---
title: "AI Security Summit San Francisco 2026"
description: "AI Security Summit is coming to San Francisco, CA on October 15, 2026. The flagship event. One full day. One room. No filler."
canonical: "https://aisecuritysummit.com/"
---

# AI Security Summit San Francisco 2026

> October 15, 2026 at the Westin St. Francis in San Francisco, CA.

The flagship AI Security Summit is one day in one room, for the people who own AI risk at the org level. Registration, the agenda, the speakers and the venue are all on this page.

## Event details

- Date: October 15, 2026
- Starts: 2026-10-15T09:00:00-07:00
- Location: San Francisco, CA
- Venue: Westin St. Francis, 335 Powell St, San Francisco, CA 94102
- Format: Single track
- Registration: open. Register on the event page: https://aisecuritysummit.com/#register

## Who should attend

The people who own AI risk at the org level: setting budgets, signing off on vendors, and writing the governance playbook in real time.

- CISOs, CTOs, VPs of Security and Heads of AI
- Leaders who set risk budgets and choose vendors
- The people who answer to the board when something goes wrong

Topics:
- Trusting what the AI software factory ships
- Agent identity, auth, and where to start on agent security
- Attacks at machine speed, and what the research shows
- Open source and open models in AI-powered defense
- How enterprise leaders, investors, and CISOs are weighing AI risk

## Agenda

### October 15, 2026

- **09:00 – 09:30** Breakfast & Registration (networking)
- **09:30 – 09:40** Opening
  - Speakers: Ken MacAskill (CEO, Snyk)
- **09:40 – 10:00** The AI Hurricane Is Here: Build for the Storm (keynote)
  - Speakers: Manoj Nair (CTO & Chief Innovation Officer, Snyk)
- **10:00 – 10:25** AI Agents: Attack Capabilities and Security Risks (panel)
  - Speakers: Vyas Sekar (Tan Family Professor of Electrical and Computer Engineering, Carnegie Mellon); Jingxuan He (Researcher, NTU & NVIDIA)
  - Moderator: Maximilian Baader (Staff Research Engineer, Snyk)
  - Classical security was built for human-timescale attacks and human-timescale defenses, but that foundation is being tested as AI enables attacks that operate at machine speed. In this research panel, leading academic security researchers cut through the industry noise to share what the data actually shows: where AI vendors' security practices and public narratives diverge from what's really happening, why systems-level thinking (not a pure-AI lens) is essential to this problem, and how rapidly improving open-weight models are simultaneously democratizing red teaming and lowering the bar for unsophisticated attackers. Grounded in original research rather than marketing claims, this conversation gives security leaders a clear-eyed view of where the frontier actually stands, and what "security by obscurity" gets wrong.
- **10:25 – 10:50** Open Source at the Inflection Point: A Fireside Chat with Anthropic on AI-Powered Defense (fireside chat)
  - Speakers: Punit Shah (Frontier Red Team, Anthropic)
  - Moderator: Liran Tal (Senior Director, Developer Relations, Snyk)
  - Open source security has hit an inflection point: AI models can now find and fix vulnerabilities at a scale no maintainer community can match by hand, and many organizations are turning to commercially patched distributions for support. Liran and Punit unpack where Project Glasswing has moved the needle most, what best practices are emerging, closing with a candid look ahead at the future of open source: can maintainers keep pace, or does secure open source become something you buy?
- **10:50 – 11:00** Break
- **11:00 – 11:25** Building a Software Factory You Can Trust (keynote)
  - Speakers: Guy Podjarny (Founder and CEO, Tessl)
- **11:25 – 11:50** Building with Open Models and Agents: Securing AI-Driven Software (fireside chat)
  - Speakers: Faisal Tameesh (Security Researcher, NVIDIA); Jeff Wang (President of Emerging Markets, Cognition)
  - Moderator: Vinod D'Souza
  - Software factories run on agents, and agents run on models. As teams choose between closed APIs and open-weight models they can inspect, fine-tune and host themselves, the security question shifts from the model to the pipeline around it. Faisal Tameesh (NVIDIA) and Jeff Wang (Cognition) discuss where open models earn trust, where agents need guardrails, and what leaders should decide now.
- **11:50 – 12:30** Investor Panel: What Investors Are Actually Seeing in AI Security (panel)
  - Speakers: Tony Kim (Managing Director, BlackRock); Ed Sim (Founder and General Partner, Boldstart); Sebastian Duesterhoeft (Partner, Lightspeed Ventures)
  - Moderator: Ken MacAskill (CEO, Snyk)
  - AI spend inside enterprise IT went from 1% to 10% in a year, and half of that is now security: one line in a much bigger reset. Software pricing is shifting from seats to usage, cost management is catching up with what these models actually cost to run, and open-weight models are closing the gap on the frontier. Add governments intervening directly on model access and chips, a regulatory regime still being written, and the oldest question in software moving at a new speed: vendor market or in-house, as LLMs speed up how fast anyone can ship. This panel brings together investors from first-check to public markets for an unfiltered read on what each of them is actually seeing.
- **12:30 – 13:30** Lunch (networking)
- **13:30 – 14:00** AAuth: Moving Beyond OAuth (panel)
  - Speakers: Jared Hanson (Co-Founder, Keycard); Karl McGuinness (Advisor, Independent); Dick Hardt (Founder & CEO, hello.co)
  - Moderator: Allie Howe (Founder, Insecure Agents)
- **14:00 – 14:25** Scaling AI Across the Enterprise: How Leaders Are Managing Risk Without Slowing Down (panel)
  - Speakers: Eddie Borrero (CIO, Cyera); Adrian Guevara (CISO, Telus Digital); Ezra Tanzer (AI Forward Deployed CTO, Snyk)
- **14:25 – 14:50** Policy at the Point of Access: Where Does the AI Control Plane Live? (panel)
  - Speakers: Jason Trunk (Field CTO, Island); Aashish Tripathi (Product, Strategy & Commercialization, 1Password)
- **14:50 – 15:00** Break
- **15:00 – 15:25** The Agent Baseline: Where Should You Start? (fireside chat)
  - Speakers: Ian Livingstone (Co-founder and CEO, Keycard); Eli Aleyner (VP of Product Strategy & Alliances, Docker); Marcelo Sousa (Snyk)
- **15:25 – 15:45** The Rise of the Watcher Agent (talk)
  - Speakers: Aparna Dhinakaran (Chief Product Officer, Arize AI)
- **15:45 – 16:30** CISO Debate (panel)
  - Speakers: Aaron Stanley (CISO, Secure Theory); Aaron Brown (Mercor); Bil Harmer (Supabase)
  - Moderator: Manoj Nair (CTO & Chief Innovation Officer, Snyk)
- **16:30 – 17:30** Happy Hour (networking)
  - Networking before the official AISS after-party.

