The API-First Blueprint for Secure AI Agents: A 14-Layer Defense Framework

About this session

AI agents are no longer just "chatbots"; they are autonomous API consumers with the power to query databases, trigger CI/CD pipelines, and manage IAM roles. But when an agent acts as a "Super User" across your service mesh, a single prompt injection can escalate into a kubectl delete namespace disaster.

This session introduces Bottom-Up AI Agent Security, a rigorous framework designed to bridge the gap between non-deterministic LLM reasoning and deterministic API security. We will deconstruct a 14-layer defense strategy that secures the entire agentic lifecycle: from local skill unit testing and static prompt analysis to ephemeral IAM credentialing and runtime tool-gatekeeping.

Attendees will walk away with a production-ready roadmap to transform vulnerable "agentic workflows" into hardened, enterprise-grade AI systems.

Speakers

Key takeaways

  • The SSL (Secure Skill Lifecycle): How to unit-test agent "skills" locally using Java before they ever touch production credentials.
  • Agentic API Gateways: Implementing tool-whitelisting and schema validation to ensure agents can’t "hallucinate" dangerous API calls.
  • Ephemeral Cloud IAM: Shifting from long-lived keys to 15-minute TTL credentials for autonomous agents.

Related sessions