← All sessions
Talk · 25 min

Watching Agents for Trouble

🕑

Time and room for this session are published in October. when the timetable goes live.

Once an agent can touch a database, send email, or deploy something, the interesting question shifts from "is the answer good" to "how much damage can it do, and would anyone notice." And the damage often isn't one forbidden step. It's a few allowed ones that add up.

This talk is about the practices that catch it. The core one is boring on purpose: mark every moment an agent crosses a line, like reading something untrusted, handing off to another agent, or doing something with real permissions. Write those moments down as plain facts and carry them through every hop. Once they're facts, traces turn into something you can actually search. An attack like "read a poisoned input, then leak data" stops being a scary string to hunt for and becomes "this happened, then that happened."

The reassuring takeaway: little of this is new. Most of it is engineering discipline we already have, a lot of it falls straight out of ordinary Go best practices, and it's no accident memory-safe languages are becoming the default choice for building agents.

Topics
Multi-Agent ArchitecturesAI Observability & ProductionAI Security
Sponsors & Partners
Main Sponsor
copebit — Main Sponsor
Gold
AWS
Silver & Featured Partners
Atlassian Flagsmith namespace re:cinq OpenAI — Workshop Partner Migros Online — End User Partner FHNW Hochschule für Informatik — Educational Partner
Bronze & Partners
BI Concepts Noser Engineering Puzzle ITC Team Extension Your Sidekicks AG AI & ML Events CH Open dev.events Java User Group Switzerland Rocket Engineers SwissDevJobs ZurichJS Conference