Skip to main content

oct 15 / san franciscowestin st. francissingle track

This is the AISS flagship event.

One full day. One room. No filler.

The people building with AI and the people who own the risk, on the same stage: agent identity, attacks at machine speed, AI-powered defense, and where the money is (or should be) going.

our-partners/

AgentCloak Arcjet AWS Cognition CrewAI Galileo AI Guidepoint HumanLayer NVIDIA Oleria Qodo RunSybil Skyflow
founding partners
founding sponsor
Arcade Atlassian Casco Cohesity Docker Google Harvey JPMC Okta Orca RBC ServiceNow SpecterOps Anthropic Arize Keycard Microsoft Opaque Systems

Interested in sponsoring an AI Security Summit edition? Partner with us at the San Francisco flagship event or one of our satellite regional editions, and put your work in front of people who evaluate on technical merit. Email us to register your interest: partners@aisecuritysummit.com

room.audience()

who-should-attend/

The people who own AI risk at the org level: setting budgets, signing off on vendors, and writing the governance playbook in real time.

  • CISOs, CTOs, VPs of Security and Heads of AI
  • Leaders who set risk budgets and choose vendors
  • The people who answer to the board when something goes wrong

topics we'll cover

  1. Trusting what the AI software factory ships
  2. Agent identity, auth, and where to start on agent security
  3. Attacks at machine speed, and what the research shows
  4. Open source and open models in AI-powered defense
  5. How enterprise leaders, investors, and CISOs are weighing AI risk

register.now()

save-your-seat/

in-person/register/

Registration open

One room, sized for the people who own AI risk. Register to claim your seat at the Westin St. Francis.

What's included

  1. A full day in one room: keynotes, fireside chats, panels, and the people doing the work, up close
  2. Zero vendor fluff: published research and trade-offs from the people who made them

loading registration form

agenda.schedule()

agenda/

The hard calls on AI risk: budgets, vendors, and deciding what your org defends vs. what it accepts.

speakers.featured()

We book speakers who've done the work: made the calls on AI risk at scale, owned the outcomes, and can show what happened next. Our bar is high. More speakers are announced as they're confirmed.

october_14_2026

  • 16:30 – 17:301 hr
    panel

    The AI Security Panel: Unfiltered

    • Deirdre Bosa Yahoo Finance
    • Manoj Nair Snyk
    • Michael D'Angelo OpenAI
    • John Hultquist Google Threat Intelligence
    • Ed Sim boldstart ventures

    Golden Gate Room, Westin St. Francis, 335 Powell St, San Francisco, CA 94102. Free. Separate registration on Luma.

october_15_2026

  • 09:00 – 09:30Breakfast & Registration
  • 09:30 – 09:4010 min

    Opening

    • Snyk
  • 09:40 – 10:0020 min
    keynote

    The AI Hurricane Is Here: Build for the Storm

    • Snyk
  • 10:00 – 10:2525 min
    panel

    AI Agents: Attack Capabilities and Security Risks

    • Carnegie Mellon
    • NTU & NVIDIA
    • moderated by Snyk

    Classical security was built for human-timescale attacks and human-timescale defenses, but that foundation is being tested as AI enables attacks that operate at machine speed. In this research panel, leading academic security researchers cut through the industry noise to share what the data actually shows: where AI vendors' security practices and public narratives diverge from what's really happening, why systems-level thinking (not a pure-AI lens) is essential to this problem, and how rapidly improving open-weight models are simultaneously democratizing red teaming and lowering the bar for unsophisticated attackers. Grounded in original research rather than marketing claims, this conversation gives security leaders a clear-eyed view of where the frontier actually stands, and what "security by obscurity" gets wrong.

  • 10:25 – 10:5025 min
    fireside chat

    Open Source at the Inflection Point: A Fireside Chat with Anthropic on AI-Powered Defense

    • Anthropic
    • moderated by Snyk

    Open source security has hit an inflection point: AI models can now find and fix vulnerabilities at a scale no maintainer community can match by hand, and many organizations are turning to commercially patched distributions for support. Liran and Punit unpack where Project Glasswing has moved the needle most, what best practices are emerging, closing with a candid look ahead at the future of open source: can maintainers keep pace, or does secure open source become something you buy?

  • 10:50 – 11:00Break
  • 11:00 – 11:2525 min
    keynote

    Building a Software Factory You Can Trust

    • Tessl
  • 11:25 – 11:5025 min
    fireside chat

    Building with Open Models and Agents: Securing AI-Driven Software

    • NVIDIA
    • Cognition
    • moderated by Vinod D'Souza Google

    Software factories run on agents, and agents run on models. As teams choose between closed APIs and open-weight models they can inspect, fine-tune and host themselves, the security question shifts from the model to the pipeline around it. Faisal Tameesh (NVIDIA) and Jeff Wang (Cognition) discuss where open models earn trust, where agents need guardrails, and what leaders should decide now.

  • 11:50 – 12:3040 min
    panel

    Investor Panel: What Investors Are Actually Seeing in AI Security

    • BlackRock
    • Boldstart
    • Lightspeed Ventures
    • moderated by Snyk

    AI spend inside enterprise IT went from 1% to 10% in a year, and half of that is now security: one line in a much bigger reset. Software pricing is shifting from seats to usage, cost management is catching up with what these models actually cost to run, and open-weight models are closing the gap on the frontier. Add governments intervening directly on model access and chips, a regulatory regime still being written, and the oldest question in software moving at a new speed: vendor market or in-house, as LLMs speed up how fast anyone can ship. This panel brings together investors from first-check to public markets for an unfiltered read on what each of them is actually seeing.

