
Threat Modelling Autonomous AI Agents
An AI agent that can call tools is a new kind of privileged user: it holds credentials, takes actions with side effects, and decides what to do next from text it did not write. This report sets out a threat model for agentic systems and the controls that constrain them — written for teams shipping agents into production rather than evaluating them in a lab.





