 - How it can be a threat for the user?
- 16:36 - Should business context be included in threat modeling?
- 21:35 - Data Flow Diagram
- 24:45 - Will increased security testing delay services?
- 29:30 - Components and Process and Data stores and hoe data flow from one point to another
- 30:29 - Audit Events and Asset Inventory
- 31:50 - How do you approach threat modeling for third-party agentic systems?
- 33:00 – What specific documentation should be requested from third parties?
- 38:00 - Draw Trust Boundaries
- 43:00 -Threats Modelling
- 46:20 - How is risk criticality decided for an organization?
- 47:40 - How to Analyze
- 49:10 - Validate the threat model
- 49:38 - Prioritize Remediation
- 51:16 - Threat Model as Living Document Level Documentation
- 52:27 - What resources are recommended for learning about new agentic AI threats?
- 53:44 - End of the conversation by thanking Akansha and looking forward to doing more Podcast.
Cited Sources
- Threat Modelling Agentic Architecture PDF — Referenced as the document prepared by the guest for the threat modeling exercise.
- Akansha's LinkedIn Profile — Provided as the guest's professional profile.
Concurring Sources
- OWASP LLM Top 10 — Mentioned as a framework for threat enumeration; aligns with the discussion's recommendations.
- MITRE ATLAS — Referenced as a framework for AI-specific threats; supports the episode's approach.
Contribution & Novelties
The episode provides a practical, structured approach to threat modeling agentic AI systems, emphasizing the need to move beyond traditional API-centric security. It offers a concrete case study and highlights the importance of business context, asset inventory, and data flow diagrams. The discussion on human approval and logging/monitoring adds practical insights.
Pour aller plus loin :
- OWASP LLM Top 10 — Official list of top vulnerabilities for LLM applications, directly relevant to threat enumeration.
- MITRE ATLAS — Knowledge base of adversary tactics and techniques for AI systems, useful for threat modeling.
- STRIDE threat model — Classic threat modeling framework referenced in the discussion.
103 words
Radar Profile
The radar profile shows high scores in information quantity and quality, with moderate technical depth and reliability. This indicates a well-rounded discussion that is informative and practical, though not deeply technical or rigorously sourced.