MEETUP
Don’t Trust the Model: Securing Agents That Act on Your Data
The moment an agent can take actions, the security question shifts from “what can it see?” to “what can it do, and what stops it?” – and you can’t answer that by trusting a non-deterministic, promptable model to behave. Late in 2025, a coding agent with too much permission decided the fix for a bug was to delete and recreate a production environment.
This talk covers the layers that make agent autonomy defensible – least-privilege identity, gateway authorization, human approval on destructive actions, guardrails, and audit – each mapped to a real failure it prevents.
