# Security & safety — AI Engineer Sydney 2026

> Agents can browse, call tools, mutate systems and act with delegated authority. This collection examines red-teaming, isolation, runtime protection and safer architectures for containing that expanded attack surface.

Canonical page: https://webdirections.org/ai-engineer/topics/security-safety/
Program status: The speaker lineup and talk descriptions are public. Session days, times, rooms and the full timetable have not yet been published.

## Published talks

- [Autonomous agents need autonomous protection](https://webdirections.org/ai-engineer/speakers/adesh-gairola-2/) — Adesh Gairola
  Autonomous agents need autonomous protection. An agent that acts alone at 3am cannot wait for a quarterly pen test, a consultant's report, or a security engineer the team does not have. We started with the data. We built and published an open threat intelligence map, 6,330 documented AI security incidents connected to 217 attack techniques and the control…
- [Oops I Hacked It Again: Six Months of Red Teaming Our AI Agents](https://webdirections.org/ai-engineer/speakers/jon-shen/) — Jon Shen
  In March I onboarded our first team member dedicated to AI Red Teaming. That was a month before the announcement of Claude Mythos Preview, and the open letters that followed from APRA in April and ASIC in May (Australia’s prudential and conduct regulators) warning organisations to act by shoring up their AI risk management and security practices. We moved…
- [Deliberate Holes Only](https://webdirections.org/ai-engineer/speakers/karla-burnett/) — Karla Burnett
  Making an AI agent vulnerable to exactly one attack is harder than making it completely secure, let alone doing it six different times. In this talk, I'll describe the process of building an agentic AI capture the flag challenge (https://owngoal.lorikeetcx.ai), in which each level has a more sophisticated agent than the last, always with one hole left for a…
- [Building a Security Agent: Model choice, Harnesses and Evals](https://webdirections.org/ai-engineer/speakers/simon-harloff/) — Simon Harloff
  In this presentation, I’ll show how we set out to give developers useful security feedback on every pull request in under three minutes. The benchmark results and methodology are published here: https://docs.damsecure.ai/blog/pr-review-security-benchmark-update/. It has become our most-cited research to date. We initially expected to compare models using…
- [Query before mutation: guardrail patterns for agents that touch production infrastructure](https://webdirections.org/ai-engineer/speakers/jeffrey-aven/) — Jeffrey Aven
  Covered in the session: - Why plan-and-apply was always a human safety mechanism: a person reads the plan, notices something is off, and stops the apply - and why this quietly disappears the moment an agent is the operator - Query before mutation as the foundational pattern: requiring agents to establish current state from the live environment before any…
- [Don't Fight Hallucinations. Make Them Impossible](https://webdirections.org/ai-engineer/speakers/nadia-makarevich/) — Nadia Makarevich
  The Heatseeker AI chat answers data questions for marketers who make decisions with million-dollar budgets. Wrong answers or hallucinated numbers are not an option here, as you can imagine ;) The fight against them (hallucinations, not marketers) was long and painful. We started with a "naive" approach, which we all tried at some point, I imagine: "Hey, AI,…
- [Assert Chaos](https://webdirections.org/ai-engineer/speakers/chris-lienert/) — Chris Lienert
  Once a product reaches the wilds of production, all sorts of things can go wrong. Carefully logging and monitoring are one thing, but what if we could do better? Bring new levels of code stability by recreating the ‘cat on a keyboard’ randomness of production with a chaos test agent. This talk goes through what it takes to implement chaos test agents on a…
- [AI Sandboxes: Running Coding Agents Safely in Production-Grade Environments](https://webdirections.org/ai-engineer/speakers/shivay-lamba/) — Shivay Lamba
  The number of cyber attacks and security risks related to Coding Agents has sky rocketed. AI coding agents like Claude Code, Codex CLI, and Gemini CLI don’t behave like your typical developer tools. They install system packages, modify configurations, delete files, run services, and even spin up Docker containers, often requiring constant permission prompts…

The timetable is not public. This page does not imply a day, time, room or track.

- [Explore the whole programme](https://webdirections.org/ai-engineer/program/)
- [Conference overview](https://webdirections.org/ai-engineer/index.md)
