Agentic AI is changing the way applications are designed, tested, deployed, and secured.Traditional application security focuses on APIs, authentication, authorization, databases, code, sessions, and technical attack surfaces.But Agentic AI introduces a different challenge.A user may not need technical knowledge to influence the system.A simple natural language prompt can make an AI agent classify intent, call a tool, retrieve data, generate a response, trigger a workflow, or influence a business decision.In this podcast episode, Prabh speaks with Akansha about Threat Modeling for Agentic AI Systems, using a practical customer support chatbot architecture as the case study.The architecture discussed includes:Classifier agentResponder agentQA reviewer agentHuman approval processRetrieval databaseTool integrationsLogging and monitoringRefund workflowThird-party integrationsThe session explains how a customer request flows through different agents, how intent is classified, how responses are generated, how refund requests are reviewed, and why human approval is important for high-risk financial actions.Content Reference https://github.com/smartdevil09/AI-Security-Professional-Roadmap/blob/main/AI%20security%20concepts/Threat%20Modelling%20Agentic%20Architecture.pdfLinkedin Profilehttps://www.linkedin.com/in/akesharwani/In this episode, we discuss:How Agentic AI differs from traditional application securityWhy prompts and natural language interactions create new risksWhy threat modeling should happen before production deploymentWhy stakeholder engagement is criticalHow to understand the business problem before identifying threatsHow to create an asset inventory for AI systemsHow to identify business assets and AI assetsHow to prepare data flow diagrams for multi-agent systemsHow to define trust boundaries between users, agents, tools, databases, and third partiesWhy refund workflows need stronger approval controlsWhy human approval is required for critical financial transactionsWhy logging and monitoring must be carefully designedHow to avoid logging sensitive PII dataHow attackers may exploit AI agents using prompt injectionHow AI agents may be manipulated into unauthorized actionsHow traditional AppSec controls still matter in Agentic AI systemsHow third-party Agentic AI systems should be assessedWhat documentation should be requested from vendorsHow to use STRIDE, MITRE ATLAS, OWASP LLM Top 10, CVE, and CWE for threat enumerationHow to evaluate likelihood, impact, business risk, and compliance riskWhy threat modeling must be continuously updated as architecture and threats changeAkansha also explains that threat modeling Agentic AI is not a simple automated checklist activity.It requires business context, stakeholder interviews, architecture understanding, asset inventory, data flow mapping, trust boundary analysis, risk assessment, guardrail design, logging, monitoring, validation, and continuous review.#AgenticAI #AISecurity #ThreatModeling #AppSec #AIGovernance #OWASP #MITREATLAS #CyberSecurity #GRC #CoffeeWithPrabh