The 2026 AI Risk Summit brings together leading security practitioners, AI experts, researchers, and executives to address the most pressing challenges surrounding enterprise AI. From AI governance and security to emerging threats, regulation, and operational resilience, this year’s agenda is packed with actionable insights designed to help organizations deploy AI with confidence.

Tuesday, August 11, 2026

Move Fast and Don't Break Things: A New Model for AI Governance

(Breakfast Session)

Every enterprise wants to move faster with AI, but most governance programs slow that down because they were built for humans, not machines. AI agents act in milliseconds, often with more access than any single task requires, and most governance programs lose sight of what they’re doing once they’re running.

Companies often feel forced into a false choice: lock AI down and slow the business or move fast and lose control. The companies pulling ahead rejected that trade-off entirely. They rebuilt their controls to match the speed of AI, getting more agents into production faster, with a complete record of every action to back it up.

This session shows how, and what becomes possible when authorization stops being a policy you set once and starts keeping pace with every decision your AI makes.

Focus Track (Salon IV)
Tue 8:15 AM - 8:45 AM

Demystifying Mythos: What Anthropic's Frontier Cybersecurity Model Means for Defenders

Anthropic's Mythos-class models — first previewed in April 2026 and formally released as Claude Mythos 5 and Claude Fable 5 in June — represent a genuine step-change in AI-assisted vulnerability discovery, with Anthropic reporting the model can identify and exploit zero-day vulnerabilities in real-world software, including flaws in every major operating system and web browser. That capability jump triggered a rare sequence of events: a multi-company defensive consortium (Project Glasswing) built around the model, a brief U.S. Commerce Department export-control suspension of both Mythos 5 and Fable 5 in June, and a subsequent restoration of access on July 1 once those controls were lifted.

This session cuts through the hype and headlines to give security practitioners a clear-eyed technical and policy briefing: what Mythos actually does differently from prior-generation models, how the gated Glasswing access model and Fable's safety classifiers work in practice, what the export-control episode signals about how governments may treat future frontier models, and — most importantly — what defenders should actually be doing today given that this class of capability is coming to the broader market whether or not any single lab gates it.

Attendees will leave with insights for evaluating AI-driven vulnerability research tools, questions to ask vendors claiming "Mythos-class" capabilities, and a realistic read on the timeline before these capabilities become commoditized.

AI Risk Summit Strategy Track (Salon I)
Tue 9:00 AM - 9:35 AM

The "Privacy-Personalization" Paradox: Building Deep Memory Without Surveillance

As assistants evolve into "Personal Guardians," they require "Deep Memory" (health, calendar, family dynamics). This session introduces the framework for On-Device Sovereignty. We examine the shift toward Federated Learning and Zero-Party Data, discussing how to design assistants that act as a "privacy buffer." This is for leaders building the next generation of trusted AI companions that reason on-device rather than in the cloud.

AI Risk Summit Tech Track (Salon II)
Tue 9:00 AM - 9:35 AM

Building the Defender Advantage in an AI-First World

AI has fundamentally changed the way enterprises think about security, not just because it introduces new risks, but because it changes the speed at which everything happens. Organizations are moving beyond experimentation and into large-scale AI deployments, forcing security leaders to rethink how they protect both their environments and the AI systems running inside them.

This session explores how CISOs can build a "Defender Advantage" in an AI-first world. Drawing on conversations with large enterprises and emerging trends across the industry, Michael will discuss how AI is changing security operations, why response time is becoming the defining metric, and what security leaders should be doing today to prepare their organizations for what's next.

CISO Forum Track (Salon III)
Tue 9:00 AM - 9:35 AM

The New Fog of War: Hidden Threats in an AI-Dominant World

For most mature organizations, traditional security controls are no longer the hard part. Detection engineering, hardening, identity, cloud security, compliance, even many forms of threat hunting have become table stakes. But in an AI-dominant world, the most consequential threats increasingly emerge outside the boundaries those programs were designed to defend.

This keynote asks a more basic question: do you actually know your assets, your risks, and your boundaries? Trust underpins all three, yet most security programs still treat trust as static and well understood. AI increases speed, scale, and ambiguity, making it harder to continuously validate who belongs inside the organization, which outside relationships create exposure, and where the company’s real operational edges actually are. Most security programs are still control-led rather than threat-led: they begin with tools, telemetry, and detections instead of a clear understanding of how adversaries will exploit the seams between people, third parties, and institutional boundaries. Before you can detect or disrupt a threat, you have to know where it is most likely to form.

The central challenge for security leaders is no longer just building stronger controls. It is learning to see earlier, wider, and more clearly. This talk argues for a threat-led approach to security in which identification comes first: understanding how threat behavior is changing, where conventional programs have blind spots, and how to illuminate the hidden surfaces where the next generation of risk is already forming. In an environment shaped by AI, better security will belong to organizations that can turn threat identification into sharper judgment, faster orientation, and more decisive action before the fog closes in.

AI Risk Summit Strategy Track (Salon I)
Tue 9:35 AM - 10:10 AM

Attackers Figured Out That Your GenAI Deployment Is the Easiest Way Into Your Enterprise

For years the security conversation around AI was about how attackers would use AI as a weapon: deepfakes, automated phishing, AI-generated malware. That conversation is still valid but it is missing something. The more immediate problem is that enterprises have deployed AI systems as first-class infrastructure components, given them access to sensitive data and internal APIs, and connected them to identity systems that can reach most of the organization. That infrastructure is now an attack surface, and it is one that most enterprise security programs have not finished building controls around.

I published research on adversarial attacks against cloud AI workloads that received the Best Paper Award at IEEE ICAIC 2025. The core finding from that work and from the production security programs I run is consistent: the attack paths into enterprise AI systems are not exotic. They rely on the same principles as web application attacks from fifteen years ago, applied to an environment where the security discipline is still catching up. Prompt injection is the new SQL injection. Over-permissioned AI service accounts are the new over-privileged database users. And just like those earlier problems, the window before attackers routinely exploit these patterns at scale is closing.

This session covers the adversarial threat landscape for enterprise GenAI deployments with enough technical grounding to be actionable but framed for the risk and security leadership audience that has to make resourcing and prioritization decisions. I'll walk through the attack classes: direct and indirect prompt injection, training data extraction, model inversion, and the abuse of AI agent tool access to pivot through enterprise infrastructure. For each I'll cover what realistic exploitation looks like, what evidence it leaves behind, and what controls actually reduce the risk in enterprise environments that are already running these systems.

The second half of the session addresses the strategic question CISOs are actually wrestling with: how do you build a security program around AI systems that are changing faster than your risk assessment cycles? I'll cover the framework we use to continuously evaluate AI deployment risk, the metrics that matter for board reporting, and the organizational changes that separate enterprises that are managing AI risk from enterprises that are hoping nothing goes wrong.

The organizations in this room are past the question of whether to deploy AI. The question now is how to do it without handing attackers a new category of access to everything you've spent years trying to protect.

Attendees will leave with an adversarial threat model for enterprise GenAI, a prioritized set of controls mapped to realistic attack paths, and a framework for continuous AI risk assessment that keeps pace with deployment velocity.

AI Risk Summit Tech Track (Salon II)
Tue 9:35 AM - 10:10 AM

Chain-of-Thought Monitorability in AI Governance

If you’ve been anywhere near modern AI research lately, you’ve probably heard people buzzing about Chain of Thought (CoT). It's the idea that advanced AI models don’t just spit out an answer—they produce a whole internal reasoning trail behind it. Think of it as the AI’s scratchpad or its inner monologue. And monitoring that monologue? That’s the new frontier of AI safety.

As AI systems evolve from predictive models to reasoning-driven agents, traditional governance approaches—focused primarily on outputs and outcomes—are becoming increasingly insufficient.

This presentation introduces Chain-of-Thought (CoT) Monitorability as an emerging and critical capability for strengthening AI risk management, particularly in high-stakes environments such as financial services.
Modern reasoning models generate intermediate deliberations before producing final outputs. These reasoning traces offer a partial but valuable window into how models arrive at decisions, enabling earlier detection of risks such as reward hacking, hidden policy violations, or deceptive behavior that may remain invisible in output-only evaluations. CoT monitorability shifts oversight from evaluating what a model produces to understanding signals about why the model behaves as it does.

The presentation outlines a practical governance framework to operationalize CoT monitorability within existing Model Risk Management (MRM) and AI governance programs. Key elements include:

Treating monitorability as a distinct, measurable risk attribute alongside accuracy, bias, and robustness
Classifying models based on whether they exhibit reasoning behavior
Implementing structured monitorability evaluations (intervention, process, and outcome-based approaches)
Integrating monitorability insights into risk-informed deployment decisions
Establishing continuous tracking to detect degradation over time

Attendees will also gain clarity on where CoT monitoring adds meaningful value—such as in agentic workflows, fraud detection, and AI-assisted decision support—and where it may be insufficient or misleading. Practical implementation considerations around cost, accountability, and integration into governance processes will be discussed, including the trade-offs associated with increased reasoning visibility.
The session concludes with key guardrails to prevent over-reliance on reasoning traces and emphasizes the urgency of adopting monitorability frameworks while the current “window of visibility” remains open.
This presentation is designed for AI governance leaders, model validators, and risk professionals seeking to evolve their oversight frameworks to address the unique challenges posed by next-generation reasoning systems.

