World Congress 2025 Aug 20, 2025 Session details

Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue

Deepu

Are your AI agents indiscriminately leaking sensitive data across unauthorized user sessions? Discover how OpenFGA and OAuth enforce zero-trust boundaries to keep your applications from going rogue.

Pause
Mute Enter Fullscreen
#1 about 2 min

Current state of security in AI applications

Why the security domain is playing catch-up with rapidly evolving AI protocols and agent interactions.

#2 about 3 min

Top security vulnerabilities for AI applications

How prompt injection, sensitive data leakage, and excessive agency create significant attack surfaces for developers.

#3 about 3 min

Preventing sensitive information disclosure in RAG systems

Why providing dynamic retrieval-augmented generation systems access to sensitive information requires rigorous authorization models.

#4 about 2 min

Limitations of traditional access control in RAG

How dynamic context and complex relationships make role-based access control insufficient for granular AI data retrieval.

#5 about 3 min

Modeling complex permission structures with OpenFGA

Using relationship-based fine-grained access control to manage object-level permissions and complex hierarchies securely.

#6 about 4 min

Implementing OpenFGA document retrieval for AI agents

How an FGA retriever filters vector database results so language models only process authorized documents.

#7 about 3 min

Mitigating excessive agency through scoped tool access

Securing AI agent execution environments by combining zero-trust principles, role-based checks, and fine-grained authorization.

#8 about 1 min

Brokering third-party APIs with OAuth federation

Calling external services securely by using a token vault to broker and refresh federated access credentials.

#9 about 2 min

Managing asynchronous human-in-the-loop workflows for AI

Utilizing the CIBA standard to require synchronous or asynchronous user approvals before allowing AI agents to execute sensitive actions.

#10 about 5 min

Demonstrating step-up authorization and token brokering

A practical implementation showing how to enforce dynamic permissions and manage multi-platform API tokens using a managed identity provider.

Matching moments

1:10 min

Identifying emerging security vulnerabilities in generative AI agents

Alejandro Saucedo Alejandro Saucedo · WWC 2025

1:03 min

From read-only models to excessive agency

Alex Olivier Alex Olivier · WWC Europe 2026

3:51 min

Governing and auditing internal AI agents for security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

2:43 min

Setting effective guardrails for enterprise agentic AI adoption

Julia Kordick Julia Kordick · Coffee With Developers

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

3:19 min

Designing fine-grained permissions for agent interactions with financial services

Milin Desai Milin Desai +3 · WWC Europe 2026

Upcoming sessions on this topic

Open session

World Congress 2026 North America

When Agents Became Users: Rearchitecting Identity and Permissions for AI at Scale

Yoav Gal, Dor Cohen

Yoav Gal
Dor Cohen
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

Zero-Trust Architecture for Agentic AI: Securing Multi-User Access and Third-Party Integrations

Borko Djurkovic

Member of Technical Staff at Cohere

Borko Djurkovic
Open session

World Congress 2026 North America

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash
Open session

World Congress 2026 North America

Closing the Visibility Gap: Lessons from Safety Critical Agentic Systems

Vivek Pandit

Principal Engineer at Cadence

Vivek Pandit
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey