Deep Dive180min
AI Security Deep Dive, Securing Agents and AI Applications
This session covers AI security for agentic coding and AI-powered apps, including risks like prompt injection, tool abuse, poisoned retrieval, and memory manipulation. It emphasizes practical defenses, architectural patterns, and security tooling, with live demos and real-world examples to help build and use AI systems more securely.
talk.summaryAiDisclaimer
Brian VermeerSnyk
talkDetail.whenAndWhere
Monday, October 5, 13:30-16:30
TBA 3
talks.roomOccupancytalks.noOccupancyInfo
AI is transforming how we write software and the applications we build, introducing entirely new security challenges.
In this session, we’ll explore two critical areas of AI security. First, we’ll look at agentic coding and the risks of AI agents that read untrusted content, execute commands, and interact with your development environment. Next, we’ll examine AI-powered applications, covering threats such as prompt injection, tool abuse, poisoned retrieval, and memory manipulation.
The focus is on practical defence. You’ll learn proven mitigation strategies, architectural patterns, and the current landscape of AI security tooling, including guardrails, runtime protection, and security testing frameworks. Through live demos and real-world examples, you’ll leave with actionable techniques to build and use AI systems more securely.
In this session, we’ll explore two critical areas of AI security. First, we’ll look at agentic coding and the risks of AI agents that read untrusted content, execute commands, and interact with your development environment. Next, we’ll examine AI-powered applications, covering threats such as prompt injection, tool abuse, poisoned retrieval, and memory manipulation.
The focus is on practical defence. You’ll learn proven mitigation strategies, architectural patterns, and the current landscape of AI security tooling, including guardrails, runtime protection, and security testing frameworks. Through live demos and real-world examples, you’ll leave with actionable techniques to build and use AI systems more securely.
Brian Vermeer
Staff Developer Advocate for Snyk, Java Champion, Oracle Ace Pro, and Software Engineer with over a decade of hands-on experience in creating and maintaining software. He is passionate about Java, (Pure) Functional Programming and Cybersecurity. Brian is a JUG leader for the Virtual JUG and the NLJUG. He also co-leads the DevSecCon community and is a community manager for Foojay. He is a regular international speaker on mostly Java-related conferences like JavaOne, Devnexus, Devoxx, Jfokus, JavaZone and many more. Besides all that, Brian is a military reserve for the Royal Netherlands Air Force and a Taekwondo Master / Teacher.