CISO Forum Track (Salon III)
Tue 9:35 AM - 10:10 AM

When Trust Has No Security: AI Risks Everything

Organizations are deploying AI systems that are fully compliant :SOC 2, HIPAA, ISO 27001, GDPR, ect and are still fully exposed. This talk dismantles the illusion that traditional security controls and compliance frameworks protect AI models, walking through a real-world attack chain that compromises a healthcare AI assistant in under two hours through nothing more than a hidden prompt injection.

Drawing on universal jailbreak techniques that bypass safety alignment across every major LLM, Harkins introduces the "Irrefutable Laws of Securing AI" and the 9-Box of AI Trust & Security framework, reframing the problem from probabilistic risk to deterministic exposure: if a model is exploitable, compromise is a matter of when, not if.

Attendees will leave with an understanding for closing the gap between AI that is well built, well run, and genuinely trustworthy.

AI Risk Summit Strategy Track (Salon I)
Tue 10:10 AM - 10:45 AM

License to Govern: The Counterintelligence Playbook for AI Security

Every organization thinks it has a James Bond security program. Sophisticated. Equipped. Ready for catch villains as soon as they break in.

The problem: today's threats don't break in. They already have a badge. They were credentialed by your own people, with good intentions, but without the knowledge or approval of the security team. Today’s threats look exactly like allies until they don’t.

Meet the three double agents already inside your organization: the Ghost (Shadow AI), the Mole (AI Agents), and the Sleeper (OAuth Tokens). Each credentialed. Each trusted. Each passing data through pathways your security team can't see.

Through real breach stories from Salesloft Drift, Vercel, and Klue, this session builds the case for AI Governance as a counterintelligence program — not a security product. The organizations who invest now in building this program will be in a much different place in 18 months than those who don’t.

Your workforce is the intelligence network. Enlist it in the mission.

AI Risk Summit Tech Track (Salon II)
Tue 10:10 AM - 10:45 AM
  • Leah Siskind Director of impact and AI research fellow - Foundation for Defense of Democracies

Iran Tested It First: What State-Sponsored Deepfakes Mean for Every CISO in the Room

Over the course of the 2026 war with Iran, hundreds of unique AI-generated deepfakes pushing pro-Iran narratives have been identified. Fake missile strikes, fabricated battlefield victories, synthetic news broadcasts, AI-generated images confirmed by Google's own watermarking tool, and a video that hit 70 million views before anyone traced it to a military video game. The volume wasn't an accident. It was the strategy. The goal isn't to make you believe any single fake. It's to make you doubt everything you see. This is the liar's dividend — and it isn't staying in the Middle East.

State actors are running the world's most sophisticated adversarial AI lab, and enterprise security teams are the next target. Drawing on original research from the Foundation for Defense of Democracies, this talk examines how Iran, Russia, and China have developed distinct but mutually reinforcing roles in AI-enabled influence operations: Iran as the content lab, Russia as the amplification infrastructure, and China as the precision targeting engine. The tactics being refined against governments and militaries today become commodity tools available to criminal enterprises within months, not years.

This talk goes beyond threat awareness. Attendees will leave with a clear-eyed view of where platform detection is failing — Meta's metadata-only gaps, Grok's contradictory deepfake assessments, Google AI summaries validating disinformation — and what those failures reveal about enterprise defense posture. FDD's research goes deeper still, including original work on how authoritarian propaganda patterns are baked into the LLMs your organization already relies on. The national security intelligence is the early warning. The enterprise implications are the talk.

Leah Siskind is an AI Fellow and Director of Impact at FDD's Center on Cyber and Technology Innovation, a veteran of the U.S. Digital Service in the White House and DHS AI Corps, and a recognized voice on adversarial AI. She has written on deepfakes for The Cipher Brief, The National Interest, and has spoken on the topic on Fox News, including on the Brian Kilmeade Show and Fox News Live.

CISO Forum Track (Salon III)
Tue 10:10 AM - 10:45 AM

Rethinking AI Risk Management as an Enabler

Effective governance should accelerate, not hinder, AI adoption.

This session asserts that well-architected risk management does not have to be a barrier for an enterprise, but can instead be the very mechanism that enables a business to move faster, in a secure way. This session will explore how current practices, particularly in Third-Party Risk Management (TPRM), often reveal contradictions: rigorous evaluation frameworks are bypassed when speed is prioritized, exposing a gap between stated risk tolerance and actual behavior.

Additionally, this presentation will highlight the critical but under-examined tradeoff between time investment and risk severity: evaluating whether exhaustive assessments truly reduce AI and security risk.

Attendees will learn:
- Why traditional risk management approaches unintentionally slow AI adoption (and how to fix that)
- Where dread risk and the investigatory reflex impact security decisions around AI
- How cognitive biases like loss aversion, target fixation and salience bias distort AI risk decisions, specifically among security leaders
- A practical method for aligning evaluation effort with actual risk (time and impact evaluated)
- Why assigning clear risk ownership is critical for both speed and accountability

AI Risk Summit Strategy Track (Salon I)
Tue 11:00 AM - 11:30 AM

When AI Coding Agents Become an Attack Surface: Lessons from Claude Code RCE Research

AI coding agents like Claude Code, Cursor, and Gemini CLI are moving from autocomplete into autonomous development workflows, where they can read code, run commands, use tools, and interact with cloud environments. In this session, Mahesh Babu (Kodem) will share lessons from newly disclosed Claude Code remote code execution research presented at RSAC 2026, building on earlier work around denial-of-service and permission escape. We will explain how these risks show up in real developer environments, why agent autonomy changes traditional application security assumptions, and what practical controls security teams should consider as these tools enter the enterprise.

AI Risk Summit Tech Track (Salon II)
Tue 11:00 AM - 11:30 AM

Trustworthy AI in Healthcare: Defending the New Attack Surface

Tagline : From deepfakes to data leakage—how CISOs build AI that’s safe, compliant, and resilient.

Healthcare is adopting AI fast—virtual agents, analytics, automation—but that also creates a brand-new attack surface: adversarial prompts, deepfakes, model and data poisoning, and high-impact failures that can erode patient trust overnight. In this session, I’ll share a CISO’s practical playbook for securing AI in healthcare: governance aligned to NIST AI RMF and ISO/IEC 42001, protecting PHI in AI/ML pipelines, building an AI integration roadmap that doesn’t slow innovation, and operationalizing “AI for defense” to strengthen detection and response. You’ll leave with a clear framework to reduce risk, meet regulators where they are heading, and confidently scale AI in regulated environments.

CISO Forum Track (Salon III)
Tue 11:00 AM - 11:30 AM

The Shadow Risk Problem: Governing Security Exceptions in AI-Driven Systems

Security programs increasingly rely on exceptions, waivers, and risk acceptances to keep critical systems running under tight delivery timelines. But in AI‑driven and highly automated environments, these exceptions create shadow risk—hidden exposures that are rarely tracked or governed. A clear example is the Chevrolet dealership incident, where a ChatGPT‑powered chatbot was tricked into “agreeing” to sell a $60,000+ SUV for $1 through simple prompt‑injection, due to missing guardrails and uncontrolled overrides. This real‑world failure shows how unmanaged exceptions in AI systems can quickly escalate into operational, reputational, and security threats

AI Risk Summit Strategy Track (Salon I)
Tue 11:30 AM - 12:00 PM

KV-Cache as Attack Surface: Side Channels in Shared LLM Inference Infrastructure

Most people think about LLM security at the prompt level. What goes in, what comes out. But there's an entire layer underneath, the KV-cache, and it has some properties that should make anyone running shared inference infrastructure genuinely uncomfortable.

Here's the problem: when a transformer model processes text, it doesn't recompute everything from scratch every time. It caches intermediate computations, the key-value pairs from the attention mechanism, so it can reuse them for efficiency. That's great for latency and cost. It's less great when multiple tenants share the same inference hardware, because those cached states don't always get cleaned up the way you'd expect.

This talk is about what happens in that gap.

We'll get into the mechanics of how KV-caches work, why they exist, and specifically where the isolation assumptions break down in multi-tenant deployments, including managed API services, on-premise inference clusters running vLLM or TensorRT-LLM, and enterprise platforms built on shared GPU pools. Then we'll look at timing-based techniques that let an observer on the same infrastructure infer whether specific content was recently processed, without ever seeing the content directly. If that sounds like a classic cache side-channel attack, that's because it is. The underlying physics haven't changed just because the workload is now a 70-billion parameter language model.

We'll walk through a concrete demonstration on a locally hosted open-weight model, nothing proprietary, nothing that requires a vendor's cooperation to reproduce. The goal is to show this isn't theoretical. It's measurable, it's repeatable, and the conditions for it exist in a lot of production deployments right now.

The second half of the talk pivots to what you can actually do about it. Cache partitioning, flush policies, inference isolation architectures, and, importantly, what questions to ask your infrastructure vendor or cloud provider, because most of them haven't published answers to these questions yet.

