How to Secure Agents That Plan, Act, and Lie to You | John Sotiropoulos | Season 1 EP 7

How to Secure Agents That Plan, Act, and Lie to You | John Sotiropoulos | Season 1 EP 7

🎙 Eva Benn 👥 101K 📅 June 1, 2026 ⏱ 25 min 👁 4K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

AI agentssecurityOWASP Top 10MCPshadow AI

Summary

In this episode of Security Mondays, host Eva Benn interviews John Sotiropoulos, a leading expert in AI security and chair of the OWASP Top 10 for Agentic Applications. The conversation focuses on the unique security challenges posed by AI agents that can plan, act, and potentially deceive. John emphasizes the speed of adoption and operation of AI agents, contrasting machine-speed attacks with human-speed governance. He advises organizations to move from merely describing risks to embedding security capabilities, using frameworks like the OWASP Top 10 and the ETSI lifecycle. Key topics include the importance of agentic inventory, addressing shadow AI, and managing supply chain risks, particularly with MCP servers. John provides practical steps for security leaders, such as using the DeepCyber playbook and slicing the Top 10 across the lifecycle. The episode concludes with actionable advice for immediate implementation.

138 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into securing AI agents, drawing on John Sotiropoulos’s extensive experience and leadership in developing industry standards. The argumentation is solid, grounded in real-world examples and practical advice. John effectively explains complex concepts like the speed of AI-driven attacks and the need for dynamic governance. He offers concrete steps for CISOs, such as conducting agentic inventories and using the OWASP Top 10 as a practical tool. The discussion is well-structured, moving from problem identification to actionable solutions, making it highly valuable for security professionals.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates strong scientific rigor by referencing authoritative sources, including the OWASP Top 10 for Agentic Applications, the UK AI Cyber Security Code of Practice, and ETSI standards. John’s credentials as chair of the OWASP Top 10 and author of the implementation guide lend credibility. The title accurately reflects the content, focusing on securing AI agents and their deceptive capabilities. The discussion is well-aligned with the title, providing in-depth coverage of the topic. The sources cited are relevant and trustworthy, enhancing the overall reliability of the information presented.

192 words

Title / Content Match

The title accurately reflects the content, focusing on securing AI agents and highlighting the deceptive capabilities of agents, as discussed by John Sotiropoulos.

Quality & Reliability

8/10

The content is presented by an expert in AI security with direct involvement in major frameworks (OWASP, ETSI, UK Code of Practice). The discussion is grounded in practical experience and references authoritative sources. However, some claims lack specific citations within the video, and the format is conversational rather than peer-reviewed.

Chapters

Cited Sources

Concurring Sources

  • OWASP Top 10 for Agentic Applications — The video aligns with the framework's guidance on agentic security.
  • ETSI EN 304 223 — The video's emphasis on lifecycle aligns with the ETSI standard.

External References

Contribution & Novelties

The video offers a practical, expert-driven perspective on securing AI agents, emphasizing the need for dynamic governance and operationalizing frameworks like the OWASP Top 10. It provides actionable steps for security leaders, such as conducting agentic inventories and using the ETSI lifecycle. The discussion highlights the unique challenges of shadow AI and supply chain risks in agentic systems, offering concrete advice on MCP security.

Pour aller plus loin :

138 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a balanced and credible discussion suitable for a professional audience.

Reliability 8/10