The New Security Model: When Software Stops Following Instructions
About This Session
For the last thirty years, we have secured software that follows instructions. The next thirty years will be about securing software that makes decisions. That shift, from deterministic applications to reasoning, planning, tool-using agents, breaks the assumptions behind the controls we have relied on for a generation.
This keynote traces three shifts every security leader will have to reckon with. First, the security model itself is changing, because least privilege, identity, and policy were all designed for software that behaves predictably, and agents do not. Second, risk is no longer simply increasing, it is compounding, as every new tool, permission, memory source, and API multiplies the range of possible behaviors. Third, success is no longer measured by what you block, but by how safely AI completes useful work.
Along the way, we will be honest about what the industry has not yet solved, because no one has completely solved this yet. The more useful question is not which product claims total coverage, but what a credible path forward actually looks like: a move from policies to behavior, from blocking to observability, from stopping AI to helping it succeed safely. Attendees will leave with a new way to think about securing decision-making software, and a framework for evaluating where their own strategy needs to evolve. (Presented by F5)
This keynote traces three shifts every security leader will have to reckon with. First, the security model itself is changing, because least privilege, identity, and policy were all designed for software that behaves predictably, and agents do not. Second, risk is no longer simply increasing, it is compounding, as every new tool, permission, memory source, and API multiplies the range of possible behaviors. Third, success is no longer measured by what you block, but by how safely AI completes useful work.
Along the way, we will be honest about what the industry has not yet solved, because no one has completely solved this yet. The more useful question is not which product claims total coverage, but what a credible path forward actually looks like: a move from policies to behavior, from blocking to observability, from stopping AI to helping it succeed safely. Attendees will leave with a new way to think about securing decision-making software, and a framework for evaluating where their own strategy needs to evolve. (Presented by F5)
Speaker
Kunal Anand
CPO - F5
Kunal Anand leads F5 as Chief Product Officer, driving product vision, strategy, and execution to create solutions that address critical challenges and deliver exceptional customer experiences. Previously, as Chief Technology and AI Officer, Kunal defined F5’s technology and AI vision. Before F5, he was CTO and CISO at Imperva, joining through its acquisition of Prevoty, an application security startup he co-founded in 2013. Earlier, he was Director of Technology at BBC Worldwide and held leadership roles at Gravity, MySpace, and NASA Jet Propulsion Lab. With 15+ years in AI and machine learning, his expertise includes model training, employing AI algorithms, and designing AI architectures. Kunal holds a Bachelor of Science in computer science from Babson College.