Summary

Completed

AI agents represent a significant shift in how organizations use artificial intelligence. Rather than only generating responses, agents can help complete goal-oriented workflows by using approved data, tools, services, and permissions.

Securing AI agents requires more than protecting applications or data alone. Organizations also need to establish trusted identities, apply governance policies, enforce least privilege, use containment while agents are running, and monitor activity across the AI development lifecycle.

Key takeaways

  • AI agents introduce new security considerations because they may access data, invoke tools, and perform approved actions across systems.
  • Identity helps establish who or what an agent is and what resources it can access.
  • Governance defines how an agent is expected to behave, including which actions require approval.
  • Least privilege means agents should receive only the minimum required permissions needed to complete assigned tasks.
  • Containment helps define runtime boundaries for where and how an agent can operate while it is running.
  • Monitoring and auditing help organizations maintain visibility, investigate unusual activity, and refine controls over time.
  • Security should be applied throughout the AI development lifecycle, from development and deployment through runtime and ongoing operations.

After completing this module, you can:

  • Describe how AI agents differ from AI experiences that primarily generate responses.
  • Identify where security risks emerge across agent workflows.
  • Explain how identity, access control, and governance help secure AI agents.
  • Describe how containment helps reduce risk while AI agents are running.
  • Explain how security practices protect code, agents, models, and data throughout the AI development lifecycle.

As AI continues to evolve, security remains a shared responsibility across development, deployment, and operations. By combining these practices with the platform security capabilities available in Windows, organizations can scale AI agent adoption with trust, control, and resilience practices in place.