Skip to content

Building Trustworthy AI Agents

Global AI Security Bootcamp banner

This companion site follows the Global AI Security Bootcamp 2026 talk and turns the deck into readable, accessible chapters - one page per slide, with expanded explanations and real-world examples.

Slide 1 thumbnail

Slide 1 · Title

Why security professionals are the most important people in the room.

Slide 2 thumbnail

Slide 2 · The Vibe Shift

From "AI in your app" to "your app IS the agent" - and why your skills are more relevant than ever.

Slide 3 thumbnail

Slide 3 · What We're Covering

Three practical topics: safe deployment, security considerations, and data privacy.

Slide 4 thumbnail

Slide 4 · What Is an AI Agent?

The Perceive → Reason → Act → Observe loop, and why every step is an attack surface.

Slide 5 thumbnail

Slide 5 · The Agent Spectrum

From assisted to multi-agent - and why your security posture must match your autonomy level.

Slide 6 thumbnail

Slide 6 · Cloud-Native Agents in the SDLC

Agents across every phase of delivery - and the security considerations at each stage.

Slide 7 thumbnail

Slide 7 · The Threat Landscape

The real numbers, OWASP's LLM Top 10, and why autonomy changes the blast radius.

Slide 8 thumbnail

Slide 8 · OWASP Top Threats for Agents

Six critical risks - prompt injection, excessive agency, supply chain - with examples and mitigations.

Slide 9 thumbnail

Slide 9 · Prompt Injection: Show Don't Tell

Vulnerable vs. defended side by side - and why architectural controls beat prompt controls.

Slide 10 thumbnail

Slide 10 · The Attack Surface Map

Every attack surface an agent presents, with real-world examples and targeted defences.

Slide 11 thumbnail

Slide 11 · Framework Overview

The five-layer Trustworthy Agent Stack and what breaks when each layer is missing.

Slide 12 thumbnail

Slide 12 · Layer 1 - Secure Design

STRIDE applied to agents, the five questions every developer must answer before deployment.

Slide 13 thumbnail

Slide 13 · Layer 2 - Identity & Least Privilege

GitHub Apps, OIDC, required reviewers - and why agents must never authenticate as humans.

Slide 14 thumbnail

Slide 14 · Layer 3 - Runtime Controls

The Agent Control Specification, output filtering, rate limiting, and GitHub as a guardrail.

Slide 15 thumbnail

Slide 15 · Layer 4 - Observability

What to monitor, why token spikes are security signals, and how ASSERT works.

Slide 16 thumbnail

Slide 16 · Layer 5 - Governance

The Agent Policy Document, Microsoft IQ, the EU AI Act, and governance as a deployment enabler.

Slide 17 thumbnail

Slide 17 · Live Demo

All five security layers in action - identity, code scanning, secret scanning, review gates, audit logs.

Slide 18 thumbnail

Slide 18 · The Developer Is Your Ally

Security in the IDE, the PR, the pipeline, and the audit log - and why the secure path must be the easy path.

Slide 19 thumbnail

Slide 19 · Agent Security Checklist

The full pre-production checklist - design, identity, code, runtime, observability, governance.

Slide 20 thumbnail

Slide 20 · The Only Question That Matters

Can you detect it, stop it, explain it, and fix it - fast? That is your security roadmap.