AI Risk Summit Tech Track (Salon II)
Tue 11:30 AM - 12:00 PM

When AI Goes Wrong: A Practical Framework for Ethical Decision-Making in Rogue and Failing AI System

As AI systems move into high-stakes enterprise and societal decisions, failures are no longer hypothetical—they are inevitable. Yet most organizations are unprepared to respond when AI systems behave unpredictably, produce harmful outputs, or operate outside intended constraints.

This session introduces a novel, practitioner-driven framework for managing AI failures and “rogue AI” scenarios through structured ethical decision-making. Rather than focusing on abstract principles, we present a real-world operational model that helps organizations detect, assess, and respond to AI failures in real time.

At the core of this session is the “Ethical Failure Response Model (EFRM),” a decision framework that integrates risk severity, stakeholder impact, reversibility, and system autonomy into a clear response strategy. Attendees will learn how to classify AI failure modes—including hallucinations, adversarial manipulation, emergent behaviors, and model drift—and apply appropriate containment and remediation actions.

We will also explore the emerging concept of “ethical blast radius,” helping leaders quantify the downstream impact of AI failures across customers, employees, and regulatory exposure. Through realistic scenarios, we will demonstrate how organizations can balance speed, accountability, and transparency when responding to AI incidents.

Key takeaways:

* A structured taxonomy of AI failure and rogue behavior patterns
* The Ethical Failure Response Model (EFRM) for real-time decision-making
* A practical method to quantify ethical and reputational impact (“blast radius”)
* Governance patterns for incident response, escalation, and auditability

This session is designed for CISOs, risk leaders, AI engineers, and product executives who need actionable strategies to manage AI failures responsibly—before they become organizational crises.

CISO Forum Track (Salon III)
Tue 11:30 AM - 12:00 PM

Beyond Vibes: Evaluation Strategies for Safe Multi-Turn AI Agents

Evaluating whether an AI agent completes a task is hard. Evaluating whether it does so safely is harder — and most teams have no systematic way to catch failures before users do. What breaks when you try to measure safe behavior across multi-step, non-deterministic agent workflows? Why aren’t classic eval pipelines built for this? And what practical evaluation strategies actually work? This talk tackles all three, offering concrete patterns — from trajectory-level assertions to adversarial scenario generation to safety-aware scoring rubrics — for teams shipping agents today. Drawing on experience building LLM evaluation frameworks and production safety systems at scale, we go beyond surface-level pass/fail metrics to show how you can build real, repeatable confidence that your agent is behaving as intended.

AI Risk Summit Tech Track (Salon II)
Tue 12:00 PM - 12:30 PM

AI at the Edge of Trust: Securing the Next Wave of Enterprise Intelligence

AI is reshaping enterprise operations while introducing new security risks, from model manipulation and data exposure to adversarial attacks and autonomous agent behavior. As organizations scale AI across endpoints, cloud, and edge, CISOs must rethink how trust, data integrity, and system control are established and maintained.

This session examines practical approaches to securing AI-enabled environments, including governance and monitoring of AI agents as they take on decision-making roles. Topics include safeguarding data pipelines, ensuring verifiable system integrity, and managing risks introduced by autonomous actions.

The discussion will focus on emerging security patterns and lessons from across the industry, highlighting how leaders are balancing innovation with risk—implementing guardrails, aligning to evolving regulations, and preparing for a future where AI systems must be both trusted and continuously verified. (Presented by Intel)

CISO Forum Track (Salon III)
Tue 12:00 PM - 12:30 PM
  • Anna Dudley Principal Advisor for Special Projects - Altamira Corporation

Red-Teaming Generative AI at Scale: The $14B Hallucination Scenario

Topic: Red-Teaming Generative AI at Scale: The $14B Hallucination Scenario
Format requested: 45-minute interactive workshop (talk + hands-on red-team exercise + Q&A)
Track fit: Adversarial AI & Deepfakes; AI Failures and Rogue AI Mitigation; National security implications
Author: Anna R. Dudley

Generative Artificial Intelligence (AI) has crossed from interesting tool to load-bearing infrastructure. Banks use it to draft credit memos. Intelligence shops use it for first-draft assessments. Law firms use it for discovery review. The failures that matter are no longer cosmetic. They are operational, and they cascade.

This 45-minute interactive workshop walks security and risk practitioners through one fully developed adversarial scenario: a confident hallucination, propagated through automated downstream systems, that produces a $14 billion exposure event before any human catches it. Attendees see the failure unfold across three layers and trace which controls would have caught it at each stage.

1. Model output
2. System integration
3. Human review

The methodological backbone is Cross-Validated Red Cell: a substantially rebuilt contrarian technique that combines adversarial Machine Learning (ML), Monte Carlo simulation over evidence, and adversarial-injection modeling to attack AI-assisted analysis where it is structurally vulnerable. It is one of four redesigned Structured Analytic Techniques (SATs) for the generative era all anchored in the Analyst-in-the-Loop AI (AITL) principle: AI surfaces, analyst decides.

Attendees leave with a five-step Monte Carlo red-team protocol they can run on any generative-AI deployment in their organization, a taxonomy of three operational failure modes (Plausible-Sounding Synthesis, Confident Hallucination, Source Traceability Collapse), and a worked artifact that converts model output into something a risk committee can interrogate.

AI Risk Summit Strategy Track (Salon I)
Tue 1:30 PM - 2:15 PM
  • Millie Huang Principle Data Scientist, Detection and Response - Salesforce

Stopping Rogue Agents in Flight: Real-Time Detection and Autonomous Containment for Enterprise AI

A compromised AI agent can execute ten irreversible tool calls in the time it takes a security log to reach your SIEM. By the time an analyst sees the alert, the data may already be gone.

At Salesforce, we defend large-scale autonomous agent deployments across thousands of organizations and millions of daily prompts. At AI Risk Summit 2025, I shared how we detect rogue agent behavior using unsupervised ML and engineered behavioral features over production telemetry. This year, I cover what comes next: detection alone is not enough.

This talk presents a runtime detection-and-response architecture for enterprise AI agents: an inline security service that subscribes to the agent event stream, scores each action against behavioral baselines in real time, and emits containment signals before the agent takes its next step.

The talk walks through the response taxonomy — session termination, per-tool restriction, retrieval redaction, step-up authentication, throttling, and egress blocking — and the hard part: deciding when each action should fire without creating more damage than the attack itself. Expect specifics on what broke, what remains unsolved, and the architectural tradeoffs every team deploying AI agents will eventually face.

Attendees will leave with a runtime detection-and-response reference architecture, a containment-action taxonomy ranked by blast radius and reversibility, and an opinionated deployment checklist to apply before their next agent ships.

AI Risk Summit Tech Track (Salon II)
Tue 1:30 PM - 2:15 PM

[Panel] Metrics That Matter: Translating Cyber Risk for the Board of Directors

The role of the CISO has fundamentally shifted from technical gatekeeper to strategic business leader. As regulatory scrutiny increases and cybersecurity becomes a central pillar of corporate risk, the ability to communicate effectively with the Board of Directors is paramount. This panel focuses on moving away from dense, technical metrics (like "number of attacks blocked") and mastering the language of business risk, financial impact, and strategic ROI.

CISO Forum Track (Salon III)
Tue 1:30 PM - 2:15 PM

[Intel Executive Roundtable] Future-Proofing Enterprise Security: Lessons from the CISO Frontline

In an environment defined by rapid technological change and expanding risk, CISOs are re-evaluating how security is designed, deployed, and measured. This private roundtable provides a forum for candid discussion among security leaders on emerging priorities—from AI risk and platform security to simplification and resilience.

Intel will facilitate an open dialogue to capture frontline insights, validate key trends, and explore how platform innovation can better align with enterprise security needs—helping shape the next generation of trusted computing.

Focus Track (Salon IV)
Tue 1:30 PM - 3:00 PM

Shadow AI and Third-Party Risk: Closing the Governance Gap

When an employee pastes sensitive data into ChatGPT, they have introduced an unvetted third party into your data environment with no contract, no assessed controls, and no exit plan. Responsibility for that risk is rarely assigned and often contested across TPRM, Security, Legal, and Privacy functions, leaving a meaningful gap in enterprise risk management programs that were never designed to see it.
This session reframes shadow AI as a governance and third-party risk problem rather than a behavior problem. Drawing on field observations and a practical maturity model, attendees will examine how to incorporate shadow AI into existing enterprise risk frameworks, why current standards including NIST AI RMF, ISO 42001, and Shared Assessments leave a structural gap, and what cybersecurity and governance strategies close it.
Attendees leave with a structured self-assessment, a cross-functional ownership model, and a prioritized action plan for integrating shadow AI risk into the enterprise risk management lifecycle.
Learning Objectives:
1. Explain why shadow AI creates a structural gap in existing TPRM and enterprise risk programs
2. Assign ownership using a practical cross-functional RACI model aligned to cybersecurity strategy
3. Use a structured self-assessment to evaluate maturity and prioritize control activities

AI Risk Summit Strategy Track (Salon I)
Tue 2:15 PM - 2:45 PM

A Deep Dive into Model Context Protocol (MCP) Security

As AI systems become more powerful and context-aware, ensuring secure and reliable interaction with Large Language Models (LLMs) is paramount. Model Context Protocol (MCP) introduces a standardized interface that governs how models are prompted, contextualized, and deployed in real-world applications.

