Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageAI Security Desk
AI Security

SoK: The Attack Surface of Agentic AI - Tools and Autonomy

A systematisation-of-knowledge paper maps the expanded attack surface of agentic AI — tool abuse, RAG poisoning, multi-agent manipulation — giving CISOs a structured threat taxonomy for risk governance.

Summary written by editorial AI · Source link below

Filed by arXiv Crypto & Security1 min readRead at source ↗

arXiv:2603.22928v2 Announce Type: replace Abstract: Recent AI systems combine large language models with tools, external knowledge via retrieval-augmented generation (RAG), and even autonomous multi-agent decision loops. This agentic AI paradigm greatly expands capabilities - but also vastly enlarges the attack surface. In this systematization, we map out the trust boundaries and security risks of agentic LLM-based systems. We develop a comprehensive taxonomy of attacks spanning prompt-level in

Editorial Analysis

Why it matters

As agentic AI adoption accelerates, enterprises lack a unified threat model; this taxonomy provides the foundation for structured risk governance across tools, RAG, and autonomous loops.

What to do

Adopt the SoK taxonomy as a baseline for threat modelling all current and planned agentic AI deployments.

Board brief

A comprehensive academic mapping of AI agent attack surfaces provides the threat taxonomy boards need to govern agentic AI risk.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at arXiv Crypto & Security

External link — opens at arXiv Crypto & Security in a new tab.

§
Continue with

More from the AI Security Desk