Talks

Conference recordings and slide decks on agent identity, honeypot research, and authorization telemetry. Every deck is the version presented, with the date it was given.

Video thumbnail for Honeypotting AI agents
HOPE 2026Gramercy track, New York

Honeypotting AI agents

Who is attacking them, how, and what they are after

Four sensors run against the open internet: a Shodan sweep for exposed agent infrastructure, pages carrying labelled payloads to see what reads them, a crawler looking for injection payloads other people planted, and twenty-two fake agents advertising credentials. The talk walks through what each one measured, including a sanctioned court filing that carried a hidden instruction, and why recon traffic and attack traffic are not the same thing.

HoneypotsIndirect prompt injectionMCPThreat research

No standalone recording was published. The link opens the full HOPE 2026 Track 3 day stream from ISOC LIVE, which starts at 07:48 EDT and runs about ten hours. This talk is scheduled for 14:00 EDT, roughly six hours in.

IEEE SVCC 2026, industry speaker sessionSan Jose

The identity crisis of autonomous AI

Why your agents need cryptographic proof

Why human IAM does not carry over to actors that authenticate once and then act thousands of times without a session boundary. Covers the thirteen open specifications across identity, trust, authorization, threat modeling, and observability, and the conformance suites that back them.

Cryptographic identityOpen specificationsConformanceAuthorization
Video thumbnail for Identity management for AI agents
Open Source Summit North America 2026The Linux Foundation

Identity management for AI agents

What forty years of IAM teaches about the layer above identity

Identity is point-in-time. An agent verified thirty seconds ago can read a page carrying an injection and still hold a valid identity. The talk traces three lessons out of four decades of identity engineering, cryptographic identity over credentials, least privilege over blanket access, and audit trails, then applies each to AI agents. Ends with a live prompt injection against a flight booking agent.

Agent identityLeast privilegeCapability enforcementAudit trails
Video thumbnail for Observing the observers
Observability Summit North America 2026CNCF

Observing the observers

Bringing OpenTelemetry to autonomous AI agents

Traces record what happened. They do not record who acted, or whether the action was authorized. This talk proposes nine semantic convention attributes covering agent identity, decision inputs, and the fine-grained authorization decision path, and shows the same attributes emitted from two different agents into one Tempo dashboard.

OpenTelemetrySemantic conventionsAuthorization telemetryAnomaly detection

Check the work

Figures in a deck are point-in-time, measured on the date shown on the slide. The sweeps, queries, and write-ups behind them are published separately.

Speaking inquiries and conference invitations: info@opena2a.org