This session explores the emerging security landscape of MCP, covering the potential risks introduced by context injection, prompt leakage, prompt chaining abuse, and data exfiltration through contextual inputs. Attendees will learn best practices for hardening MCP implementations across enterprise LLM stacks—whether proprietary or using API-based access like OpenAI, Anthropic, or Cohere.

From input validation and sandboxing to contextual trust boundaries, this session offers a strategic and technical roadmap to secure LLM interactions using MCP.

Key Takeaways:

* Understand the structure and components of the Model Context Protocol (MCP)
* Explore key threat vectors in context-driven LLM workflows
* Learn security best practices for MCP usage, including prompt hygiene, red teaming, and audit logging
* Dive into real-world attack scenarios such as indirect prompt injection and model manipulation via context chaining
* Recommendations for integrating MCP with existing AppSec and SOC workflows

Prerequisites:

Familiarity with Large Language Models, AI security principles, and API-based architecture.

AI Risk Summit Tech Track (Salon II)
Tue 2:15 PM - 2:45 PM

The Underwriter in the Room: How Cyber Insurers Are Already Scoring Your AI Program

Most CISOs know AI introduces new risk. Far fewer know they're already being evaluated on it, or that the evaluation is happening quietly, every insurance renewal cycle, by people who set your premiums and write your policy exclusions.

Cyber insurance underwriters are rapidly building AI-specific risk assessment frameworks. They’re asking new questions, pulling new signals, and increasingly categorizing enterprise risks into preferred, standard, and high-risk AI tiers. The decisions they're making are affecting coverage availability, pricing, and even whether a claim gets paid when something goes wrong.

This session gives enterprise security and risk leaders an inside look at how AI programs are actually being underwritten today.

Drawing on data from CyRisk’s AI risk analytics platform used by cyber insurers to assess organizational AI posture at scale, attendees will learn which AI governance controls underwriters weight most heavily, which gaps trigger sublimits and exclusions, how agentic AI deployments are changing the assessment picture, and how to use the insurance market’s emerging AI pricing signals as a practical benchmark for your own risk quantification.

A key theme is how underwriting criteria both align with and diverge from familiar frameworks like NIST AI RMF and the EU AI Act. Where NIST and the Act define what good governance looks like in principle, insurance underwriting criteria are calibrated by actual loss data. They reflect what has already gone wrong and what it cost. The result is a more adversarially grounded view of AI risk that cuts through compliance theater and surfaces the controls that matter when a claim is on the table.

Attendees will leave with a concrete, insurer-tested framework for evaluating their AI program. One that satisfies both the boardroom and the underwriter, and that holds up when a loss actually occurs.

CISO Forum Track (Salon III)
Tue 2:15 PM - 2:45 PM

5 Pillar Framework for Building an Enterprise AI Agents Governance and Security Program

Enterprises are deploying AI agents faster than any governance framework was designed to handle. AI agents make decisions, take actions, and interact with live enterprise systems in ways that are non-deterministic, difficult to audit, and rarely tied to a clear accountable owner.

The result is a governance vacuum. Security teams are responsible for the perimeter but not the agent. Legal owns data compliance but didn't approve the agent's tool access. Business units deployed the agent but don't monitor what it does post-launch. And when something goes wrong, a data leak, an unauthorized transaction, a compliance violation, nobody can reconstruct what the agent did, why, or on whose authority.

This session presents a practical enterprise governance framework built specifically for AI agents, designed from the ground up for the operational reality of autonomous systems acting inside corporate infrastructure.

This session introduces a 5-pillar governance framework built ground-up for agentic AI in enterprise environments, developed from real-world deployments and security incidents across industries.

AI Risk Summit Strategy Track (Salon I)
Tue 2:45 PM - 3:15 PM

Closing the AI Visibility Gap: Why SBOM Alone is No Longer Enough

The shift toward Software Bill of Materials (SBOM) and its extension, the Artificial Intelligence Bill of Materials (AIBOM), is a fundamental change in how we manage risk, security, and compliance in the modern digital world. As an organization, adopting both of these frameworks doesn't just check a box, it provides a crucial, non-negotiable layer of transparency that is essential for both operational excellence and legal defense.
In short, SBOM gives you a complete, structured inventory of the code and libraries in your software, allowing for fast vulnerability response and license management. AIBOM takes this concept further, providing an inventory of the non-code components of an AI system, the models, training data, and configurations, to manage risks unique to artificial intelligence like bias, data leakage, and adversarial attacks.

AI Risk Summit Tech Track (Salon II)
Tue 2:45 PM - 3:15 PM

AI Agent Governance for Risk Leaders: Lessons from the Frontlines

As enterprises rapidly transition from passive LLM chatbots to autonomous AI agents capable of executing multi-step business tasks, risk leaders face an entirely new paradigm of operational danger. Unlike static models, autonomous agents have the authority to act—calling APIs, querying databases, and modifying corporate environments. Knowing how to establish guardrails without halting business innovation has left many security leaders paralyzed. This session cuts through the hype, delivering hard-learned lessons and actionable insights gathered directly from the frontlines of enterprise AI deployment and incident response.

Moving past theoretical frameworks, this talk addresses the real-world friction points keeping leadership up at night: privilege creep, "black box" execution pathways, and the rise of shadow agent deployments by business units. Attendees will learn how organizations are successfully balancing innovation and risk, exploring practical strategies to safely enable these high-productivity tools without inadvertently opening a backdoor to enterprise data assets.

Key areas covered include:
- The Agentic Risk Landscape: A frontline analysis of the unique security, compliance, and operational risks introduced when autonomous agents are granted execution capabilities.
- The Governance Blueprint: Core pillars for establishing operational guardrails, creating cross-functional oversight, and integrating agentic threat modeling into existing enterprise risk management frameworks.
- Real-World Case Studies: Lessons learned from early enterprise deployments, highlighting both rapid business wins and overlooked security gaps that led to live incidents.
- Securing the Ecosystem: High-priority technical and procedural controls to secure the AI agent lifecycle without degrading model performance.

CISO Forum Track (Salon III)
Tue 2:45 PM - 3:15 PM

Chaos Testing for Chatbots: Simulating Customers to Evaluate AI Agents

Most conversational AI demos look great in single-turn prompts. But real customers don’t behave like prompts: they interrupt, change goals mid-way, provide incomplete information, and ask follow-ups that force the system to stay consistent across multiple steps.

In this session, I’ll share how we built an AI Simulator to evaluate multi-turn conversational systems in a realistic way. Instead of testing a chatbot with isolated prompts, we simulate complete customer journeys, troubleshooting flows, account issues, configuration tasks and automatically measure task completion, correctness, and recovery behavior when the agent makes mistakes.

You’ll learn how multi-turn simulation exposes failure modes that traditional evaluation misses (wrong tool usage, premature answers, policy violations, drift across turns, and “confidently wrong” resolution). We’ll cover the design of customer personas, scenario templates, success criteria, and how to turn simulation results into a production-grade metric suite that enables regression testing and reliable iteration.

If you're building agents, RAG assistants, or support chatbots, this talk will show you how to evaluate them like real systems, not like demos.

AI Risk Summit Strategy Track (Salon I)
Tue 3:30 PM - 4:00 PM

Preventing Excess Agency: Architecting Secure, Skill-Scoped Runtimes for Enterprise AI Agents

As enterprises transition from simple chat assistants to autonomous agentic workflows, they face a critical security paradigm shift: the separation of "the brain" (cognitive LLMs) from "the hands" (execution environments). In this session, we will dissect the emerging security risks of the "agent skills" ecosystem—modular, reusable bundles of prompt context and executable scripts.

While frameworks have made agent building highly approachable, they introduce severe vulnerabilities. If an agent executes a poorly sandboxed script, a single prompt injection can compromise database credentials, mutate external systems, or trigger malicious system commands. We will explore a modern, secure architecture that solves "the excess agency" problem. Attendees will learn how to design a zero-trust runtime that isolates execution sandboxes, enforces principle-of-least-privilege on a per-tool/per-skill basis, and safely implements model-agnostic control planes in heavily regulated enterprise environments.

Key Learning Objectives for Attendees:
Understand the Anatomy of the Agent Harness: Learn how to isolate the agent runtime control plane from the untrusted sandboxes where model-generated code actually executes, ensuring sensitive credentials are never reachable by the model's environment.

Implement Skill-Scoped Security Policies: Discover how to declare network and file-system dependencies in declarative manifests (such as the open agentskills.io standard) to prevent high-trust database tokens from leaking into low-trust API integrations.

Mitigate Enterprise Scale Multi-Tenancy Risks: Analyze the structural, performance, and security trade-offs of always-on containers versus dynamic, on-demand execution sandboxes.

AI Risk Summit Tech Track (Salon II)
Tue 3:30 PM - 4:00 PM

Why Responsible AI is a Hard Data Engineering Problem (Not a Legal Checklist)

While enterprise leaders are eager to unlock the velocity of generative AI and autonomous agents, deployment frequently stalls at the governance layer due to concerns over data hallucinations, compliance risk, and unverified automated actions. The industry has spent significant cycles treating "Responsible AI" as an abstract ethical policy. In a production B2B environment, it is fundamentally an infrastructure architecture challenge.

This session bypasses the high-level policy hype to deliver a battle-tested, vendor-neutral blueprint for building deterministic validation and risk mitigation frameworks directly into the enterprise data layer.

CISO Forum Track (Salon III)
Tue 3:30 PM - 4:00 PM

Wednesday, August 12, 2026

Morning Keynote

AI Risk Summit Strategy Track (Salon I)
Wed 9:00 AM - 9:35 AM

Ignore Previous Instructions: Offensive Intelligence for the AI Era

We keep trying to secure AI the same way we secure software, and that assumption is already costing us.

Modern AI systems don't behave like traditional applications. They write code, call tools, chain decisions, and interact with the world with increasing autonomy -- and most organizations are still spending their time trying to control what the model says. That's not where the bodies are buried.

David Campbell spent three years red teaming AI systems across enterprise and government environments, and the same pattern shows up every time. The interesting failures aren't in the model. They emerge in everything built around it.

These systems expose a different kind of attack surface: agents with delegated authority, tool sprawl across environments, workflows that drift from read to action, memory and context that outlast any single session. This talk walks through how those surfaces get exploited.

We'll look at real adversarial scenarios. How a benign prompt that becomes an action chain, a low-privilege interaction that escalates through tool access, an agent that routes around intended controls without touching a traditional vulnerability, "allowed behavior" that becomes the attack path.

To make sense of why this keeps happening, Campbell uses a simple frame: behavior, identity, and control. The industry is obsessed with behavior. Attackers aren't. They're going after authority and the absence of meaningful control around it.

What that produces is a class of systems that don't need to be broken in order to be exploited. They only need to be used as designed.

'Ignore previous instructions: Embracing AI Red Teaming' was so three years ago, this is a talk about how AI systems actually get hacked.

AI Risk Summit Tech Track (Salon II)
Wed 9:00 AM - 9:35 AM

Balancing Innovation and Control: How to Scale AI Safely Across the Enterprise.

As organizations scale AI rapidly, the challenge is no longer adoption—but managing risk without slowing innovation. This session explores how to embed governance, accountability, and practical guardrails into the AI lifecycle, enabling leaders to accelerate value creation while maintaining trust, compliance, and resilience. It will highlight practical concepts from operational risk lens, including risk-based use case tiering, clear ownership and human-in-the-loop controls, and embedding governance across the AI lifecycle to ensure transparency, accountability, and rapid intervention when needed. Attendees will gain actionable guidance on operationalizing AI governance to accelerate value creation while maintaining trust, compliance, and enterprise resilience.

CISO Forum Track (Salon III)
Wed 9:00 AM - 9:35 AM

Breaking the Sound Barrier: End-to-End Red Teaming for AI Voice Agents

AI voice agents are a lot like their text-based counterparts. Helpful, deliberate, and vulnerable. As voice becomes a more prominent modality for user interaction and enterprise product capabilities, safety and security testing lags far behind. Voice introduces novel attack surfaces and the practical challenges of automating audio make it difficult to efficiently scale testing.

Voice agents built on speech-to-text pipelines inherit the vulnerabilities of their text-based counterparts, but introduce new attack surfaces at the transcription layer: acoustic adversarial inputs, prosody manipulation, and exploitable gaps between what a human hears and what the system transcribes. Native audio models present a different risk profile, processing speech without an intermediate text representation and creating attack vectors at the layer of sound.

Automating voice agent testing is practically harder than text. Full pipeline testing requires generating adversarial audio inputs programmatically, handling spoken latency and interruptions, and achieving meaningful coverage across languages and dialects. These challenges contribute to an immature safety and security landscape across a quickly emerging modality.

Attendees will leave with an understanding of the voice agent risk landscape, how attackers approach reconnaissance and exploitation, and practical guidance for building safety and security audio testing programs that scale.

AI Risk Summit Strategy Track (Salon I)
Wed 9:35 AM - 10:10 AM

Controlling What Flows Between Your Data and AI Applications

AI and agentic applications are only as reliable as the data pipelines feeding them, yet that layer is often ungoverned and inconsistent. This session examines an infrastructure layer that sits between enterprise data sources and AI applications to normalize, filter, and enforce policy on data in real time. It covers techniques such as schema validation, PII filtering, and access control applied inline before data reaches a model or agent. Attendees learn how stronger pipeline governance reduces data-quality and exposure risk without slowing AI delivery. (#SS Presented by Fleak AI)

AI Risk Summit Tech Track (Salon II)
Wed 9:35 AM - 10:10 AM

Governing the Intelligent Enterprise: AI Risk Management Frameworks for Production Systems

AI systems are failing faster than governance can keep up. Documented AI safety incidents surged 56.4% in recent years, with hallucination rates nearly doubling and autonomous agents executing unintended real-world transactions. For AI engineers shipping production systems at scale, the question is no longer whether to implement risk management, but which frameworks actually work when things go wrong.

This talk examines the operational reality of AI risk governance through the lens of the NIST AI Risk Management Framework and its ecosystem: the EU AI Act (enforceable August 2026), ISO/IEC 42001 certification standards, and NIST AI 600-1's 12 generative AI-specific risk categories. Unlike theoretical discussions of "responsible AI," this session focuses on what production teams actually need: inventory systems for AI components, monitoring architectures that catch drift before it becomes disaster, and accountability structures that survive real incidents.

You'll learn the four-function GOVERN-MAP-MEASURE-MANAGE cycle that applies across the AI lifecycle, how to instrument AI systems for continuous monitoring, and why organizations with documented governance infrastructure respond to failures 10x faster than those operating without it. We'll cover practical implementation patterns for managing third-party model risks, red-team evaluation protocols that find vulnerabilities before adversaries do, and the emerging insurance and procurement requirements that are making governance a competitive differentiation.

This isn't compliance theater. When AI systems execute millions of decisions daily - approving loans, routing patients, generating customer-facing content, traditional human-in-the-loop review cannot scale. The gap between capability deployment and risk infrastructure is widening, not closing. Organizations that embed governance into AI design earn the trust that converts capability into sustained advantage. Those that don't are building liability at scale.

Expect tactical guidance on building AI risk management flywheels, navigating multi-framework compliance across jurisdictions, and translating voluntary standards into engineering requirements before regulators mandate them. Whether you're deploying foundation models, building agentic systems, or integrating AI into critical infrastructure, you'll leave with a practical roadmap for governing AI systems that cannot afford to fail.

Key Takeaways:
- The NIST AI RMF four-function architecture and how to implement it in production environments
- NIST AI600-1's 12 AI-specific risks and mitigation actions engineers can deploy now
- Monitoring strategies for detecting model drift, bias, and adversarial exploitation
- Building incident response capabilities before the first material AI failure
- Why organizations treating governance as optional are making an increasingly poor regulatory timing bet

For AI/ML engineers, engineering leads, architects, and CxOs responsible for production AI systems.

CISO Forum Track (Salon III)
Wed 9:35 AM - 10:10 AM

When Face Value Is Dead, How Do You Get to Truth?

AI has made it hard to know who is real. Even the world's most advanced AI companies are being penetrated by foreign operators, while criminal networks use deepfakes and synthetic identities to slip past existing controls. Regulators are reacting with sweeping restrictions that continue to shift.

How bad is it, and how do you adjust without slowing down growth?

In this session, we'll show you the threat on a real-life heat map of international fraud rings, then you'll hear how leading companies are using the same identity layer trusted by the government to prove their guardrails are real.

Governments want to trust the private sector to innovate. Learn how to earn that trust now. (Presented by Socure)

AI Risk Summit Strategy Track (Salon I)
Wed 10:10 AM - 10:40 AM

Allow? [Y/N] The Hidden Risks of AI Coding Tools — and the Button we Keep Clicking

AI coding assistants have become far more than autocomplete. Today's agents can read repositories, execute commands, install packages, access secrets, and push code—often with little human oversight. While they're transforming developer productivity, they're also introducing entirely new security risks.

In this session, we'll break down the five biggest threats organizations face when adopting AI coding tools, from prompt injection and CI/CD compromise to malicious plugins, insecure AI-generated code, and the growing challenge of governing autonomous AI agents. Using real-world exploits and recent security research, we'll show how these attacks work, why they're succeeding, and what security and engineering leaders should do about them.

Attendees will leave with a practical framework for securing AI-assisted software development, reducing enterprise risk, and enabling developers to safely take advantage of the next generation of AI coding tools. (Presented by HiddenLayer)

AI Risk Summit Tech Track (Salon II)
Wed 10:10 AM - 10:40 AM

AI-Generated Media in the Wild: Risks, Failures, and Mitigations

As generative AI systems evolve from text to image and video, the nature of risk is shifting - becoming more complex, harder to detect, and increasingly impactful at scale.

