World Congress 2026 Europe • Jul 9, 2026 • Session details

The day the chatbot asked for sudo

Alex Olivier

When an AI agent asks for system privileges, probabilistic guardrails become useless. Learn how a zero-trust runtime layer stops prompt injections by authorizing the action, not the answer.

Pause
Mute Enter Fullscreen
#1 about 3 min

The risks of deploying untethered AI agents

How running agents under excessive user permissions creates significant security vulnerabilities.

#2 about 2 min

From read-only models to excessive agency

The transition from read-only AI applications to autonomous agents and the resulting security risks.

#3 about 2 min

The missing sandbox in current agent patterns

Why naive tool exposure models and eager autonomous modes lack essential governance and gateways.

#4 about 3 min

Four core challenges for production agents

The critical need for auditability, governance, drift control, and fine-grained kill switches in agentic systems.

#5 about 2 min

Authorizing the action instead of the prompt

Why organizations must switch from prompt engineering safety to deterministic execution constraints.

#6 about 2 min

Applying external policy to agent actions

Using external policy-based access control engines to evaluate and enforce rules on AI tooling requests.

#7 about 5 min

Reference architecture for secure agent deployments

A structured framework leveraging agent sandboxes, egress proxies, and workload identities for governance.

#8 about 5 min

Live demo: Handling support actions deterministically

How a support agent is constrained by policy to respect identity, token exchange, and tool permission scope.

#9 about 3 min

Live demo: Stopping prompt injections dynamically

Utilizing deterministic task binding and policy to prevent unauthorized actions triggered by malicious inputs.

#10 about 2 min

Surgical kill switches and forensic auditing

How externalizing policy checks enables pinpoint revocation of misbehaving agents and complete forensic trails.

#11 about 4 min

Best practices for surviving production AI

Core principles for safer autonomous systems including workload identities, step-down authorization, and task binding.

Matching moments

1:11 min

Shifting security models from passive chatbots to active agents

Péter Farkas Péter Farkas · Europe 2026 Virtual

2:28 min

Mitigating excessive agency through scoped tool access

Deepu Deepu · World Congress 2025

1:55 min

Current state of security in AI applications

Deepu Deepu · World Congress 2025

3:42 min

Securing AI agents through scoped authorization

Justin Kitagawa · Coffee With Developers

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

1:55 min

Treating autonomous agents as privileged identities requiring safety guardrails

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 5

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

September 24, 2026 · 11:00–11:30

Stage 7

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash
Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Stage 7

When Agents Became Users: Rearchitecting Identity and Permissions for AI at Scale

Yoav Gal

Product Lead

Yoav Gal
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Mainstage

I Don't Trust AI Agents (And Neither Should You): Building Production-Ready Architectures

Darko Mesaros

Distinguished Developer Advocate at AWS

Darko Mesaros
Open session

World Congress 2026 North America

September 25, 2026 · 12:20–12:50

Stage 4

Give the Agent a Budget, Not a Token

Sachin Malhotra

MTS @Anthropic

Sachin Malhotra
Open session

World Congress 2026 North America

September 24, 2026 · 09:45–10:15

Mainstage

Manufacturing trust: speed and safety in the age of agents

Mark Cavage, Michael Irwin, Hervé Bizira

Mark Cavage
Michael Irwin
Hervé Bizira