
Agents, MCP integrations, and LLM-powered applications are entering codebases faster than most security programs can track them. Mend.io’s new practitioner guide, ‘Securing AI agents, MCP servers & LLM apps: A practical framework’, targets that gap. It is organized around three moves: see what matters, fix what matters faster, protect AI in production and ships seven reusable artifacts. Why traditional AppSec breaks AppSec was built on one assumption: applications do what their
A practitioner guide addresses how to secure AI agents, MCP servers, and large language model applications in production environments. Traditional application security approaches fail for agentic AI because agent behavior emerges from multiple sources—models, prompts, context, user input, and available tools—rather than code alone, creating new failure modes like prompt injection through data and over-permissioned agents taking harmful actions without exploited vulnerabilities. The guide proposes a framework organized around three moves: discovering and mapping what matters through a five-layer attack surface, prioritizing and triaging findings with evidence-backed automation, and protecting systems at runtime through guardrails, prompt hardening, and monitoring. The approach aligns to established security frameworks including NIST AI RMF, OWASP AIMA, ISO/IEC 42001, and the EU AI Act.

Long-running agents accumulate state that no transcript captures. A coding agent at step 10 holds edited files, a running dev server, installed packages, and a warm prompt cache. When it misreads a traceback and rewrites a file that was already correct, neither available recovery path is cheap: patching forward grows the context and the token bill, and restarting from step one re-pays every model and tool call while reproducing nothing exactly, because runs are non-deterministic. Jumping back t

New AI toolbars and prompts are showing up in Google Docs and Gmail. If you don’t want Gemini’s help in writing documents and emails, here’s how to turn that stuff off.

In October 2025, a storm brewed over the Caribbean Sea. Weather models differed on its trajectory. Would it remain weak and end up in Haiti, or would it intensify and head to Jamaica? Artificial intelligence model WeatherNext, developed by Google’s DeepMind and Google Research, went with the latter. Five days before landfall, it predicted with 80 percent confidence that the storm system would hit Jamaica as a Category 5 hurricane. Hurricane Melissa was catastrophic, causing flooding and landslid
Want to go deeper than the news? Explore live, cohort-based AI courses taught by practitioners.
Browse AI courses on Maven