In this session, I’ll share practical insights from building and deploying AI media safety systems at Meta, with a focus on how risks in generative systems are discovered, evaluated, and mitigated in real-world environments.

We’ll cover:
1. Risk discovery in generative media systems - identifying failure modes across images and video, including adversarial prompts and edge cases
2. Post-training alignment techniques, including reinforcement learning approaches to reduce harmful outputs
3. Automated red-teaming pipelines for systematically uncovering visual and temporal risks before deployment
4. Multimodal safety classifiers that balance risk reduction with usability (minimizing false positives and unnecessary refusals)
5. Scaling evaluation frameworks to increase testing coverage and iteration speed
6. Operationalizing safety through automation, including content risk labeling systems that significantly reduce manual effort and cost

This talk is intended for engineers, researchers, and practitioners working on deploying AI systems responsibly. The goal is to provide concrete patterns for identifying, measuring, and mitigating risk in modern AI systems - especially those operating at scale in real-world environments.

CISO Forum Track (Salon III)
Wed 10:10 AM - 10:40 AM

[Sponsored Session] The Rise of Agentic Fraud Ops: Fighting Fraud at Machine Speed

AI has fundamentally broken trust on the internet, and the numbers prove it. With AI-driven fraud attacks up 311% in Q1 2026, synthetic IDs growing increasingly convincing, and deepfakes now indistinguishable from real video, fraudsters are operating at machine speed. Meanwhile, financial institutions are being asked to do more with less: flat budgets, frozen headcount, and every tool under scrutiny.

In this session, Sardine founder and CEO Soups Ranjan makes the case that the only way to fight AI fraud is with AI, and lays out a practical blueprint for redesigning fraud operations around agentic workflows. Drawing on real attack scenarios, including a February 2026 case where 150K+ fraudulent accounts were created using stolen identities, Soups demonstrates how a coordinated chain of specialized AI agents, including anomaly detection, data analysis, graph analysis, and rule generation, can compress a week of data science work into five minutes.

Attendees will leave with a clear framework for getting their data AI-ready, identifying the right first use cases, and building agentic pipelines that let lean fraud teams punch far above their weight.

AI Risk Summit Strategy Track (Salon I)
Wed 11:00 AM - 11:30 AM

From Prompt to Breach: Memory Forensics in AI-Augmented Attack Surfaces

AI-augmented applications are redefining the attack surface, from prompt injection in LLMs to memory-resident payloads that blur the lines between inference and intrusion. This session examines real-world case studies where generative AI systems were exploited and how memory forensics plays a pivotal role in uncovering volatile threats. We’ll walk through advanced techniques for detecting and analyzing malicious behavior in memory, especially where conventional logging fails, and offer a forward-facing look at what “threat surfaces” truly mean in a post-AI era.

AI Risk Summit Tech Track (Salon II)
Wed 11:00 AM - 11:30 AM

AI Without Borders: The Collision of Regulation, Innovation, and Enterprise Reality

AI is evolving faster than any regulatory framework can keep up with, and organizations are caught between innovation pressure, unclear obligations, and real security risks that policy cannot yet address. In this session, cybersecurity executive Joshua Copeland and GRC leader Kayla Williams break down the widening gap between regulation and reality. They explore what developers truly face on the ground, what AI security teams cannot technically enforce, and the gray zones where compliance becomes theater. Attendees will learn how to build AI governance that is practical, scalable, and aligned with real-world enterprise constraints without slowing innovation to a crawl.

CISO Forum Track (Salon III)
Wed 11:00 AM - 11:30 AM

Your AI Security Stack Can’t See What AI Agents Are Doing at Runtime

Enterprises are rapidly moving from AI experimentation to AI execution. AI agents, copilots, LLM workflows, and MCP-connected tools are accessing sensitive data, calling APIs, and taking actions across production environments. Yet many organizations still focus on where AI is deployed instead of what it is doing at runtime.
This session explores why runtime AI behavior has become one of the biggest blind spots in enterprise security. Attendees will learn how AI is shifting security from static access controls to continuous execution governance, why AI security and API security are converging, and where today's cloud security and posture management tools fall short.

The session will examine how organizations can gain visibility into agent behavior, govern non-human identities, map agent-to-API interactions, detect sensitive data movement, enforce policy, and reduce shadow AI risk without slowing innovation. It will also discuss how these capabilities support emerging regulatory requirements, including the EU AI Act, where continuous evidence and auditability are becoming essential.

Attendees will leave with a practical framework for moving from AI visibility to runtime control, enabling security teams to monitor, govern, and intervene before autonomous AI actions become business risk.

AI Risk Summit Strategy Track (Salon I)
Wed 11:30 AM - 12:00 PM
  • David Abutbul AI Security Researcher - Prompt Security, a SentinelOne company

When AI Agents Become the Supply Chain: Hidden Control Planes in Agentic Systems

Agentic AI risk is no longer only prompt injection. Once assistants can read repositories, browse pages, load plugins, install dependencies, and call tools, the real security boundary moves into the control plane around the model.
This session maps that boundary through three concrete failure modes from recent research: repository instruction files that silently steer coding agents, marketplace skills and plugins that alter dependency installation, and agentic browser/runtime patterns where untrusted content becomes model context and tool execution.
Attendees will leave with a practical threat model for agentic systems: content ingestion, context translation, tool authority, dependency provenance, and runtime containment. The session will also cover defensive controls security leaders can apply now, including instruction provenance, allowlisted tools, permission gates, dependency-source enforcement, audit logs, and review workflows for agent behavior.
This is an educational, vendor-neutral session for CISOs, AppSec teams, AI platform owners, and developers adopting coding assistants or autonomous agents. The examples come from real research into agentic AI and AI coding-assistant behavior, but the talk focuses on repeatable risk patterns rather than any single product.

Learning objectives:
1. Recognize hidden instruction sources that can steer agent behavior.
2. Explain why agentic AI risk resembles supply-chain and control-plane security.
3. Identify practical controls that reduce the blast radius of AI agents in enterprise environments.

AI Risk Summit Tech Track (Salon II)
Wed 11:30 AM - 12:00 PM

Human in the Loop, Out of Control

As AI systems become more autonomous, the central risk is not that humans disappear from the process entirely, but that they remain “in the loop” while being pushed into the passenger seat. They approve outputs they do not fully understand, rely on recommendations they cannot audit, and delegate decisions to agents whose reasoning and methods are only partially visible.

This creates a dangerous governance gap because an agent may summarize sensitive data, recommend policy changes, modify code, trigger workflows, or escalate access.

Keeping humans in the driver’s seat cannot become a checkbox exercise. Automation may be acceptable for low-risk tasks, but high-risk actions require stronger controls such as audit trails, mandatory escalation paths, constrained permissions, token usage restrictions, and kill-switch capabilities. The goal is to ensure that human authority remains operationally real while maintaining efficiency.

Attendees will leave with a practical way to evaluate whether their human-in-the-loop controls are meaningful or merely cosmetic.

CISO Forum Track (Salon III)
Wed 11:30 AM - 12:00 PM

From AI Theory to Control

The shift from AI tools to autonomous agents has outpaced our risk models. Enterprise environments face a sprawl of tool access where agents operate with a blast radius that moves at machine speed. This creates a disconnect between the permissions granted and the actual oversight required to manage those agents in production. The only way to manage the risks of AI at machine speed is with human-AI systems.
We will focus on "Context Based Control" policies that balance agentic permissions with situational measurement of the appropriateness of their actions. We will also address designing probabilistic systems, informed by rules and context, that help you balance human oversight and machine work.

AI Risk Summit Strategy Track (Salon I)
Wed 12:00 PM - 12:30 PM

The Synthetic Insider: When Deepfakes and Autonomous AI Agents Collide Inside the Enterprise

The phishing email asking a CFO to wire funds is yesterday's problem. In 2026, the attacker doesn't email the CFO. They clone the CFO's voice, leave a voicemail for an AI assistant that has calendar access, payment approval permissions, and a helpful disposition, and the AI does the rest. No human in the loop. No malware on the endpoint. No anomaly the SOC was trained to catch.

This session is about the collision the security industry has not fully reckoned with yet: deepfakes and synthetic media on one side, autonomous AI agents with real enterprise privileges on the other, and the identity layer in the middle that was never designed for either.

Drawing on years of architecting large-scale enterprise AI systems and serving on NIST's AI Agent Security subcommittee, I'll walk through the new attack chain step by step. How a few minutes of LinkedIn video becomes a convincing voice clone. How that clone bypasses help-desk verification. How it manipulates an AI agent that trusts authenticated channels more than it trusts judgment. And how a single compromised agent then cascades into others through the trust relationships your teams have quietly been building all year.

AI Risk Summit Tech Track (Salon II)
Wed 12:00 PM - 12:30 PM

The Good, the Sad and the Ugly: What Research Reveals About AI Safety and Security Gaps and Options

How can a CISO or risk officer be confident that their AI-enabled applications are safe and secure?

