Deepu
Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue
#1about 4 minutes
Understanding the current state of AI security challenges
AI systems often have poor judgment, and the security domain is playing catch-up with the rapid evolution of AI agents and protocols.
#2about 3 minutes
Focusing on key OWASP Top 10 risks for developers
Application developers should focus on mitigating sensitive information disclosure and excessive agency, as these have a large attack surface under their control.
#3about 3 minutes
Why traditional RBAC fails for RAG systems
Traditional role-based access control (RBAC) is insufficient for RAG systems due to dynamic context and complex data relationships, necessitating a fine-grained authorization (FGA) approach.
#4about 5 minutes
Implementing OpenFGA to secure RAG data access
OpenFGA uses authorization models and relationship tuples to filter documents from a vector store, ensuring the LLM only receives data the user is permitted to see.
#5about 2 minutes
Mitigating excessive agency with zero trust tool access
Control an AI agent's tool access at the code level using zero trust principles, applying standard RBAC for simple cases and FGA for granular, user-dependent permissions.
#6about 1 minute
Securing third-party API calls using OAuth federation
Use OAuth 2.0 federation to allow AI agents to call third-party APIs on a user's behalf without handling raw credentials, using a broker to manage access tokens.
#7about 1 minute
Adding human guardrails with asynchronous authorization
Implement human-in-the-loop approvals for high-stakes actions by using the CIBA flow to send asynchronous authorization requests to users for confirmation.
#8about 5 minutes
Demoing step-up authorization and system architecture
A live demo showcases step-up authorization where an agent requests user consent before accessing sensitive data, followed by an overview of the application's architecture.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
14:10 MIN
Managing the fear, accountability, and risks of AI
Collaborative Intelligence: The Human & AI Partnership
37:57 MIN
Q&A on AI adoption, tools, and challenges
Navigating the AI Wave in DevOps
24:08 MIN
Practical governance and technical solutions for ethical AI
AI & Ethics
24:53 MIN
Understanding the security risks of AI integrations
Three years of putting LLMs into Software - Lessons learned
19:14 MIN
Addressing data privacy and security in AI systems
Graphs and RAGs Everywhere... But What Are They? - Andreas Kollegger - Neo4j
13:54 MIN
The ethical risks of outdated and insecure AI models
AI & Ethics
41:16 MIN
Answering audience questions on authorization best practices
Un-complicate authorization maintenance
25:30 MIN
The role of human oversight in the age of AI
Putting People at the Center: Women in Tech and the Future of Work
Featured Partners
Related Videos
GenAI Security: Navigating the Unseen Iceberg
Maish Saidel-Keesing
Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails
Alex Soto
The State of GenAI & Machine Learning in 2025
Alejandro Saucedo
The AI Security Survival Guide: Practical Advice for Stressed-Out Developers
Mackenzie Jackson
On a Secret Mission: Developing AI Agents
Jörg Neumann
AI & Ethics
PJ Hagerty
Tackling the Risks of AI - With AI
Kai Grunwitz, Klaus Bürg & Tomislav Tipurić
From A2A to MCP: How AI’s “Brains” are Connecting to “Arms and Legs”
Brad Axen
From learning to earning
Jobs that call for the skills explored in this talk.
Agentic AI Architect - Python, LLMs & NLP
FRG Technology Consulting
Intermediate
Azure
Python
Machine Learning
Security-by-Design for Trustworthy Machine Learning Pipelines
Association Bernard Gregory
Machine Learning
Continuous Delivery
Security Engineer, AI Agent Security Advanced
Google Inc
Zürich, Switzerland
Junior
Python
Network Security
Full-Stack Engineer - AI Agentic Systems
autonomous-teaming
Potsdam, Germany
Remote
Linux
Redis
React
Python
+7
Forward Deployed Engineer - AI Security (Zürich)
Lakera
Zürich, Switzerland
API
Amazon Web Services (AWS)


