Building Agentic Tools for ProductionGuardrails, governance and security in 2026
38 sessions
PodcastEnterprise AI Operations: The Missing PieceClaimOrganizations should start AI pilots in forgiving back-office settings, provide training, use centralized governance, and measure results continuously.39:26
Tool definitions are the new Prompt EngineeringClaimShared tools can provide organizational governance, but they introduce questions about ownership, access, versioning, and downstream evaluation.47:23
MCP Security: What Happens When Your Agents Talk to Everything?ClaimAll-or-nothing permissions can give an inventory agent access to customer data, financial records, pricing algorithms, and other resources that it does not need.4:46
Co-Engineering: The New Era of Human-AI CollaborationClaimEnterprise coding agents need to account for legacy code, security, compliance, performance, and stability.3:41
Stop Building AI Like Traditional SoftwarePushed backAishwarya Naresh Reganti said prompting should be a last resort for controlling agent access, preferring deterministic guardrails and rule-based access controls.16:30
The Shadow AI Problem Nobody's Talking AboutClaimGiving employees AI tools within guardrails allows them to discover useful use cases that central teams would not have invented themselves.2:44
Tool CallingPushed backLuciana Ledesma argues against uniform governance and favors governance that scales to risk through graded intervention.28:02
Building Artificial Engineering Intelligence for Engineering TeamsClaimAishwarya Shankar says AI coding tools still leave organizations with challenges around safe deployment, security vulnerabilities, and team collaboration.1:57
MCP Security: The Exploit Playbook (And How to Stop Them)ClaimVitor says MCP adoption is accelerating faster than the security protections available for malicious actors.0:27
When Agents Learn to Feel: Multi-Modal Affective Computing in ProductionClaimEmotion-aware systems create risks involving privacy, ownership, consent, transparency, manipulation, and the effects of delegating emotional labor to AI.11:48
Time to become a hackerPushed backMatt Sharp disputes the assumption that the main opportunity in AI is only generative AI investment, saying cybersecurity was the leading organizational investment in 2025.12:14
PodcastCracking the Black Box: Real-Time Neuron Monitoring & Causality TracesClaimMike Oaten says TIKOS can compare live model traces with a normal or expected profile and flag out-of-profile behavior such as possible prompt injection.32:37
PodcastMLflow Leading Open SourcePushed backRedacting all personal information is not always the right governance goal because it can remove valuable information needed for debugging and analysis.52:40
A Playground for AI EngineersClaimHotmart Tutor uses language models, retrieval-augmented generation, vector storage, fallbacks, and guardrails to answer students using only a creator's course content.13:21
Enterprise-ready MCPClaimNatural-language instructions make automation accessible to nontechnical users while also creating a prompt-injection risk.4:56
MCP Dev Summit [Day 1]ClaimAlex Salazar argues that authorization for an agent action should require the intersection of the agent's permissions and the user's permissions.2:59:59
The Coding Agent Multiverse of MadnessClaimCoding agents create a deployment challenge for enterprises because developers use multiple tools while IT must manage separate contracts, consoles, billing systems, usage visibility, and security policies.2:29
Ship Agents: A Virtual Conference Track 2ClaimSecurity remediation needs to move into the developer workflow instead of being handled only near deployment or in production.28:29
A New Kind of MarketplaceClaimPedro Chaves says an intermediate marketplace layer could provide trust, escrow, agent discovery, and connections between supply and demand.41:40
OpenXData ConferencePushed backSatish argued that language-model judges should not be the root of trust for SQL governance.2:21:51
Stop AI Agents From SQL Injecting Your DatabasePushed backAveri Kitsch says there is not yet a clearly established best natural-language-to-SQL technique for answering difficult analytical questions securely.15:23
Building AI Agents That Survive ProductionClaimHaytham Abuelfutuh says agent-generated code should run in a secure, network-isolated environment that is separated from the host.20:22
Architecting Modern AI SystemsClaimThe hackathon focused on building guardrails for mental-health conversational agents, including deciding when to transfer a sensitive conversation to a human.2:14
PodcastAgents & the $40M Bet on Multiplayer AIClaimStanislas Polu says early Stripe worked with little management because people had local trust, distant attraction through open writing, and alignment around a clear vision.4:02
PodcastAutonomous Agents at Work: From OpenClaw Hype to Enterprise RealityClaimOpenClaw demonstrated the possibilities of highly autonomous agents but also exposed serious security problems when adequate controls were absent.14:02
Omnigent: Composition, Control, and Collaboration for AI AgentsClaimDenny Lee says token spending repeats the shift from centralized CapEx control to developer-aware OpEx and requires both developer visibility and central governance.40:08
Sandboxing, Agent Harnesses, and Agent TeamworkClaimAgent teams will need governance, shared context, isolation, and explicit rules about when one agent must listen to, consult, or inform another.1:04:24
Policy Enforcement and Tamper-Evident Audit ChainsPushed backImran Siddique argued that governance alone is insufficient and that verifiability is also required.2:39
Before the Agent Calls: Source-level Findings from 100 MCP ServersPushed backThe host suggested that read operations could also be vulnerabilities through information leakage, while Akash Sathish had primarily described executable commands and library calls as sinks.23:37
Responsible Autonomy: Building Governance Frameworks for AI That Act in the Real World via MCPClaimSaurabh Mishra says organizations need policies, identity and access controls, and human approval points to govern agents that can affect real-world systems.4:54
What We Learned from Dozens of Enterprise MCP DeploymentsPushed backThe discussion separates what companies should build from what they should buy: companies should build business-specific MCP layers but may buy trusted infrastructure for routing, authentication, security, and encryption.24:12
Reading groupPrompt Injection as Role Confusion: Rethinking Agent SecurityClaimArthur says instruction hierarchies, which assign different priorities to roles, are one mechanism for substantially reducing prompt injection.1:12