TELUS Digital recently completed more than 650k adversarial tests on 34 leading AI models. We will talk about how the vendor, model size, country-of-origin, reasoning capabilities, openness, and other factors impact AI safety and security. Importantly, we will also discuss how that translates into what CISOs should focus on when evaluating AI apps, both before launch and in production.

We will also review our latest research around AI agent testing and the gaps in current practices that result in avoidable risk. And we will review a recent survey of CISOs regarding their AI safety and security practices, as well as data from testing AI-enabled applications that consume more than 2T AI tokens annually.

TELUS Digital's AI Research Labs have published extensive research on AI safety and security in technical journals and conferences, built AI models that have compromised every AI model they've encountered, and worked directly with CISOs on how to automate testing, validation, and auditing of the safety and security of AI-powered systems.

The goal of this talk will be to offer data-driven insights about actual AI risks seen in the field, techniques that make a difference in vulnerability discovery, and straightforward steps that telcos, airlines, healthcare providers, and financial services companies have taken to proactively reduce risk and instill confidence in their AI investments, without increasing the burden on CISO organizations.

The presentation will provide specific data, concrete examples, and specific recommendations, while avoiding generalizations.

CISO Forum Track (Salon III)
Wed 12:00 PM - 12:30 PM

The Real Risk of AI Isn’t Hallucinations - It’s the Collapse of Business Models

Most organizations focus on visible AI risks - hallucinations, data leakage, bias, compliance failures, and cybersecurity threats. Those risks matter, but they are not the risks most likely to destroy enterprise value.
The larger danger is structural: AI is changing the rules of competition, shifting control points, redistributing value across ecosystems, and altering what positions create sustainable advantage. As markets move through successive waves of AI transformation, business models that once appeared durable can weaken quickly - or collapse suddenly.
In this executive-focused session, Dr. Barnett introduces a practical framework for identifying AI-driven business model risk across three waves: efficiency disruption, market reinvention, and industry restructuring. Attendees will leave with a sharper lens for assessing strategic exposure, protecting long-term value, and recognizing early signals of collapse before competitors do.

AI Risk Summit Strategy Track (Salon I)
Wed 1:30 PM - 2:05 PM

When Agents Go Rogue: A Threat Model and Defense Framework for Agentic AI Systems

As enterprises rush to deploy agentic AI systems — autonomous agents that plan, reason, and execute multi-step tasks across tools and APIs — the security community is confronting an entirely new threat landscape. Unlike traditional LLM deployments, agentic systems can take irreversible real-world actions, exfiltrate data through tool calls, and propagate attacks across integrated environments.

This talk presents a practitioner-built threat model for agentic AI, developed through hands-on work building and securing production agentic systems at Microsoft. Drawing on real-world deployment experience, I will introduce a structured taxonomy of agentic AI failure modes — from prompt injection through orchestration chains to privilege escalation via tool misuse — and map each to concrete, implementable defenses.

Key topics covered:
• Why existing LLM security frameworks (OWASP Top 10 for LLMs, MITRE ATLAS) are insufficient for agentic architectures
• A novel threat model covering agent memory poisoning, cross-agent trust exploitation, and tool-layer attacks
• Defense-in-depth patterns: identity-aware orchestration, agent sandboxing, guardrail design, and behavioral monitoring
• Case studies from production agentic deployments illustrating real attack surfaces and mitigations

Attendees will leave with a practical, immediately applicable framework for assessing and hardening their own agentic AI deployments — not theory, but battle-tested patterns from the field.

Learning Objectives:
1. Understand why agentic AI introduces fundamentally new security risks beyond traditional LLM threats
2. Apply a structured threat model to identify attack surfaces in their own agentic systems
3. Implement concrete defense patterns including agent sandboxing, identity-aware orchestration, and behavioral guardrails

AI Risk Summit Tech Track (Salon II)
Wed 1:30 PM - 2:05 PM

When AI Meets the Courtroom: Building Trustworthy AI Systems Through Legal and Technical Governance

As organizations race to embed AI into their products, platforms, and decision-making pipelines, a critical question often goes unanswered until it’s too late: what happens when AI systems fail, produce harmful outputs, or become the subject of litigation?
This session, led by Daniel B. Garrie—co-creator of the JAMS AI Dispute Resolution Rules, JAMS arbitrator, Harvard adjunct professor, and founder of Law & Forensics—bridges the gap between AI engineering and the legal frameworks now shaping how AI is built, deployed, and defended in court. Drawing on 20+ years at the intersection of law and computer science, and hands-on experience as a court-appointed expert in landmark technology cases (including In Re: Facebook), Daniel will walk attendees through the real-world legal risks that product teams, CTOs, and AI engineers face today.
Key takeaways include:
• AI in litigation: How courts are evaluating AI-generated evidence, model outputs, and synthetic media—and the technical standards emerging from these rulings.
• Dispute-ready architecture: Practical engineering decisions (logging, versioning, documentation) that protect AI products when disputes arise.
• The JAMS AI Rules framework: A first look at the dispute resolution rules purpose-built for AI conflicts—covering IP infringement, data privacy breaches, synthetic content misuse, and LLM-related trade secret claims.
• Governance as competitive advantage: How proactive AI governance (cybersecurity audits, compliance frameworks, board-level oversight) reduces risk and accelerates enterprise adoption.
Whether you’re building AI products, leading engineering teams, or advising executive stakeholders, this session delivers the practical legal and technical intelligence you need to ship AI that’s not only powerful—but defensible.

CISO Forum Track (Salon III)
Wed 1:30 PM - 2:05 PM
  • Jerry Adams Franklin AI/ML Research Consultant | Ex-Senior AI Engineer, DCG & Intel - Independent | Ex-Digital Currency Group & Intel Corporation

Federated Learning as AI Risk Infrastructure: The Aggregation Problem Enterprises Are Not Ready For

Every enterprise AI system has a data problem: the most valuable training data is also the most sensitive. Financial transactions, client communications, proprietary records centralizing this data to train models creates exactly the risk enterprises are trying to avoid. Federated learning offers a third path: train across distributed nodes without raw data ever leaving its origin. But federated learning in production introduces its own risk surface that most enterprise teams are unprepared for.

The deeper problem is aggregation. Current federated deployments assume that model update aggregation strategies can be fixed before training begins and held constant across all rounds. In practice this assumption breaks down. Early rounds over-communicate, later rounds under-communicate at precisely the phase where model integrity is most sensitive. The result is a federated system that is simultaneously privacy-preserving and fragile.

This session presents an adaptive aggregation framework developed through original research in communication-efficient federated learning, validated across multiple model scales, that dynamically selects aggregation strategies based on live training signals rather than static configuration. Attendees will leave with a clear framework for evaluating federated learning as an enterprise AI risk mitigation strategy, an understanding of the aggregation vulnerabilities unique to federated architectures, and practical guidance on the governance mechanisms that separate a robust federated deployment from a vulnerable one.

AI Risk Summit Strategy Track (Salon I)
Wed 2:05 PM - 2:35 PM

Breaking the Agentic Sandbox

AI coding agents are being deployed behind sandboxes, egress allowlists, and scoped filesystem access - and enterprises are calling it contained. This session proves otherwise with three original attack chains, each starting from a single indirect prompt injection and ending with full secret exfiltration or arbitrary code execution.
The attacker has zero prior access. No credentials, no malware, no endpoint compromise. Just a crafted GitHub issue that the agent is configured to read. From there, the agent does the rest - hijacked step-by-step into working on the attacker's behalf through a technique we call agentjacking.
We show a responsibly disclosed zero-day that escapes Claude Desktop's network sandbox entirely. A technique that exfiltrates stolen API keys and source code through an allowlisted package registry, indistinguishable from normal developer traffic. And an MCP configuration hijack that rewrites the agent's own trust chain — turning a verified tool into an attacker-controlled execution channel that delivers remote code execution, persistent access, and full secret exfiltration from inside a "secured" environment.
Every action is legitimate. Every destination is allowlisted. Every control in the path sees nothing. The failure is structural - not a bug in any single component, but a broken assumption about what containment means when the thing you're containing can reason.
The session closes with a practical hardening framework mapped to agent autonomy levels, so attendees leave knowing which controls actually matter for their deployment model.
All vulnerabilities responsibly disclosed. Live demos included.

