> Markdown version of [/events/world-congress-2026-north-america/sessions/1927-sandboxing-the-swarm](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1927-sandboxing-the-swarm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sandboxing the Swarm: Building Secure, Serverless AI Agents with Wasm - **Date:** Thursday, Sep 24, 2026 - **Time:** 16:10–16:40 (30 min) - **Room:** Stage 1 - **Event:** World Congress 2026 North America ## Description The true power of AI agents lies in their autonomy—their ability to reason and access internal/external tools dynamically. However, giving agents execution privileges introduces immediate security and cost vectors: prompt injection attacks escalating to host compromise, and traditional container models burning through cloud budgets on idle compute. This talk moves past naive agent sandboxing to present a zero-trust, serverless architecture built for high-concurrency agent swarms. We will examine how to bridge the gap between autonomous tool execution and strict system isolation by leveraging WebAssembly’s capability-based security model. Using CNCF Spin and Akamai Functions, we will build a globally distributed execution fabric from scratch that scales sub-millisecond workloads from zero to thousands of concurrent requests with near-zero idle overhead. We will cover technical areas like: Capability-Based Security: Replacing coarse container permissions with Wasm’s default-deny isolation to restrict agent network, memory, and filesystem access at runtime. Sub-Millisecond Execution: Bypassing Docker cold starts to spin up disposable micro-sandboxes on demand for individual tool calls and code execution steps. Globally Distributed Swarms: Edge-native orchestration patterns that keep compute close to the user while maintaining centralized policy enforcement. You will leave with a production-ready blueprint for securing autonomous workflows, turning untrusted agents from an operational risk into an auditable, deterministic asset." ## Speakers ### [Lena Hall](https://www.wearedevelopers.com/@lena-hall) Data + AI Engineer, Pragmatic AI Adoption Expert and Architect ### [Thorsten Hans](https://www.wearedevelopers.com/@thorsten-hans) Sr. Developer Advocate @ Akamai Technologies ## Related talks at this congress - [Context Engineering Kung Fu](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1410-context-engineering) — Carl Lapierre - [Context Engineering: How machines remember and forget](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1765-context-engineering) — Emre Okcular - [AI Agents are Only as Smart as their Context: Building a Real-Time Context Engine at Intuit](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1736-ai-agents-are-only) — Bharat Patel - [Proactive AI That Doesn’t Annoy Users: Building Context-Aware Notification Systems](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1672-proactive-ai-that) — Raju Dandigam Dandigam ## Watch remotely Can’t make it to San José? Watch this session live with Pro. You also get: - All full videos, bookmarks, and playlists - World Congress livestreams [See pricing](https://www.wearedevelopers.com/pricing) ## Links - [Get tickets](https://www.wearedevelopers.com/world-congress-north-america/tickets)