  • 12:30 – 13:30Lunch
  • 13:30 – 14:0030 min
    panel

    AAuth: Moving Beyond OAuth

    • Keycard
    • Independent
    • hello.co
    • moderated by Insecure Agents
  • 14:00 – 14:2525 min
    panel

    Scaling AI Across the Enterprise: How Leaders Are Managing Risk Without Slowing Down

    • Cyera
    • Telus Digital
    • Snyk
  • 14:25 – 14:5025 min
    panel

    Policy at the Point of Access: Where Does the AI Control Plane Live?

    • Island
    • 1Password
  • 14:50 – 15:00Break
  • 15:00 – 15:2525 min
    fireside chat

    The Agent Baseline: Where Should You Start?

    • Keycard
    • Docker
    • Marcelo Sousa Snyk
  • 15:25 – 15:4520 min
    talk

    The Rise of the Watcher Agent

    • Arize AI
  • 15:45 – 16:3045 min
    panel

    CISO Debate

    • Secure Theory
    • Aaron Brown Mercor
    • Bil Harmer Supabase
    • moderated by Snyk
  • 16:30 – 17:301 hr
    networking

    Happy Hour

    Networking before the official AISS after-party.

  • 17:30 – 20:303 hr
    networking

    Official AISS after-party: AAuth Night

    111 Minna Gallery, 111 Minna St, San Francisco, CA 94105. Free. Separate registration on Luma.

venue.location()

venue/

venue.details()

Westin St. Francis

335 Powell St, San Francisco, CA 94102

directions

A San Francisco landmark on Union Square, open since 1904. The event spaces have the bones to match: grand ballrooms with carved ceilings and gilt pillars in the historic Landmark Building, and floor-to-ceiling views of the Bay Bridge and Golden Gate from the 32nd floor. The kind of venue where the room does some of the work for you.

panel.unfiltered()

the-ai-security-panel/

The afternoon before the flagship event, on the 32nd floor of the same hotel. Hosted by Snyk.

The AI Security Panel: Unfiltered, with Snyk, OpenAI, Google Cloud and boldstart.

on the panel

  • moderator Deirdre Bosa Host, DB Live, Yahoo Finance
  • panelist Manoj Nair CTO and Chief Innovation Officer, Snyk
  • panelist Michael D'Angelo Technical Lead, Cyber, OpenAI
  • panelist John Hultquist Chief Analyst, Google Threat Intelligence
  • panelist Ed Sim Founder and General Partner, boldstart ventures

The threat now

What attackers are already doing with AI, what red teamers are finding models can do, and how the software supply chain became a front line.

The threat to come

What gets hit first, how fast it spreads, and whether the market is pricing it in. Is "tsunami" just fearmongering?

Who owns it

Whether a lab should ever certify its own model as safe, what only government can do, and who is furthest behind.

What to do Monday morning

What infrastructure can realistically contain, how to use open models safely, and the one move every CISO should make before a frontier-class open model ships.

date

Wed, Oct 14

time

4:30 to 5:30 PM PDT

Register free on Luma

after.hours()

official-after-party/

Official AISS after-party

The summit's official after-party, co-hosted with Insecure Agents. After happy hour, head to 111 Minna Gallery for live demos of AAuth, the agent auth protocol from OAuth's author Dick Hardt, lightning talks, and drinks.

AAuth Night: Moving Beyond OAuth, from The AI Security Summit. Thursday, October 15, San Francisco, CA, 5:30 PM to 8:30 PM PDT.
date
Thursday, October 15, 2026
time
5:30 to 8:30 PM PDT
hosts
AI Security Summit with Insecure Agents, powered by Keycard
entry
Free. Separate registration on Luma.
Register on Luma

mission.why()

the-mission/

The best AI security knowledge right now lives inside companies. It's in incident reports that nobody publishes, in architecture decisions that never leave the engineering org, in red team findings that stay in internal wikis. AISS exists to get that knowledge on stage.

San Francisco is where it all started. AISS launched here in 2025 and sold out. The city has been its flagship ever since. Satellite editions take AISS to other cities around the globe: Copenhagen and Sydney follow on November 25.

We select talks the way peer review works: show us what you found, how you tested it, and what happened once it hit production.

There's no place for platitudes, no panels where everyone agrees: the tough conversations are welcome here.

That's the deal: practitioners share what they've found, built, broken, or defended. Leaders share the real-life trade-offs behind the decisions they've made. In a room of the people who own AI risk, that level of honesty is worth it.

75+ speakers across five events
500+ attendees builders and defenders
45+ sessions talks, workshops, panels

latest-videos/

keynote · London 2026

Agentic Development Security: The Three Problems Nobody Was Solving and the One That Matters Most for 2026

Manoj Nair, Snyk

Three security problems in agentic development: the tools agents use, how they behave, and the code they produce.

View all videos

register.now()

secure-the-thing-
everyone-is-shipping/

Save your seat