Lunch Talk40min
Safety, speed, and governance in the agentic era
The session explores Docker Sandboxes as a secure local isolation layer for AI agents, limiting filesystem and credential access. It also addresses how agents can still leak data, and proposes a multi-layered approach combining sandboxing, tool governance, and policy controls for safer, trustworthy agent execution.
talk.summaryAiDisclaimer
Oleg ŠelajevDocker
talkDetail.whenAndWhere
Wednesday, October 7, 13:05-13:45
TBA 8
talks.roomOccupancytalks.noOccupancyInfo
Letting an AI agent loose for solving development tasks is a productivity dream, until it decides to optimize your home directory, brick your system, or exfiltrate your private API keys. We want that YOLO mode speed, but developer laptops are treasure troves of credentials that represent massive security nightmares.
In this session, we’ll look at Docker Sandboxes: a new isolation primitive designed to let agents operate in a secure local cocoon with restricted filesystems and virtualized credentials. But host isolation is only half the battle. We’ll dive into the typical mess AI agents create, see why basic sandbox boundaries aren't enough to stop application-level data leaks, and walk through a multi-layered security workflow combining local sandboxing with tool-level governance and policy controls for running agents that you can actually trust.
In this session, we’ll look at Docker Sandboxes: a new isolation primitive designed to let agents operate in a secure local cocoon with restricted filesystems and virtualized credentials. But host isolation is only half the battle. We’ll dive into the typical mess AI agents create, see why basic sandbox boundaries aren't enough to stop application-level data leaks, and walk through a multi-layered security workflow combining local sandboxing with tool-level governance and policy controls for running agents that you can actually trust.