
< session />
Thu, December 10Trust, Security & GovernanceAI-Native Applications & Product Systems
In the past, software security focused primarily on securing code. AI systems introduce a different challenge: inputs can influence model behaviour in ways that affect decisions, actions, and access to information. A few lines of text hidden in an email, web page, or retrieved document can redirect a model, expose data, or influence the tools it uses.
This session begins with a review of real AI security incidents and examines where attacks occur in modern AI systems, including prompts and context, RAG pipelines, agents, and tools accessed through MCP. We will then walk through each layer of the stack and pair common attack patterns with practical, developer-focused defense-in-depth strategies.
Attendees will explore approaches such as handling untrusted retrieved content, placing guardrails around model interactions, applying least-privilege access to tools, and incorporating observability and red-teaming practices. The session is grounded in the OWASP LLM Top 10 and MITRE ATLAS frameworks and focuses on building a containment-first approach to AI security. Participants will leave with a practical understanding of how to reduce the impact of compromised prompts, tools, or identities within AI systems.
What You Will Learn:
Who Should Attend:
< speaker_info />
Brent Laster is a global trainer, author, and speaker on open-source technologies, as well as an experienced developer, manager, and director. He is also the founder and president of Tech Skills Transformations, LLC – a company dedicated to making technology understandable and usable. Throughout his career in software development and management, Brent has always made time to learn and develop both technical and leadership skills and share them with others. He believes that regardless of the topic or technology, there’s no substitute for the excitement and sense of potential that come from providing others with the knowledge they need to accomplish their goals.