A textbook · Manuscript, 2026

Agentic AI

Foundations, Systems, and Security

Quanyan Zhu · New York University

Artificial intelligence is moving from systems that answer to systems that act. An agent receives a goal, breaks it into steps, calls tools, reads what comes back, and keeps going, often for many steps and with real authority delegated by a person or an organization. This book builds system-scientific foundations for such agents and connects them to how agents are engineered, attacked, defended, and governed.

18chapters
3parts
6hands-on labs
~760pages
Cover of Agentic AI: Foundations, Systems, and Security by Quanyan Zhu
Chapter 1 · Example 1.1

Answering versus acting

Three systems built on the same language model, each asked about getting to New York on Friday evening.

System A

Answers from memory

Answers travel questions from its training data. A person reads the answer, checks it, and acts.

An error yields a wrong sentence.

System B

Answers with retrieval

First looks up the current timetable with a search tool. Better informed, but no more agentic in the sense that matters for risk.

An error yields a wrong, but current, sentence.

System C

Acts

Receives the goal “book me a refundable seat to New York for Friday evening under $150”, and may search, hold, purchase, and edit the calendar.

An error yields a wrong purchase, a double booking, or a leaked payment credential.

The difference between producing an output and pursuing an outcome is the subject of this book.

Why foundations

Six questions no benchmark settles

Without foundations, we proceed by trial and error: expensive in any engineering discipline, and dangerous in an adversarial one. When failures are found by trial, the first to find them may be an attacker.

01

Resources

How should an agent spend tokens, compute, time, and human attention, and when does more reasoning, sampling, or verification pay for itself?

02

Security

An agent reads untrusted content while holding real permissions, and attackers write part of its input and adapt to its defenses.

03

Interoperability

Agents connect through protocols such as MCP and Agent2Agent. What must those protocols guarantee, and who bears the risk when a composition fails?

04

Governance

How are trust, accountability, and liability allocated along the chain from model developer to deployer, user, and agent?

05

Emergent risks

Failures that appear only at scale: correlated errors across copies of one model, cascades through pipelines, tacit collusion among pricing agents.

06

Agent networks

What collective behavior emerges when many self-interested agents, acting for different principals, coordinate, compete, and form coalitions?

Three perspectives, one per part

An agent as a feedback system among principals, adversaries, and institutions

The book draws on decision theory, control, learning, game theory, and information theory, the disciplines that have long studied such systems, and connects them to the engineering of real agents and to their security, safety, and governance.

Part I · Ch. 1–6

Foundations

Agents as decision-makers: how an agent decides, learns, plans, and interacts with other agents.

  • Sequential decisions, MDPs, partial observability
  • From reinforcement learning to foundation models
  • Reasoning, planning, and control
  • Game theory and strategic information
Part II · Ch. 7–12

Systems

How agents are built, connected, and measured in practice.

  • Architectures of LLM-based agents
  • Tools, actions, environments, MCP
  • Memory, knowledge, and context
  • Multi-agent orchestration, evaluation, case studies
Part III · Ch. 13–18

Security, Safety, and Governance

How agents are attacked, defended, overseen, and held accountable.

  • Threat models and adversarial games
  • Resilience, guardrails, runtime assurance
  • Alignment and human oversight
  • Trust, accountability, and regulation
Engineering without theory gives no guarantees.
Theory without systems misses the ways real agents fail.
Neither is enough without a strategic account of adversaries and institutions.
Interactive · Section 2.5, Proposition 2.13

How long can an agent run before it fails?

A long task gives an agent many chances to go wrong and, if it is well designed, many chances to put things right. After each step the agent is on track, off track but recoverable, or has failed irreversibly. The presets reproduce the book's Example 2.14 for the software engineering agent R2 over a 40-step budget.

a wrong edit or a misread file, noticed later if at all
spots and repairs a standing error on a given step
an irreversible action even when things are going well
e.g. force-pushing over a teammate's branch while confused
–succeeds (on track at T)
–still off track at T
–failed irreversibly
–steps until success halves

Effective hazard – per step · long-run plateau without hazard –

Probability of each state by step
On track (G) Off track, recoverable (E) Failed (F)
gt+1 = (1−ε−φ)·gt + ρ·et,   et+1 = ε·gt + (1−ρ−ψ)·et,   ζ = (ρφ + εψ)/(ε + ρ)

Without an irreversible hazard, success plateaus at ρ/(ε+ρ). With any hazard it decays geometrically, and no amount of recovery beats the hazard. Recovery helps by shortening the time spent off track, where the hazard is high.

Running examples

Three agents carried through every chapter

Each is a composite of systems described in the research literature and deployed in practice, chosen so that together they span theory, systems, and security.

