cd /news/ai-agents/leanpub-book-launch-securing-enterpr… · home topics ai-agents article
[ARTICLE · art-77946] src=leanpub.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Leanpub Book LAUNCH 🚀 Securing Enterprise AI Agents: A Field Guide to Bounded AI Autonomy, AgentSecOps, and MCP Security by Thomas De Vos

Thomas De Vos has launched the book 'Securing Enterprise AI Agents: A Field Guide to Bounded AI Autonomy, AgentSecOps, and MCP Security' on Leanpub, providing a six-part, 21-chapter field guide for production AI agent security in regulated environments. The book targets engineers, architects, and security leads who need a seven-layer reference architecture, a production readiness checklist, and a definition of bounded AI autonomy to defend to auditors.

read2 min views1 publishedJul 29, 2026
Leanpub Book LAUNCH 🚀 Securing Enterprise AI Agents: A Field Guide to Bounded AI Autonomy, AgentSecOps, and MCP Security by Thomas De Vos
Image: Leanpub (auto-discovered)

Books The book is for the person who owns the sign-off. The engineer whose demo now has to go live. The architect triaging a stack of agent proposals.

Welcome to the Leanpub Launch video for Securing Enterprise AI Agents: A Field Guide to Bounded AI Autonomy, AgentSecOps, and MCP Security by Thomas De Vos!

About the Book #

Your CTO just asked the question. The team wants to put an AI agent in front of customers. Not a chatbot. An agent that can read from the CRM, decide, and act. Payments, cases, refunds, entitlements.

Is it safe to ship?

What is your plan?

Whose name goes on the decision?

The old security playbook was not written for this. Reviewing prompts and logging chatbot sessions is not enough once an AI system can pick a tool, call an API, and change state in production. Something that can act needs an identity, a boundary, an audit trail, and a way to fail safely. It also needs someone who has thought carefully about what happens when the model decides badly, when the retrieval layer returns poisoned content, or when a tool wrapper leaks a token.

Securing Enterprise AI Agents is the field guide that answers those questions. Six parts, twenty-one chapters, worked examples drawn from financial services because that is what regulated builds look like. Part I reframes the risk model. Part II is the reference architecture for a production agent, from human user down through the orchestrator, the model, the tool wrapper, MCP, policy, and data layer. Part III turns evals and observability into the release control your CI does not have yet. Part IV is secure RAG, including the parts most teams skip. Part V is coding agents in professional teams. Part VI is deployment, policy as code, incident response, and how to run all of this as one AgentSecOps discipline.

The book is for the person who owns the sign-off. The engineer whose demo now has to go live. The architect triaging a stack of agent proposals. The security lead asked to bless something they cannot fully see. The engineering director choosing where the next quarter of platform investment goes.

No AGI speculation. No vendor comparison. No "challenges and opportunities" bullet lists at the end of every chapter. You will leave with a seven-layer reference architecture you can defend to an auditor, a production readiness checklist you can run in an afternoon, and a working definition of bounded AI autonomy that keeps the model useful without giving it the whole surface.

About the Author #

Engineer and AI practitioner with over a decade building production AI systems for global financial institutions. Focused on the intersection of autonomous agents, regulatory compliance, and operational reliability. Currently leading AI strategy for banking, insurance, and fintech clients across multiple continents.

── more in #ai-agents 4 stories · sorted by recency
── more on @thomas de vos 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/leanpub-book-launch-…] indexed:0 read:2min 2026-07-29 ·