
When AI Can Hack: Engineering Safe Autonomy for AI Agents
AI agents can now act, not just advise. The challenge is defining what they may do, where they must stop, and how we verify it safely.
Topic
When & Where
Details
Format:
it-sa insights
Language:
English
Session description
Speaker: Muneeb Zafar
AI agents are moving from systems that generate advice to systems that can act through tools, APIs and connected environments. In offensive security, that shift is especially visible: an agent may be capable of reconnaissance, validation and multi-step attack reasoning, but capability alone does not tell us what it should be allowed to do.
This session introduces the idea of an “autonomy envelope”: externally enforced boundaries around authority, execution environment, side effects, oversight and stop conditions. Using offensive security as a stress test, Muneeb Zafar will show why model-level safety is not enough once AI can act, and why trustworthy autonomy depends on the system architecture around the model.
The principle is simple: maxim ...

