Course

Detection Engineering for AI and Agentic Systems

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Advanced
Modules 3
Lessons 3
Time 2 hr 30 min
Language en
Created by Threat Intelligence Lab
Updated 16 September 2026
Detection Engineering for AI and Agentic SystemsEVIDENCE connects to UNDERSTANDING. The course carries one line of reasoning from observation to a bounded claim.Detection Engineering for AI and Agentic SystemsEVIDENCEUNDERSTANDINGThe course carries one line of reasoning from observation to a bounded claim.

About this course

Understand how identity, delegated authority, tool use, memory, and data movement create evidence in AI systems that can act on a user’s behalf. The course is written for one reader and develops its ideas through continuous explanation, realistic thought experiments, and explicit distinctions between fact, assessment, and uncertainty.

What you'll learn

  • Reason from a security concern to evidence and a bounded analytical claim.
  • Explain assumptions, tradeoffs, and limitations in plain language.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Detection Engineering: From Telemetry to Tuned Detections — You should understand the basic detection lifecycle and common telemetry sources.

Course content

Module 1: Understand the Agent as an Authority Chain

Follow the user, application, model, agent, credential, tool, and resource identities that make an action possible.

Module 2: Observe Tool Use Without Logging Everything

Design evidence for tool calls, model interactions, retrieval, memory, and policy decisions while respecting privacy and proportionality.

Module 3: Detect Boundary Crossing and Respond Safely

Recognize unauthorized goal expansion, dangerous tool sequences, and policy bypass while keeping automated response proportional to certainty.

Keep building