Answering versus acting
Three systems built on the same language model, each asked about getting to New York on Friday evening.
Answers from memory
Answers travel questions from its training data. A person reads the answer, checks it, and acts.
An error yields a wrong sentence.
Answers with retrieval
First looks up the current timetable with a search tool. Better informed, but no more agentic in the sense that matters for risk.
An error yields a wrong, but current, sentence.
Acts
Receives the goal “book me a refundable seat to New York for Friday evening under $150”, and may search, hold, purchase, and edit the calendar.
An error yields a wrong purchase, a double booking, or a leaked payment credential.
The difference between producing an output and pursuing an outcome is the subject of this book.
Six questions no benchmark settles
Without foundations, we proceed by trial and error: expensive in any engineering discipline, and dangerous in an adversarial one. When failures are found by trial, the first to find them may be an attacker.
Resources
How should an agent spend tokens, compute, time, and human attention, and when does more reasoning, sampling, or verification pay for itself?
Security
An agent reads untrusted content while holding real permissions, and attackers write part of its input and adapt to its defenses.
Interoperability
Agents connect through protocols such as MCP and Agent2Agent. What must those protocols guarantee, and who bears the risk when a composition fails?
Governance
How are trust, accountability, and liability allocated along the chain from model developer to deployer, user, and agent?
Emergent risks
Failures that appear only at scale: correlated errors across copies of one model, cascades through pipelines, tacit collusion among pricing agents.
Agent networks
What collective behavior emerges when many self-interested agents, acting for different principals, coordinate, compete, and form coalitions?
An agent as a feedback system among principals, adversaries, and institutions
The book draws on decision theory, control, learning, game theory, and information theory, the disciplines that have long studied such systems, and connects them to the engineering of real agents and to their security, safety, and governance.
Foundations
Agents as decision-makers: how an agent decides, learns, plans, and interacts with other agents.
- Sequential decisions, MDPs, partial observability
- From reinforcement learning to foundation models
- Reasoning, planning, and control
- Game theory and strategic information
Systems
How agents are built, connected, and measured in practice.
- Architectures of LLM-based agents
- Tools, actions, environments, MCP
- Memory, knowledge, and context
- Multi-agent orchestration, evaluation, case studies
Security, Safety, and Governance
How agents are attacked, defended, overseen, and held accountable.
- Threat models and adversarial games
- Resilience, guardrails, runtime assurance
- Alignment and human oversight
- Trust, accountability, and regulation
How long can an agent run before it fails?
A long task gives an agent many chances to go wrong and, if it is well designed, many chances to put things right. After each step the agent is on track, off track but recoverable, or has failed irreversibly. The presets reproduce the book's Example 2.14 for the software engineering agent R2 over a 40-step budget.
Effective hazard – per step · long-run plateau without hazard –
Without an irreversible hazard, success plateaus at ρ/(ε+ρ). With any hazard it decays geometrically, and no amount of recovery beats the hazard. Recovery helps by shortening the time spent off track, where the hazard is high.
Three agents carried through every chapter
Each is a composite of systems described in the research literature and deployed in practice, chosen so that together they span theory, systems, and security.
Research assistant
Searches the web and scholarly databases, extracts findings, runs analyses in a Python sandbox, keeps notes across sessions, and delivers a cited report.
Stresseslong-horizon information gathering, memory, and source reliability. In the security chapters it is the canonical agent that reads untrusted content while holding private data and an outbound channel.
Software engineering agent
Explores a codebase, edits files, runs the tests in a container, iterates until they pass, and opens a pull request for human review.
Stressestool use over many steps and verification through tests. Its clear feedback signal is also a vulnerability: it can learn to make tests pass without fixing the bug.
Security operations agent
Triages alerts, queries logs and threat intelligence, correlates events into incidents, and with human approval executes containment such as isolating a host.
Stressesacting under adversarial pressure, where the attacker writes part of the input and a wrong containment action has real cost.
Three courses
Foundations of agentic AI (theory)
Chapters 1–6, 14, and 16, with Appendices A–C as background.
Building agents (systems)
Chapter 1, Sections 2.5–2.6 and 4.4, Chapters 7–13 and 15, and the labs of Appendix D.
Secure and trustworthy agents
Chapters 1, 5, 7, 8, and 13–17.
Every chapter opens with learning objectives and closes with key takeaways, notes on further reading, and exercises from proofs to programming. Prerequisites: probability, linear algebra, basic optimization, and some programming.
Build a working agent, step by step
- A minimal agent loop
- Tools and the Model Context Protocol
- Retrieval and memory
- Multi-agent debate
- Prompt-injection red teaming in a sandbox
- Building an evaluation harness
18 chapters in 3 parts, plus 4 appendices
Part I's first three chapters are available now as a free sample, together with the preface, full contents, and notation.
Part IFoundations: Agents as Decision-Makers
- 1Agentic AI: Concepts, History, and Scopesample
- 2Agents as Sequential Decision-Makerssample
- 3Learning Agents: From Reinforcement Learning to Foundation Modelssample
- 4Reasoning, Planning, and Control
- 5Multi-Agent Systems and Game Theory
- 6Information, Beliefs, and Communication
Part IISystems: Engineering Agentic AI
- 7Architectures of LLM-Based Agents
- 8Tools, Actions, and Environments
- 9Memory, Knowledge, and Context
- 10Multi-Agent Orchestration
- 11Evaluation and Benchmarking
- 12Agentic AI in Practice: Case Studies
Part IIISecurity, Safety, and Governance
- 13Threat Models for Agentic Systems
- 14Adversarial Games and Strategic Defense
- 15Resilience, Guardrails, and Runtime Assurance
- 16Alignment and Human Oversight
- 17Trust, Accountability, and Governance
- 18Open Problems and the Road Ahead
AppendicesBackground
- AProbability, Optimization, and Information Theory
- BGame Theory Primer
- CReinforcement Learning and Control Primer
- DLaboratory Exercises
Papers behind the book
- The Internet of Agentic AI: Communication, Coordination, and Collective Intelligence at ScaleQ. Zhu · arXiv:2606.12835, 2026
- Internet of Agentic AI: Incentive-Compatible Distributed Teaming and WorkflowY.-T. Yang and Q. Zhu · WiOpt 2026 · DOI
- Internet of Agentic Things: Networked AI Agents for Closed-Loop IoT OrchestrationQ. Zhu · arXiv:2607.12662, 2026
- Controlling Agentic AI: Game-Theoretic Foundations of Coordination and Competition in LLM Multi-Agent SystemsQ. Zhu · LSU Symposium on Control, Learning, and Intelligent Systems, 2026 · DOI
- Reasoning and Behavioral Equilibria in LLM-Nash Games: From Mindsets to ActionsQ. Zhu · arXiv:2507.08208, 2025
- A Variational Framework for LLM Generator-Regulator GamesQ. Zhu · arXiv:2606.18424, 2026
- Agentic AI for Cyber Resilience: A New Security Paradigm and Its System-Theoretic FoundationsT. Li and Q. Zhu · arXiv:2512.22883, 2025
- Toward Reliable Design of LLM-Enabled Agentic Workflows: Optimizing Latency-Reliability-Cost TradeoffsY.-T. Yang and Q. Zhu · arXiv:2605.23929, 2026
- Agentomics: Economic Foundations for the Valuation, Attribution, and Pricing of AI Agents in Human-AI WorkflowsQ. Zhu · arXiv:2606.14769, 2026
- Insurance of Agentic AIQ. Zhu · arXiv:2606.05449, 2026
