
How to Secure Agents That Plan, Act, and Lie to You | John Sotiropoulos | Season 1 EP 7
Keywords
Summary
138 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides valuable insights into securing AI agents, drawing on John Sotiropoulos’s extensive experience and leadership in developing industry standards. The argumentation is solid, grounded in real-world examples and practical advice. John effectively explains complex concepts like the speed of AI-driven attacks and the need for dynamic governance. He offers concrete steps for CISOs, such as conducting agentic inventories and using the OWASP Top 10 as a practical tool. The discussion is well-structured, moving from problem identification to actionable solutions, making it highly valuable for security professionals.
Scientific Rigor, Source Quality, Title Accuracy
The video demonstrates strong scientific rigor by referencing authoritative sources, including the OWASP Top 10 for Agentic Applications, the UK AI Cyber Security Code of Practice, and ETSI standards. John’s credentials as chair of the OWASP Top 10 and author of the implementation guide lend credibility. The title accurately reflects the content, focusing on securing AI agents and their deceptive capabilities. The discussion is well-aligned with the title, providing in-depth coverage of the topic. The sources cited are relevant and trustworthy, enhancing the overall reliability of the information presented.
192 words
Title / Content Match
The title accurately reflects the content, focusing on securing AI agents and highlighting the deceptive capabilities of agents, as discussed by John Sotiropoulos.
Quality & Reliability
8/10
The content is presented by an expert in AI security with direct involvement in major frameworks (OWASP, ETSI, UK Code of Practice). The discussion is grounded in practical experience and references authoritative sources. However, some claims lack specific citations within the video, and the format is conversational rather than peer-reviewed.
Chapters
- Why AI Agents Create New Security Risks
- Meet John Durbin & The Future of AI Security
- Machine Speed Attacks vs Human Speed Governance
- From Describing Risk to Embedding Security Capability
- How CISOs Should Operationalize AI Security Frameworks
- Shadow AI Is Every Security Leader’s Problem
- Supply Chain Attacks & MCP Server Risks
- How to Evaluate MCP Security & Runtime Governance
- The First Steps Every Security Team Should Take This Week
Cited Sources
- OWASP Top 10 for Agentic Applications (2026) — Referenced as the community standard for securing autonomous AI agents.
- Implementation Guide for the AI Cyber Security Code of Practice — Written by John Sotiropoulos, commissioned by the UK government, and fed into the ETSI standard.
- UK AI Cyber Security Code of Practice — The Code itself, published by DSIT, January 2025.
- DeepCyber — John's UK practice working on national-scale AI security.
- DeepCyber AI Readiness assessment — Offering page for the AI Readiness assessment.
- Adversarial AI: Attacks, Mitigations and Defense Strategies — John's book on adversarial AI, referenced as a resource.
- Adversarial AI book, GitHub code repo — Companion code for the book.
- ETSI EN 304 223 — First globally applicable European standard for AI cybersecurity, published January 2026.
- ETSI TS 104 223 — Earlier Technical Specification that the EN builds on.
- OWASP Agentic Security Initiative — Hub for agentic security guides, including MCP cheat sheets.
- OWASP GenAI resources archive — Archive of GenAI resources.
- A Practical Playbook for Adopting the OWASP Top 10 for Agentic Applications — Eva Benn's 90-day plan for operationalizing the Agentic Top 10.
Concurring Sources
- OWASP Top 10 for Agentic Applications — The video aligns with the framework's guidance on agentic security.
- ETSI EN 304 223 — The video's emphasis on lifecycle aligns with the ETSI standard.
External References
Contribution & Novelties
The video offers a practical, expert-driven perspective on securing AI agents, emphasizing the need for dynamic governance and operationalizing frameworks like the OWASP Top 10. It provides actionable steps for security leaders, such as conducting agentic inventories and using the ETSI lifecycle. The discussion highlights the unique challenges of shadow AI and supply chain risks in agentic systems, offering concrete advice on MCP security.
Pour aller plus loin :
- OWASP Top 10 for Agentic Applications — The core framework discussed, essential for understanding agentic security risks.
- ETSI EN 304 223 — The European standard for AI cybersecurity, providing a lifecycle approach.
- UK AI Cyber Security Code of Practice — The national code that influenced the ETSI standard.
- DeepCyber AI Readiness Assessment — Practical tool for assessing agentic exposure.
- MCP Security Cheat Sheets — Resources for securing MCP servers.
138 words
Radar Profile
The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a balanced and credible discussion suitable for a professional audience.