Building Trustworthy AI Agents

This companion site follows the Global AI Security Bootcamp 2026 talk and turns the deck into readable, accessible chapters - one page per slide, with expanded explanations and real-world examples.
Slide 1 · Title
Why security professionals are the most important people in the room.
Slide 2 · The Vibe Shift
From "AI in your app" to "your app IS the agent" - and why your skills are more relevant than ever.
Slide 3 · What We're Covering
Three practical topics: safe deployment, security considerations, and data privacy.
Slide 4 · What Is an AI Agent?
The Perceive → Reason → Act → Observe loop, and why every step is an attack surface.
Slide 5 · The Agent Spectrum
From assisted to multi-agent - and why your security posture must match your autonomy level.
Slide 6 · Cloud-Native Agents in the SDLC
Agents across every phase of delivery - and the security considerations at each stage.
Slide 7 · The Threat Landscape
The real numbers, OWASP's LLM Top 10, and why autonomy changes the blast radius.
Slide 8 · OWASP Top Threats for Agents
Six critical risks - prompt injection, excessive agency, supply chain - with examples and mitigations.
Slide 9 · Prompt Injection: Show Don't Tell
Vulnerable vs. defended side by side - and why architectural controls beat prompt controls.
Slide 10 · The Attack Surface Map
Every attack surface an agent presents, with real-world examples and targeted defences.
Slide 11 · Framework Overview
The five-layer Trustworthy Agent Stack and what breaks when each layer is missing.
Slide 12 · Layer 1 - Secure Design
STRIDE applied to agents, the five questions every developer must answer before deployment.
Slide 13 · Layer 2 - Identity & Least Privilege
GitHub Apps, OIDC, required reviewers - and why agents must never authenticate as humans.
Slide 14 · Layer 3 - Runtime Controls
The Agent Control Specification, output filtering, rate limiting, and GitHub as a guardrail.
Slide 15 · Layer 4 - Observability
What to monitor, why token spikes are security signals, and how ASSERT works.
Slide 16 · Layer 5 - Governance
The Agent Policy Document, Microsoft IQ, the EU AI Act, and governance as a deployment enabler.
Slide 17 · Live Demo
All five security layers in action - identity, code scanning, secret scanning, review gates, audit logs.
Slide 18 · The Developer Is Your Ally
Security in the IDE, the PR, the pipeline, and the audit log - and why the secure path must be the easy path.
Slide 19 · Agent Security Checklist
The full pre-production checklist - design, identity, code, runtime, observability, governance.
Slide 20 · The Only Question That Matters
Can you detect it, stop it, explain it, and fix it - fast? That is your security roadmap.