Abstract
As AI agents increasingly operate with system-level privileges across cloud environments, they face significant security vulnerabilities—most notably prompt injection and unauthorized command execution. With 72% of agent deployments experiencing security incidents within 90 days, there is a critical need for robust, defense-in-depth strategies. This article introduces "Bottom-Up AI Agent Security," a comprehensive 14-layer framework designed to secure AI agents from the foundation up. The strategy covers five essential domains: code-level security, container hardening, cloud IAM, runtime monitoring, and human oversight. By providing actionable implementation templates (including Java, YAML, and GitHub Actions) and a structured 4-week deployment roadmap, this framework enables cloud architects to transform vulnerable AI deployments into hardened, production-ready systems with measurable reductions in risk and operational costs.