R1

Research assistant

Searches the web and scholarly databases, extracts findings, runs analyses in a Python sandbox, keeps notes across sessions, and delivers a cited report.

Stresseslong-horizon information gathering, memory, and source reliability. In the security chapters it is the canonical agent that reads untrusted content while holding private data and an outbound channel.

R2

Software engineering agent

Explores a codebase, edits files, runs the tests in a container, iterates until they pass, and opens a pull request for human review.

Stressestool use over many steps and verification through tests. Its clear feedback signal is also a vulnerability: it can learn to make tests pass without fixing the bug.

R3

Security operations agent

Triages alerts, queries logs and threat intelligence, correlates events into incidents, and with human approval executes containment such as isolating a host.

Stressesacting under adversarial pressure, where the attacker writes part of the input and a wrong containment action has real cost.

Using the book in a course

Three courses

Foundations of agentic AI (theory)

Chapters 1–6, 14, and 16, with Appendices A–C as background.

Building agents (systems)

Chapter 1, Sections 2.5–2.6 and 4.4, Chapters 7–13 and 15, and the labs of Appendix D.

Secure and trustworthy agents

Chapters 1, 5, 7, 8, and 13–17.

Every chapter opens with learning objectives and closes with key takeaways, notes on further reading, and exercises from proofs to programming. Prerequisites: probability, linear algebra, basic optimization, and some programming.

Appendix D

Build a working agent, step by step

  1. A minimal agent loop
  2. Tools and the Model Context Protocol
  3. Retrieval and memory
  4. Multi-agent debate
  5. Prompt-injection red teaming in a sandbox
  6. Building an evaluation harness
Contents

18 chapters in 3 parts, plus 4 appendices

Part I's first three chapters are available now as a free sample, together with the preface, full contents, and notation.

Part IFoundations: Agents as Decision-Makers

  1. 1Agentic AI: Concepts, History, and Scopesample
  2. 2Agents as Sequential Decision-Makerssample
  3. 3Learning Agents: From Reinforcement Learning to Foundation Modelssample
  4. 4Reasoning, Planning, and Control
  5. 5Multi-Agent Systems and Game Theory
  6. 6Information, Beliefs, and Communication

Part IISystems: Engineering Agentic AI

  1. 7Architectures of LLM-Based Agents
  2. 8Tools, Actions, and Environments
  3. 9Memory, Knowledge, and Context
  4. 10Multi-Agent Orchestration
  5. 11Evaluation and Benchmarking
  6. 12Agentic AI in Practice: Case Studies

Part IIISecurity, Safety, and Governance

  1. 13Threat Models for Agentic Systems
  2. 14Adversarial Games and Strategic Defense
  3. 15Resilience, Guardrails, and Runtime Assurance
  4. 16Alignment and Human Oversight
  5. 17Trust, Accountability, and Governance
  6. 18Open Problems and the Road Ahead

AppendicesBackground

  1. AProbability, Optimization, and Information Theory
  2. BGame Theory Primer

  

  1. CReinforcement Learning and Control Primer
  2. DLaboratory Exercises
Related research

Papers behind the book

  • The Internet of Agentic AI: Communication, Coordination, and Collective Intelligence at Scale
    Q. Zhu · arXiv:2606.12835, 2026
  • Internet of Agentic AI: Incentive-Compatible Distributed Teaming and Workflow
    Y.-T. Yang and Q. Zhu · WiOpt 2026 · DOI
  • Internet of Agentic Things: Networked AI Agents for Closed-Loop IoT Orchestration
    Q. Zhu · arXiv:2607.12662, 2026
  • Controlling Agentic AI: Game-Theoretic Foundations of Coordination and Competition in LLM Multi-Agent Systems
    Q. Zhu · LSU Symposium on Control, Learning, and Intelligent Systems, 2026 · DOI
  • Reasoning and Behavioral Equilibria in LLM-Nash Games: From Mindsets to Actions
    Q. Zhu · arXiv:2507.08208, 2025
  • A Variational Framework for LLM Generator-Regulator Games
    Q. Zhu · arXiv:2606.18424, 2026
  • Agentic AI for Cyber Resilience: A New Security Paradigm and Its System-Theoretic Foundations
    T. Li and Q. Zhu · arXiv:2512.22883, 2025
  • Toward Reliable Design of LLM-Enabled Agentic Workflows: Optimizing Latency-Reliability-Cost Tradeoffs
    Y.-T. Yang and Q. Zhu · arXiv:2605.23929, 2026
  • Agentomics: Economic Foundations for the Valuation, Attribution, and Pricing of AI Agents in Human-AI Workflows
    Q. Zhu · arXiv:2606.14769, 2026
  • Insurance of Agentic AI
    Q. Zhu · arXiv:2606.05449, 2026