> Markdown version of [/events/world-congress-2025/sessions/608-delay-the-ai](https://www.wearedevelopers.com/events/world-congress-2025/sessions/608-delay-the-ai). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue - **Date:** Thursday, Jul 10, 2025 - **Time:** 14:10–14:40 (30 min) - **Room:** Stage 8 - **Event:** World Congress 2025 ## Recording [Watch recording](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Description What happens when your AI agents bypass controls, abuse tool permissions, or hallucinate sensitive data from RAG pipelines? The path to an “AI Overlord” starts with one unguarded API call. In this talk, you’ll learn how to weaponize OAuth2, OpenFGA, and battle-tested authorization strategies to keep AI agents in check. We’ll cover: ✅ Role-Based Shackles: Enforce least privilege for AI toolchains using RBAC and Fine-Grained Authorization (FGA). ✅ Credential-Free Tool Calls: Fortify API integrations with OAuth2 token exchange, letting agents act on behalf of users without ever touching raw credentials. ✅ RAG Jailbreaking Fixes: Embed FGA directly into retrieval workflows to prevent agents from leaking confidential data ✅ Human Guardrails: Leverage asynchronous authorization workflows to audit high-stakes actions. Forget sci-fi doomsday scenarios—we’re tackling today’s threats. Walk away with knowledge to armor your AI agents against rogue behavior and security nightmares. ## Speaker ### [Deepu](https://www.wearedevelopers.com/@deepu) JHipster co-lead, Java Champion & Staff Developer Advocate at Okta ## Related talks at this congress - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/events/world-congress-2025/sessions/552-beyond-the-hype) — Alex Soto - [Azure AI Foundry for Developers: Open Tools, Scalable Agents, Real Impact](https://www.wearedevelopers.com/events/world-congress-2025/sessions/735-azure-ai-foundry-for) — Oliver Will - [GenAI Security: Navigating the Unseen Iceberg](https://www.wearedevelopers.com/events/world-congress-2025/sessions/515-genai-security) — Maish Saidel-Keesing - [Securing the Future: Trust, Policy, and Governance in Agentic Workflows ](https://www.wearedevelopers.com/events/world-congress-2025/sessions/777-securing-the-future) — Michael Donovan