# ON-DEMAND

## AI Agent Security Summit

## Security in the Agentic Era Starts in San Francisco

Last October's AI Agent Security Summit was the largest one to date - This May, it returned to San Francisco at a watershed moment in the AI revolution. The agentic attack surface has changed rapidly in a frighteningly short time span; the emergent risks of shadow AI, frameworks like the OWASP Top 10 for Agentic Applications, or the adoption of new open-source tools like OpenClaw have shifted the conversation. See the content from the Commonwealth Club on May 27 to catch up on what's new, what's noise, and what's next.

### What's Changed in 2026

Developments in agent adoption in the last six months have fundamentally changed the conversation around purpose-built security.

### Autonomous Security

Emergent tools like Anthropic's Claude Mythos and OpenAI's GPT-5.5 have made traditional vulnerability management roles more operational. Security practitioners and decision-makers are forced to re-think how their teams will take ownership moving forward.

[Link to post](/content/blog/the-owasp-top-10-for-agentic-applications/index.html)

### Democratized Agents

Wide spread adoption of open source programs like ClawHub allow attackers to prey on the same tools and connectors that make agents so useful. With skills becoming more useful to developers by the day, MCP servers have continued to manifest as a predominant attack surface

### Security Shared Ownership

When AI mandates come from company leadership, deployment starts in development teams, and agents start using identities and permissions of internal employees, the security responsibility no longer belongs to the SOC alone. Security leaders have to take ownership over the success and potential risk introduced by enterprise AI.

## Explore the Sessions

### Registration & Breakfast

08:45 AM – 09:30 AM

### “Mythos-ready”: On Personal Relevance and Building Security Programs

09:30 AM – 10:10 AM Ferry Track

In this talk Gadi will walk through AI security from three perspectives, the security practitioner, be it the vulnerability researcher or the CISO, the entrepreneur, creating a startup, or surviving one in the reddest blue ocean.

#### Gadi Evron

CEO and Founder, Knostic

### A Fork in the Road for Security

10:10 AM – 10:50 AM Ferry Track

Security at companies has been broken since the beginning. The status quo does not work. Is AI the tool that will finally enable security teams to win? Or will it tip us over?

#### Travis McPeak

Security Lead, Cursor

### Red, Green, Refactor, Secure: The New Loop for Building with Agents

11:05 AM – 11:20 AM Ferry Track

What if I told you that agents can produce secure, stable software?

#### Aron Eidelman

Sr. DevRel Engineer, AI Security @ Google

### Twitter Doesn't Understand Auth and Neither Does Your Coding Agent

Building agents that call APIs sounds easy until authentication breaks everything.

#### Allie Howe

Founder, Insecure Agents

### AI Gardening as a Security Discipline: Managing Context, Memory, and Entropy in Long-Running Agents

11:20 AM – 11:35 AM Ferry Track

AI agents do not usually fail all at once. They get worse over time.

#### Ishan Shah

Software Engineer, PayPal

### Red Teaming the Red Team: A Comparative Study of Autonomous AI Security Agents

11:20 AM – 11:35 AM Cable Car Track

In this session, we present a practitioner-focused comparative study of modern AI red teaming approaches across four categories.

#### Vivek Vinod Sharma

Lead AI Security Architect, Microsoft

### PromptPwnd: Prompt Injection Vulnerabilities in GitHub Actions Using AI Agents

11:30 AM – 11:45 AM Cable Car Track

Last week’s Shai-Hulud 2.0 attack demonstrated that GitHub Actions have become one of the most attractive and vulnerable entry points.

#### Rein Daelman

Security Researcher, Aikido Security

### When Green Doesn't Mean Go: How AI Skill Registries Create False Security

11:35 AM – 12:05 PM Ferry Track

AI skill registries are growing fast, and so is the assumption that the security signals displayed actually mean something.

#### Jenn Gile

Co Founder, OpenSourceMalware

### Perfectly Compliant, Completely Compromised

12:50 PM – 01:05 PM Ferry Track

This session is a live attack-to-defense demo built on OWASP FinBot CTF, demonstrating a compromised supply chain.

#### Venkata Sai Kishore Modalavalasa

Chief Architect, Straiker

### Loop, Rinse, Repeat: The Self-Amplifying Agent Attack Prompt Hardening Won't Stop

12:50 PM – 01:05 PM Cable Car Track

This talk presents findings from controlled simulation runs across two enterprise attack scenarios.

#### Chandan Vedavyas

IT Engineer, Carnegie Mellon University

### Beyond the Front Door: Securing your resources from AI Agents using Transaction Tokens

01:05 PM – 01:20 PM Ferry Track

As AI agents move from simple chatbots to autonomous orchestrators, traditional security is failing.

#### Ashay Raut

Principal Engineer, Amazon

### Verifiable Agentic Identity: Securing AI Supply Chains with SBOM and Provenance

01:05 PM – 01:20 PM Cable Car Track

This talk presents a hands-on exploration of risks in agentic supply chains.

#### Aamiruddin Syed

Senior Product Security Engineer, AGCO

### Agents vs. Scammers: Deploying Multi-Agent Systems to Infiltrate and Map Trust-Based Fraud at Scale

01:20 PM – 01:50 PM Ferry Track

We built an AI agent system that fights back on online scams by engaging in conversations with fraudsters at scale.

#### Daniel Spokoyny

CEO & Co-Founder, BeeSafe AI

### Towards Effective & Scalable Vulnerability Management with AI Agents

01:20 PM – 01:50 PM Cable Car Track

This talk presents how Lyft’s security team built an AI agent platform to automate the vulnerability triage lifecycle.

#### Aditya Dubey

Software Engineer, Lyft

### The Last Hacker Standing: Surviving the Age of AI

02:05 PM – 02:45 PM Ferry Track

This talk shows firsthand experiences with AI in the cybersecurity landscape.

#### Ben Sadeghipour (Nahamsec)

Hacker & CEO, HackingHub

### AIUC-1: The First Agentic AI Standard

02:45 PM – 03:25 PM Ferry Track

This panel explores why agentic AI demands its own security standard.

#### Chris Hughes

VP, Security Strategy

### Responding to Agentic AI Incidents: A Live Simulation

02:45 PM – 03:25 PM Cable Car Track

Participants will engage in a live simulation of an agentic AI incident.

#### Alexandra Robinson

Director - Responsible AI @ Slalom

### Cybersecurity A.M. (After Mythos)

03:35 PM – 04:05 PM Ferry Track

This session examines the implications of AI-accelerated cybersecurity.

#### Jim Reavis

CEO at Cloud Security Alliance

### No Country for Old Ideas

04:05 PM – 04:45 PM Ferry Track

This session discusses effective mitigations against current security challenges.

#### Michael Bargury

Co-founder and CTO, Zenity
