About
In 2024, we secured the input (Prompt Injection). In 2025, we secured the output (Hallucinations and Data Leakage). In 2026, we must secure the action. As organizations move from passive "Chatbots" to "Autonomous Agents" capable of browsing the web, accessing databases, and executing code, the attack surface has shifted from text manipulation to unauthorized systemic agency. This session provides security leaders with a strategic framework for governing AI in production. We will move beyond the OWASP Top 10 for LLMs to address the new regulatory landscape by establishing Eqo's "Unbreakable Chain" of AI Governance: Policy, Identity, and Manifest.
Attendees will leave with a leadership blueprint for establishing a zero-trust perimeter around AI-generated code, ensuring that as AI gets more independent, our security, governance, and verification remain absolute.
Learning Objectives
1. Define the "Agentic Shift": Understand the architectural difference between a retrieval-augmented generation (RAG) chatbot and a tool-use autonomous agent.
2. Shift-Zero Policy Enforcement: Move beyond reactive guardrails. Learn how to implement Policy-as-Code firewalls that intercept logic drift and policy violations *before* the first token is generated.
3. Agent-ID Verification (Identity for AI): Establish a framework for deterministic Machine Identity Management. Learn how to assign hardware-backed, cryptographic Agent-IDs to guarantee that every autonomous action is explicitly authorized and linked to a verifiable identity.
4. The PBOM Manifest (Continuous Provenance): Evolve past the "kill-switch." Discover how to automate transparency by generating a Package/Provenance Bill of Materials (PBOM)—the cryptographic "birth certificate" for every line of AI code—ensuring full audit provenance and readiness for EU AI Act Article 11.