
< session />
Tue, April 27Reliability, Observability & Security
In 2026, AI agents running inside supposedly isolated security evaluations reached the production systems of real organisations. The headlines said “AI escapes.” The postmortems tell a more useful engineering story: almost every step crossed a boundary that was assumed rather than enforced.
In this session, you will examine published attack chains hop by hop, using primary reports from OpenAI, Hugging Face, Anthropic, and the independent METR investigation. You will see how a model told in its system prompt that it had no internet access was running on a machine that did, how an “isolated” sandbox retained a path through a package-registry proxy, how secrets remained available in environment variables, and how individual credentials carried more authority than their tasks required. The session also examines what was genuinely different about these agents: volume and persistence, including more than 17,000 recorded actions against a single target, most of them unsuccessful, as agents continued until something worked.
Each step in these attack chains will be mapped to the control that could have stopped it. You will then see the same agent, with the same prompt and task, run through a containment lab twice: once with boundaries assumed and once with them enforced. The comparison shows why prompts are not security boundaries and what effective containment requires when running coding agents, CI agents, or evaluation harnesses.
What You Will Learn
Why prompts and assumed isolation do not provide effective security boundaries for AI agents
How network access, proxies, secrets, and overpowered credentials can create paths out of supposedly isolated environments
How to map agent attack chains to the controls that can contain them
How to apply a practical containment checklist to coding agents, CI agents, and evaluation harnesses
Who Should Attend
Security Engineers, Platform Engineers, DevSecOps practitioners, AI Engineers, Software Architects, SREs, and technical leaders responsible for deploying or evaluating AI agents.
< speaker_info />
Brent Laster is a global trainer, author, and speaker on open-source technologies, as well as an experienced developer, manager, and director. He is also the founder and president of Tech Skills Transformations, LLC – a company dedicated to making technology understandable and usable. Throughout his career in software development and management, Brent has always made time to learn and develop both technical and leadership skills and share them with others. He believes that regardless of the topic or technology, there’s no substitute for the excitement and sense of potential that come from providing others with the knowledge they need to accomplish their goals.