AI Superstream: Securing Agentic Systems
Published by O'Reilly Media, Inc.
Safeguard the next generation of AI agents
As organizations rapidly adopt agentic AI, new and serious risks have emerged: prompt injection, agent hijacking, goal misalignment, autonomous misuse, data leaks, and compliance challenges. Protecting AI that thinks, decides, and acts independently is critical to keeping it working for you. Discover how to safely deploy and govern the next generation of AI agents from the people who know them best, and pick up actionable strategies to secure, monitor, and govern agentic systems without slowing down innovation.
We’re still working on finalizing the schedule for this event. Please check back closer to the event date for more information.
What you’ll learn and how you can apply it:
- Secure agents by controlling identity, tools, and permissions.
- Safely steer agent decisions with real-time guidance, workflows, and approvals.
- Defend against emerging threats, including prompt injection, hijacking, and data leaks.
Recommended follow-up:
- Read Securing AI Systems (early release book)
- Take Agentic AI Security Bootcamp (live online course with Dr. Petar Radanliev)
- Take Agentic AI Safety and Security (live online course with Thomas Nield)
Schedule
The time frames are only estimates and may vary according to how the class is progressing.
Introduction – Andreas Welsch (5 minutes)
Andreas welcomes you to the AI Superstream.
Who’s Behind the Agent? Securing AI at the Edge – Vicki Reyzelman (35 minutes)
AI agents don’t browse; they act. They shop, transact, and call your APIs on behalf of real users, and they’re already a fast-growing slice of your traffic. That breaks every assumption baked into your WAF and bot tools, which were built to ask “human or bot?” Agents force a harder question: who’s behind this one, what does it want, and should it be allowed to act? Vicki Reyzelman, a senior solutions engineer at Akamai, gives you a working model for securing agents across their real attack surface: verify identity and tie it to a human, infer intent to catch good actions chained toward bad outcomes, rein in over-permissioned API access, and enforce trust at the edge in real time. You’ll leave knowing where legacy defenses break, and how to shape agentic traffic instead of fearing it.
Your Agent Needs a Steering Wheel – Sandhya Subramani (35 minutes)
How can we build autonomous agents that have room to reason without allowing unchecked decisions? Whether reviewing loan applications, handling medical requests, triaging security incidents, resolving customer issues, or operating in other high-stakes environments, agents need to adapt while still following required steps, respecting approval boundaries, recovering from tool failures, and communicating in the right tone. Prompts cannot reliably control behavior throughout execution, guardrails often catch problems only at the input or output layer, and rigid workflows sacrifice flexibility. Senior developer advocate Sandhya Subramani introduces steering, a just-in-time guidance mechanism inside the agent loop that applies deterministic control at runtime. Through a live demo using an open source agentic framework, you’ll learn how to influence agent actions, guide recovery, enforce required steps, shape conversational boundaries, and add approval points, all without sacrificing the flexibility that makes agents useful.
Break (5 minutes)
The Agentic Attack Surface: How Autonomous AI Gets Compromised and How to Stop It – Sagar Rao (35 minutes)
Most agentic breaches start with someone manipulating the agent through the content it reads, then abusing the fact that the agent can act far beyond what the task requires. AWS senior technical account manager Sagar Rao takes you through how an agentic attack unfolds, from a hidden instruction planted in a trusted source, to the agent chaining its own tools, and finally to a quiet data leak. He pairs each stage with the control that stops it. You’ll leave with a repeatable defense-in-depth pattern and a practical checklist you can apply to your own agents, independent of which model, framework, or tools you use.
When Agents Go Off-Script: Prompt Injection, Hijacking, and Goal Misalignment – Udita Patel (35 minutes)
Once an LLM can browse, call tools, and act on retrieved content, every untrusted token becomes a potential instruction, and the classic distinction between data and command collapses. Udita Patel, senior applied scientist at Amazon, takes a science-driven look at three failure modes that matter most in production: indirect prompt injection through tools and retrieved context, agent hijacking across multistep and multi-agent workflows, and goal misalignment, where an agent pursues a plausible objective, but not the one you asked for. You’ll see how these attacks work and what defense-in-depth looks like when the attack surface is the agent’s own reasoning loop. Take away a concrete threat model for your own agents and a set of mitigations you can evaluate against it.
Break (5 minutes)
Session to Come (35 minutes)
Please check back for more information.
Session to Come (35 minutes)
Please check back for more information.
Closing Remarks – Andreas Welsch (5 minutes)
Andreas closes out today’s event.
Your Hosts and Selected Speakers
Andreas Welsch
Andreas Welsch is a definitive voice in the shift toward agentic AI, specializing in helping enterprises navigate from chatbots to autonomous systems. The founder of Intelligence Briefing and author of The HUMAN Agentic AI Edge, Andreas draws on 20 years of experience, including a decade of global leadership at SAP, to demystify the technical architecture behind business AI. Recognized as a Top 10 Thought Leader in Agentic AI, he is a frequent keynote speaker and educator whose work has been featured in VentureBeat, CIO.com, and InformationWeek.
Vicki Reyzelman
Vicki Reyzelman is a senior solutions engineer at Akamai, where she helps organizations around the globe protect and secure their online applications. She’s worked extensively in the fields of cloud integration, security, API ecosystems, and software development and has written dozens of blog posts and articles on technology solutions to business problems and on technology trends for e_Week_ magazine. She’s also a patent holder for a search assistant technology at Yahoo! Vicki holds an AI certificate from MIT, an MBA from Georgia State University and a bachelor’s degree in computer science from Kennesaw State University.
Sandhya Subramani
Sandhya Subramani is a senior developer advocate with over 10 years of experience in applied AI research, currently specializing in large language models and agentic AI systems. She has developed and deployed AI solutions at organizations including Amazon, Warner Bros., and Fidelity Investments. Her work focuses on translating cutting-edge research into practical applications, with a growing focus on AI governance, agent reliability, and responsible deployment. Sandhya is passionate about helping developers build intelligent systems that solve complex problems at scale.
Sagar Rao
Sagar Rao is a senior technical account manager at Amazon Web Services, where he partners with Fortune 500 financial services organizations to design, secure, and scale their most critical cloud workloads. With nearly six years at AWS and deep expertise in AI/ML security, cloud architecture, and operational resilience for regulated industries, Sagar helps FSI organizations adopt generative AI responsibly, balancing innovation velocity with regulatory expectations.
Udita Patel
Udita Patel is a senior applied scientist at Amazon, where she leads science strategy for language modeling and builds enterprise-scale agentic AI systems. Her work spans LLM evaluation, long-context modeling, and the new failure modes that appear once agents gain tools and autonomy. She has spent 10 years in applied ML and NLP and speaks regularly on the science of making AI systems trustworthy at production scale.