The API-First Blueprint for Secure AI Agents: A 14-Layer Defense Framework
About this session
AI agents are no longer just "chatbots"; they are autonomous API consumers with the power to query databases, trigger CI/CD pipelines, and manage IAM roles. But when an agent acts as a "Super User" across your service mesh, a single prompt injection can escalate into a kubectl delete namespace disaster.
This session introduces Bottom-Up AI Agent Security, a rigorous framework designed to bridge the gap between non-deterministic LLM reasoning and deterministic API security. We will deconstruct a 14-layer defense strategy that secures the entire agentic lifecycle: from local skill unit testing and static prompt analysis to ephemeral IAM credentialing and runtime tool-gatekeeping.
Attendees will walk away with a production-ready roadmap to transform vulnerable "agentic workflows" into hardened, enterprise-grade AI systems.
Speakers
Key takeaways
- The SSL (Secure Skill Lifecycle): How to unit-test agent "skills" locally using Java before they ever touch production credentials.
- Agentic API Gateways: Implementing tool-whitelisting and schema validation to ensure agents can’t "hallucinate" dangerous API calls.
- Ephemeral Cloud IAM: Shifting from long-lived keys to 15-minute TTL credentials for autonomous agents.
Related sessions
- The Model Is Not the Problem: Why Data Quality Is the Real Bottleneck in Agentic AI
- The Governance Paradox: Why Faster AI Adoption Requires More Governance, Not Less
- Can You Prove Your AI Is Working? Most Leaders Can't. Here's the Fix.
- The Human Advantage: Use AI to Reclaim Time Without Outsourcing the Thinking That Makes You Valuable