AI Agent Security Bible
by Isaac Otu
You have let an AI assistant into your email, your files or your accounts. Three questions tell you whether a stranger's words could turn it against you, and what to do about it.
Your assistant reads your mail and sends messages as you. It also reads whatever strangers put in front of it: an email, a web page, a shared document. One planted sentence in that text can steer it into forwarding files or sending messages.
This book gives you one test, in plain English. Can it see your private information? Does it read words from people you do not control? Can it send things out? When all three answers are yes, you change the job or the setup until one becomes no.
Learn to:
- trace the routes planted text takes into an assistant, from email to plug-ins and saved memory, so you can close them in your own setup
- shrink what an assistant can reach, with its own account, one folder and access that expires, so a hijacked assistant has little to damage
- set approvals that still mean something at the fortieth prompt, so a person decides where it counts
- find the record and the off switch, so you can see what happened and stop it
- weigh the risk that remains, so you can grant, narrow or decline the job
Inside: eighteen real cases, sorted by what really happened, from a poisoned plug-in that copied outgoing email to a crafted message that made a work assistant leak data. Checklists for a person and for a team. Four ready-to-use templates: an access request, an approval policy, a first-hour response and vendor questions. An engineers' appendix with the standards behind the advice.
Start with the assistant you already use, and finish with a one-page review you can keep.