Elektrine lite

← Feed

@danielkennedy74@infosec.exchange

Post #1787839

2026-04-29 19:54 UTC

If a prevailing theme at RSAC 2025 was the role of co-pilots to leverage large language model capabilities in security tooling via a chat interface, RSAC 2026 considered agentic AI in situations where the price of hallucinations may be a wrong or destructive autonomous action in a live production environment. Much of "security for AI" today consists of guardrails in a chat context; similarly, the first stages of AI in code creation consisted of auto-complete. Without necessarily solving the application security issues associated with greater speed, larger pull requests and a different mix of vulnerabilities, we are quickly entering a phase where applications can be created via prompt and agentic interplay, and questions are emerging just as quickly about how reasonable controls can ensure security visibility into agentic workflows and assure that code entering production is secure. A number of potential answers are emerging from various corners of application security, including how to efficiently use AI to find vulnerabilities or token-efficient triage, without it inefficiently spinning out using excessive tokens. There is ongoing exploration into guiding developers' prompting to ensure that security requirements are accurately captured. Secure supply chain vendors are exploring how to ensure only safe models, along with vetted open-source and known-good Model Context Protocol servers. This effort aligns with software bill of materials (SBOM) initiatives, which are now incorporating AI bill of materials (AI BOM) to enhance transparency and security. There are considerations for how "human in the loop" can actually work. Given that, in a liability-based culture, AI agents can't be held responsible, what tooling will actually be needed to ensure accurate review? The "proximate human most likely to be blamed" needs some arming to actually evaluate AI outputs and reasoning. There are considerations to providing a "paved road" of components to support prompt-created micro-applications. On the offensive security side, AI is facilitating machine-speed vulnerability chaining. Increasingly, "runtime context" means examining what autonomous agents are accessing. https://www.spglobal.com/market-intelligence/en/news-insights/research/2026/04/rsac-conference-2026-confronting-both-the-promise-and-threat-of-agentic-ai

Replies (0)

No replies.