General session image of Knowledge Forum B

When AI Can Hack: Engineering Safe Autonomy for AI Agents

AI agents can now act, not just advise. The challenge is defining what they may do, where they must stop, and how we verify it safely.

Topic

AI & Quantum SecurityWebsecurity / VPNNetwork Security / Patch ManagementGovernance, Riskmanagement and Compliance

When & Where

calendar_month

Wed, 10/28/2026 02:15 PM - 02:30 PM

location_on

Forum B, Booth 7A-206

Download session as iCaldownload_for_offline

Details

  • Format:

    it-sa insights

  • Language:

    English

Session description

Speaker: Muneeb Zafar 

AI agents are moving from systems that generate advice to systems that can act through tools, APIs and connected environments. In offensive security, that shift is especially visible: an agent may be capable of reconnaissance, validation and multi-step attack reasoning, but capability alone does not tell us what it should be allowed to do.

This session introduces the idea of an “autonomy envelope”: externally enforced boundaries around authority, execution environment, side effects, oversight and stop conditions. Using offensive security as a stress test, Muneeb Zafar will show why model-level safety is not enough once AI can act, and why trustworthy autonomy depends on the system architecture around the model.

The principle is simple: maxim ...

Sponsored by