New: Compliance toolkits for the EU AI Act and NIS2 (cybersäkerhetslagen) — templates your auditor will actually accept. Browse toolkits →

Services

Securing AI Agents in Production

A hands-on workshop for security teams deploying AI agents. Your team scores one of your own agent deployments and leaves with a prioritized gap list and a control roadmap mapped to NIS2 and the EU AI Act.

Contributor, OWASP Top 10 for Agentic Applications 2026 · CISSP · PhD · 15+ years enterprise security

What your team leaves with

Documents about your own systems, not slides about mine.

A scored Agent Security Scorecard

Your team scores one of your own agent or MCP deployments during the session, using the same interactive Scorecard that anchors every Molntek review.

A prioritized gap list

The specific exposures the scorecard surfaces on your system, ranked so you know the first three things to fix.

The Containment Ladder reference card

The four-rung framework for deciding what an agent is allowed to do: the control, what it stops, what it costs, and the NIS2 / EU AI Act evidence it produces.

A pre-deployment checklist

The checks to run before the next agent ships to production, so the gap you just found does not reopen on the next release.

The four modules

Four parts across a half day. The executive briefing is a shorter cut of the same material.

Why agents break your security model

The deployment-versus-readiness gap, two real incidents told as stories, and why an agent that perceives, decides, and acts with real credentials defeats perimeter thinking.

The Containment Ladder

The four rungs of agent containment, each mapped to what it stops, what it costs, and the NIS2 / EU AI Act evidence it produces. Anchored to a real multi-cluster Kubernetes deployment.

Hands-on lab: break it, then contain it

One attack chain, run twice. First it exfiltrates data through a poisoned tool description. Then the same attack is stopped by scoped permissions and a human gate. Browser-based, no setup.

The Monday-morning plan

Your team scores a real deployment during the session, pairs up on the gaps, and leaves with the first three controls to implement and a 90-day roadmap template.

Formats and pricing

One workshop, three cuts of the same material. Pick the format that fits the room.

Executive briefing

90 minutes, remote

1,500
  • Modules 1 and 2 plus a live Scorecard demo
  • For CISO, CIO, and Head of Security
  • No hands-on lab
  • Recording and Containment Ladder card
Core

Half-day workshop

4 hours, remote

2,900
  • All four modules and the full hands-on lab
  • Up to 12 participants
  • A scored Scorecard and gap list for your team
  • Participant workbook and reference cards

Private on-site

4 hours plus Q&A, at your office

4,900
€ plus travel
  • The half-day, tailored to your stack
  • Intro rebuilt from your own agent context
  • Travel billed at cost
  • Delivered on-site anywhere in the EU

Common questions

Security teams and leaders who own the risk for AI agents already in or heading to production, plus the platform and engineering leads who control agent identity and permissions. It is not for ML engineers after model internals, or teams wanting a build bootcamp.

No. The lab runs in the browser against a representative target, so no one needs to set anything up. When your team scores its own deployment, that assessment stays on your side of the table. Nothing touches production.

Honestly: the AI Act's high-risk obligations were deferred to December 2027 under the June 2026 Digital Omnibus. But the AI-literacy duty (Article 4) has applied since February 2025, and Swedish NIS2 has been in force since January 2026. The workshop maps controls to what is live now, not to a deadline that may still move.

The controls stand on their own security merit. NIS2 and the EU AI Act happen to ask for evidence of the same controls, so you get the compliance mapping for free rather than as the reason to do it.

Yes. That is the private on-site format: the intro is rebuilt around one of your own agent deployments, so the framework lands against systems your team recognizes.

Three to twelve. Small groups get more hands-on time and sharper gap discussions. Larger organizations usually split into an executive briefing plus a team half-day.

The problem

Your organization is deploying AI agents faster than security can assess them. In Cisco’s 2025 AI Readiness Index, 83% of organizations were rolling out AI agents while only 29% felt ready to secure them. The usual defenses — prompt filters, guardrails, “be careful what you paste in” — fail against injection delivered through the data an agent reads. And regulators now expect evidence that you have looked, not good intentions.

This workshop closes that gap in a single session. Your team takes one real agent or MCP deployment, runs an attack against it, then contains that same attack using controls your security program already knows how to enforce: scoping, identity, segmentation, and human approval gates.

What makes it different

Most AI security training is a jailbreak tour. Alarming, abstract, and impossible to act on come Monday. This one rests on a single thesis, drawn from running AI agents with read access across multi-cluster Kubernetes estates: prompt-level controls fail, infrastructure controls hold. The attacks are new. The durable defenses are the ones your team already understands.

That framing is the point. You leave less anxious and more equipped, because the fix is not a new security paradigm. It is applying scoping, identity, and segmentation to a system that happens to reason in natural language.

Who should attend

  • Security teams that own the risk for AI systems the business has already shipped
  • Security leaders (CISO, Head of Security) who need a framework to assess agent deployments and report on them to a board
  • Platform and engineering leads responsible for how agents get identity, permissions, and network access

Who should not

  • ML engineers looking for model internals, training, or prompt-tuning technique. This is not that workshop.
  • Teams wanting a coding bootcamp. The lab is about blast radius and controls, not building agents.

Naming who it is not for keeps the room aligned and the outcomes sharp.

Where this fits your obligations

Two obligations are already live for teams in the Nordics and the EU:

  • Swedish NIS2 (cybersäkerhetslagen, SFS 2025:1506) has been in force since 15 January 2026, putting cybersecurity risk management and incident reporting on the board’s agenda.
  • The EU AI Act’s AI-literacy duty (Article 4) has applied since February 2025, with its enforcement regime starting August 2026.

The AI Act’s high-risk system obligations were deferred to December 2027 under the June 2026 Digital Omnibus, so the pressure is less a single deadline than a standing expectation that you can show your AI systems have been assessed. The workshop maps each control back to the evidence these regimes ask for, so the session doubles as a start on that record.

Not ready to talk yet?

Free checklists, guides, and a sample assessment report. No call required.

Browse free resources →

Sounds like a fit?

A short call is usually enough to figure out whether this is what you need and what it would look like.