Workshop

Secure AI

What happens when a model is allowed to operate tools, and how to limit the damage.

As soon as an AI assistant is allowed to operate tools, meaning it reads files, creates tickets or changes code, a text risk turns into an action risk. The model does not distinguish between what its operator wants and what a text it has read says: to the model, both are text.

Anyone who hands a new employee every key on day one knows the problem: what is dangerous is rarely the intent but the reach. This workshop covers how to limit a model's reach before use cases are discussed. The general picture is covered in What is an AI agent in the enterprise?

Duration
1 day
Format
On site or remote
Group size
Up to 15 people
Language
German or English
The key point up front

Keep a tool list: every tool a model may call, with three answers next to it. Does it read or does it write? Whose permissions does it use? What happens on a misfired call? A tool without these three answers gets no access. You can create this list today, without us. The workshop fills it in for your integrations and settles at which points a human approval belongs in between.

Schedule

Agenda

Presentation plus demonstrations: attacks are demonstrated, not just described. Lukas Hügle leads an internal AI security taskforce and speaks on AI security.

Prompt injection

Direct and indirect: why input filters do not solve the problem and which architecture decisions actually contain it.

Tool security

Which tools an agent may be given, how to cut permissions to size and what a tool should never return.

MCP security

Confused deputy, token passthrough, SSRF, session hijacking and the risks of local servers, each with a demonstration.

Agent security

Excessive agency: what happens when an agent is allowed too much, and at which points a human has to stay in the loop.

Model isolation and data separation

Which data a model may see and how to separate tenants and confidentiality levels cleanly.

Logging and traceability

What has to be logged so that after an incident you can reconstruct what an agent did.

AI governance

Approval process, policy and repeat review: how AI features go into production under control and stay that way.

Practicalities

Who it is for, what you bring, what you take away.

Audience Teams that ship AI features or use agents internally: security engineering, application security, AI development.
Prerequisites A basic understanding of LLM applications, for example from a project of your own. Prior security knowledge is helpful, but not required.
Outcome A threat model for your specific AI use case.
Not included Implementing the measures and testing the system. Both can follow as a project, see Cybersecurity.

Dates and terms are agreed individually.

Contact

Request this workshop.

Write to us which group is to be trained and what should be different afterwards. You get a proposal for scope and schedule.

Request a date