Securing Agentic AI [Testμ 2026]
Blog post from TestMu AI
A Testμ Conf 2026 session by Nagarro’s Deepshikha and Anamika Mukhopadhyay examines why AI agents can cause harmful outcomes while operating within valid permissions, arguing that risks arise from their decision-making, memory, tool use, identity, and inter-agent communication rather than the language model alone. Using the OWASP agentic AI threat model, they describe goal manipulation through indirect prompt injection, persistent memory and retrieval poisoning, cross-tenant RAG data exposure, tool misuse involving manipulated parameters, confused-deputy privilege abuse, and communication poisoning that can spread compromised reasoning between agents. The speakers emphasize that conventional functional and login authorization tests are insufficient because legitimate agent credentials can make harmful actions appear normal in audit logs. They recommend testing the full agent decision loop through adversarial prompts, poisoned memory and retrieval data, tool-boundary tests, continuous authorization checks, and mocked agent-to-agent exchanges, while treating agents as privileged software requiring approvals, auditability, isolation, and ongoing security evaluation.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 6 | 931 | 231 | 103 | -84% |
| RAG | 3 | 101 | 30 | 23 | -91% |
| Vector Search | 2 | 265 | 57 | 33 | -89% |
| AI Model Fine-tuning | 1 | 139 | 28 | 14 | -75% |
| LLM | 1 | 747 | 162 | 79 | -85% |
| MCP | 1 | 2,241 | 148 | 72 | -74% |
| Multi-agent systems | 1 | 41 | 24 | 19 | -91% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.