Skip to main content

Talks

Conference recordings and slide decks on agent identity, honeypot research, and authorization telemetry. Every deck is the version presented, with the date it was given.

WeAreDevelopers World Congress North America 2026Stage 5

Securing AI agent infrastructure

Identity, attestation, and behavioral trust at scale

System prompts are suggestions, not security controls, so the talk moves enforcement to the tool call. Three rings sit around it: an identity that is a keypair the host generates, a capability grant where anything not granted does not exist, and a signed trail of every decision, allowed and refused. Covers tool attestation and drift, a trust score that moves with behavior, and a live run of the same agent code with and without an identity.

Agent identityTool callsMCPCapability grants
GSX 2026Georgia World Congress Center, Atlanta

AI Agent Governance

Extending IAM Principles to Autonomous Machine Identities

Your IAM program can name every human identity and none of the agents. The talk separates managed from unmanaged agents, shows how to inventory the unmanaged ones on a laptop with one command and stop new ones shipping from CI, and walks through what an agent identity is: a key pair, capability grants, and an audit trail that maps to PAM and SIEM. Closes with the same agent run unmanaged and then under AIM, and the design partner program.

Agent identityShadow AIIAMGovernance
Video thumbnail for Honeypotting AI agents
HOPE 2026New Yorker Hotel, New York

Honeypotting AI agents

Who is attacking them, how, and what they are after

Four sensors run against the open internet: a Shodan sweep for exposed agent infrastructure, pages carrying labelled payloads to see what reads them, a crawler looking for injection payloads other people planted, and twenty-two fake agents advertising credentials. The talk walks through what each one measured, including a sanctioned court filing that carried a hidden instruction, and why recon traffic and attack traffic are not the same thing.

HoneypotsIndirect prompt injectionMCPThreat research

No standalone recording was published. The link opens the full HOPE 2026 Track 3 day stream from ISOC LIVE, which starts at 07:48 EDT and runs about ten hours. This talk is scheduled for 14:00 EDT, roughly six hours in.

IEEE SVCC 2026, industry talksSan Jose State University

The identity crisis of autonomous AI

Why your agents need cryptographic proof

Why human IAM does not carry over to actors that authenticate once and then act thousands of times without a session boundary. Covers the thirteen open specifications across identity, trust, authorization, threat modeling, and observability, and the conformance suites that back them.

Cryptographic identityOpen specificationsConformanceAuthorization
Video thumbnail for Observing the observers
Observability Summit North America 2026Minneapolis

Observing the observers

Bringing OpenTelemetry to autonomous AI agents

Traces record what happened. They do not record who acted, or whether the action was authorized. This talk proposes nine semantic convention attributes covering agent identity, decision inputs, and the fine-grained authorization decision path, and shows the same attributes emitted from two different agents into one Tempo dashboard.

OpenTelemetrySemantic conventionsAuthorization telemetryAnomaly detection
Video thumbnail for Identity management for AI agents
Open Source Summit North America 2026Minneapolis

Identity management for AI agents

What forty years of IAM teaches about the layer above identity

Identity is point-in-time. An agent verified thirty seconds ago can read a page carrying an injection and still hold a valid identity. The talk traces three lessons out of four decades of identity engineering, cryptographic identity over credentials, least privilege over blanket access, and audit trails, then applies each to AI agents. Ends with a live prompt injection against a flight booking agent.

Agent identityLeast privilegeCapability enforcementAudit trails

Check the work

Figures in a deck are point-in-time, measured on the date shown on the slide. The sweeps, queries, and write-ups behind them are published separately.

Speaking inquiries and conference invitations: info@opena2a.org