AI Risk Summit Tech Track (Salon II)
Wed 2:05 PM - 2:35 PM

The Accountability Gap: Why AI Governance Fails Before the Breach Occurs

The AI risk conversation in enterprise security is dominated by two categories of threat: external adversaries exploiting AI, and model-level failures such as bias, hallucination, and data leakage. Both are real. Neither is the governance failure that causes the most damage in high-stakes project, program and portfolio environments.
The most consequential AI risk in organizations today is internal and organizational: no human in the workflow has clear, documented, enforceable accountability for verifying what the AI produced before it became a decision. By the time the error surfaces, it has already propagated through compliance documentation, resource allocations, or regulatory filings. The breach did not come from outside. It was built into the process from the start.
Dr. Tricia Diamond draws on her experience directing a $386 million ARPA Implementation PMO, where AI-assisted tools were deployed in a federally audited environment with zero tolerance for undetected error, to present a practitioner's framework for closing the accountability gap before it becomes a liability. This session examines the specific organizational conditions under which AI errors compound undetected, the human-in-the-loop validation architecture that actually works under operational pressure, and the documentation and traceability practices thatmake AI-assisted decisions defensible when the regulator or the auditor arrives.
This is not a theoretical framework. It is a field account of AI governance built and operated under real federal scrutiny, with real consequences for failure, in an environment where the cost of an undetected error was measured in potential clawback of public funds and community harm.
Learning Objectives are
Identify three organizational conditions that allow AI errors to compound undetected in enterprise environments, and the governance interventions that interrupt each one before they become a security or compliance event.
Design human-in-the-loop validation checkpoints that function under operational pressure rather than creating the appearance of oversight while the process moves too fast for genuine verification.
Build the documentation and traceability architecture that makes AI-assisted decisions auditable, defensible, and correctable after the fact by satisfying both internal risk management requirements and external regulatory scrutiny.

CISO Forum Track (Salon III)
Wed 2:05 PM - 2:35 PM

Shaken, not Secured: A Dossier for Closing the AI Visibility Gap

In the movies, secret agents are either protecting the mission or quietly undermining it. The scary part is that they often look the same at first: both have credentials, both have access, and both move through restricted areas without setting off alarms.

As AI infiltrates everyday apps and agent builders, security teams can't settle for tailing a known watchlist of AI tools; they need eyes on a constantly shifting network of double agents—AI embedded in other SaaS tools, agents, integrations, and permissions that traditional network- and endpoint-based security tools were never built to surveil.

This session unpacks why shadow AI reconnaissance is a different mission entirely from past shadow IT operations, and how today's organizations are adapting their tradecraft to keep up. Attendees will leave with a field-tested framework for closing their AI visibility gap, a clear briefing on why discovery is the precondition for every other security control, and a solid case for unlocking budget across security, AI innovation, and compliance.

Because every successful mission starts with good intelligence.

AI Risk Summit Strategy Track (Salon I)
Wed 2:35 PM - 3:05 PM

Managing Risk in Autonomous Software Development

As AI agents begin to write, test, and ship code continuously, enterprises face new risks around code provenance, security, and accountability. This session examines how to position humans as the governance layer over autonomous development, defining approval gates, policy controls, and audit trails for agent-generated software. It covers practical guardrails such as automated security review, scoped permissions, and traceability from requirement to commit. Attendees explore how to scale autonomous software production while maintaining quality, compliance, and control. (#SS Presented by Factory)

AI Risk Summit Tech Track (Salon II)
Wed 2:35 PM - 3:05 PM
  • Bethany Abbate Director, AI Policy - Software & Information Industry Association (SIIA)

Why Fragmented AI Policy is Fueling Public Skepticism — and What Security Leaders Can Do About It

The trust gap in AI is real, and possibly expanding. A 2025 Pew Research Center study found that while a majority of AI experts believe AI will have a positive impact on the United States, only 17% of the American public agrees. More than half of U.S. adults say they are more concerned than excited about AI, and both the public and experts alike indicate concern that government regulation will fall short rather than go too far.

AI governance is evolving, but not always in the same direction. Across the United States, states are writing their own AI rules in the absence of federal law. Internationally, a growing number of countries are each charting distinct regulatory paths. The result is a “patchwork” landscape that is active, ambitious, and complex to navigate from a compliance standpoint, which can send mixed signals to a public already uncertain about whether AI is being governed responsibly.

That perception challenge has real consequences. Public uncertainty about AI can slow adoption and create friction for organizations trying to deploy AI thoughtfully and at scale. For security and business leaders, trust is increasingly part of the AI risk calculus.

This session explores the relationship between policy fragmentation and public confidence in AI, and makes the case that today's regulatory complexity can also be viewed as an opportunity. Leaders who understand the policy landscape, and can translate it clearly for their organizations and stakeholders, are uniquely positioned to help close the gap.

Drawing on firsthand experience navigating the AI policy and regulatory landscape across federal, state, and international jurisdictions, this talk will map the current AI regulatory trends for a security-literate audience, connect it to enterprise risk in practical terms, and offer a framework for turning policy complexity into a trust-building advantage.

CISO Forum Track (Salon III)
Wed 2:35 PM - 3:05 PM

The Defender's Window

The dynamics of AI and cyber security have reached a structural inflection point.

The 3 dynamics between AI and cyber security with which we are concerned are as follows. These are the axes of the strategic space of LLMs and cyber security:

• LLM enabled capability uplift at the lower end of the attacker capability spectrum – Attacker capability uplift determines the change in threat population that your organisation faces
• Ability to leverage LLMs for analytical capability for defenders – What can your organization do with the infrastructure you have?
• Tiered access governance for LLM cybersecurity capability – What tier of defensive capability can your organization reach?

The three tiers of access governance for LLM cybersecurity capability are currently:
• Glasswing - Closed to all but fifty firms (roughly).
• TAC - Open to thousands of verified defenders, the one most peers will likely operate in.
• Public models and open-source agent frameworks - Public research has found that with the right expertise this tier may well be much closer to the top tier than the hype suggests.


Together, the dynamics produce the window - The time-bounded period during which the access-governance advantage is real, the analytical leverage is being built, and the capability uplift at the lower attacker tier is still being absorbed rather than exploited at full tilt.

We analyze the threat to and from AI implementations under the COMPASS framework - Compute, Operations, Models, Power and utilities, Alliances, and Supply Signals.
We assess the AI derived problems facing organizations and their technology stacks, detailing what those problems are, why they matter, and what can be done about them.
Attendees to this session will leave with an elevated understanding of the current AI situation from a cybersecurity governance and opportunity perspective.

AI Risk Summit Strategy Track (Salon I)
Wed 3:30 PM - 4:00 PM

Rethinking How we Evaluate Security Agents for Real-World Use

Security agents are gaining momentum across industry, but the way we evaluate them remains rooted in narrow, outcome-only benchmarks. These evaluations tell us whether an agent produced a correct answer, but not “how” it arrived there or whether that behavior will remain stable once deployed.

In practice, enterprise security is not a sequence of isolated tasks. It is a connected, end-to-end workflow that follows a find → confirm exploit → patch → validate loop. Agents that perform well on task-specific benchmarks often fail in these multi-stage settings due to contextual loss and brittle transitions across steps.

This talk introduces a practical framework for evaluating security agents by mapping agentic capabilities (planning, reasoning, memory, perception, tool use) to security functions (reconnaissance, exploit confirmation, root-cause analysis, patching, validation) across the full lifecycle.

We also share insights from our large-scale survey of existing agentic systems and presents a lightweight, unified end-to-end scoring perspective that teams can use to assess an agent’s readiness for real operational environments.

AI Risk Summit Tech Track (Salon II)
Wed 3:30 PM - 4:00 PM
  • Sabah Rahman Independent Researcher & Design Leader - Independent (AI Explainability Research)

The EU AI Act Takes Effect This Year. Your Explainability Tools Aren't Ready.

Article 13 of the EU AI Act requires high-risk AI systems to produce interpretable, documented explanations of their decisions. Those requirements take effect in August 2026—just days after this summit. The Colorado AI Act follows in June.

Most organizations plan to meet these requirements using SHAP, particularly KernelSHAP, the leading model-agnostic approach for black-box models. The problem is that KernelSHAP relies on permutation sampling, meaning it can generate different explanations for the same input every time it runs.

That creates a critical compliance question: How do you submit a non-reproducible audit trail to a regulator?

While TreeSHAP is deterministic, it only works for tree-based models and doesn't solve the broader problem.

This session introduces four deterministic, model-agnostic methods designed to address that gap:

Interaction Mapping – Detects feature synergy and redundancy.

Counterfactual Pathing – Identifies the minimal sequence of changes needed to flip a decision.

Reasoning Drift Tracking – Measures how model reasoning changes over time using Jensen-Shannon divergence.

Deterministic Reproducibility – Produces identical explanations without stochastic sampling.

All four methods are gradient-free, run in O(n) time, and execute entirely in the browser with no backend.

Attendees will see live demonstrations of each technique, learn what Article 13 actually requires, why current explainability tools fall short of auditability standards, and what a regulation-ready explanation artifact should look like.

Designed for risk leaders, compliance teams, and AI engineers building AI systems for regulated industries, this session provides practical guidance for ensuring explainability pipelines can withstand regulatory scrutiny.

CISO Forum Track (Salon III)
Wed 3:30 PM - 4:00 PM

Panel: Securing AI at Scale - How CISOs Are Navigating the AI Race

This panel brings together CISOs from across industries for a candid conversation about managing AI risk in production environments. Panelists will share how they're approaching the expanding AI attack surface — from shadow AI and data leakage to securing models, APIs, and agents — and where governance frameworks are working or falling short. The discussion explores practical lessons on balancing rapid AI adoption with security, earning board-level trust, and building controls that scale across hybrid environments. Attendees will leave with peer-tested perspectives on turning AI risk management from a blocker into a business enabler.

CISO Forum Track (Salon III)
Wed 4:00 PM - 5:00 PM