## Speakers

- **Aaron Stanley (CISO, Secure Theory)**: Originally a sysadmin for a regional ISP, Aaron developed the forensic technology for Stroz Friedberg, built an eDiscovery engine for Apple, and ran the cybersecurity function at Twilio before joining dbt Labs to head Security and IT in 2023. He believes that a good security team incentivizes smart risk-taking, draws...
- **Aashish Tripathi (Product, Strategy & Commercialization, 1Password)**: Aashish is Vice President of Product Strategy at 1Password. Prior to 1Password, Aashish spent over a decade as Director of Product and General Manager at AWS and Amazon. During that time he built and ran cloud based enterprise services, consumer focused businesses, and developer programs. Prior to Amazon, he led...
- **Adrian Guevara (CISO, Telus Digital)**: Adrian Guevara is Global VP, Information Technology at TELUS Digital, where he leads enterprise technology strategy, IT operations, and information security, including workforce identity across roughly 150,000 identities. He previously served as CISO of TELUS Digital Solutions (formerly WillowTree). Over a career of...
- **Allie Howe (Founder, Insecure Agents)**: Allie is a Member of Technical Staff at Keycard and host of the Insecure Agents podcast. She has spoken at AI Engineer, the Agent Security Summit, and AI Council. She has a background in security engineering and holds a master’s degree in cybersecurity.
- **Aparna Dhinakaran (Chief Product Officer, Arize AI)**: Aparna Dhinakaran is Co-founder and Chief Product Officer at Arize AI, where she works on infrastructure for evaluating, observing, and improving production AI systems. Before founding Arize, she was a machine learning engineer and leader at Uber, Apple, and TubeMogul, and helped build core ML infrastructure at Uber....
- **Dick Hardt (Founder & CEO, hello.co)**
- **Ed Sim (Founder and General Partner, Boldstart)**: Ed Sim is the founder of boldstart ventures, a $1.1B AUM venture firm that invests at Inception, helping the bold start. Since 2010, boldstart has been the first check for technical founders building across cybersecurity, AI infrastructure, physical AI, agents, and the occasional wonderfully weird thing. Notable...
- **Eddie Borrero (CIO, Cyera)**: Eddie Borrero is Chief Information Technology Officer at Cyera, a data security company, where he shapes AI governance strategy for enterprise customers, and helps product teams build governance-forward solutions. He brings more than 25 years of enterprise cybersecurity and technology leadership, with prior executive...
- **Eli Aleyner (VP of Product Strategy & Alliances, Docker)**
- **Ezra Tanzer (AI Forward Deployed CTO, Snyk)**
- **Faisal Tameesh (Security Researcher, NVIDIA)**: Faisal Tameesh is a senior security researcher at NVIDIA and a former red team operator with more than a decade of experience spanning software engineering, penetration testing, vulnerability research, exploit development, reverse engineering, and social engineering. Prior to NVIDIA, he served as a Technical Director...
- **Guy Podjarny (Founder and CEO, Tessl)**: Guy Podjarny is the founder of Tessl, and previously founded Snyk. Tessl is reimagining software development for the AI era, helping shape AI Native Development. Snyk created and leads the Developer Security category, and is now a multi-billion dollar company with over 1,000 employees.
- **Ian Livingstone (Co-founder and CEO, Keycard)**: Ian Livingstone is the Co-Founder & CEO of Keycard, building identity and access infrastructure for the agent-native era. A 3x founder with deep experience in security and developer platforms, he has helped shape platform strategy at Snyk and held senior engineering roles at Salesforce. Recognized as a leader in...
- **Jared Hanson (Co-Founder, Keycard)**: Jared Hanson is the creator of Passport.js, the most widely used authentication framework for Node.js, downloaded millions of times each week. He was previously Chief Architect at Auth0 and a senior technical leader at Okta following its acquisition. At Keycard, Jared is redefining identity and access for AI agents,...
- **Jason Trunk (Field CTO, Island)**: Jason Trunk serves as Vice President and Field CTO at Island bringing over 35 years experience with emerging end-user compute technologies, app performance, network decryption, and virtualization. Jason has held prior leadership roles at Amazon Web Services, BigPanda, JPMorganChase, AppDynamics, Mercury Interactive...
- **Jeff Wang (President of Emerging Markets, Cognition)**: Jeff Wang is President of Emerging Markets at Cognition, the company behind the Devin software engineering agent. He previously served as CEO of Windsurf, stepping in as interim CEO in July 2025 when its founders departed, and led the company through its acquisition by Cognition. Earlier he held executive roles at...
- **Jingxuan He (Researcher, NTU & NVIDIA)**: Jingxuan He is a researcher at NVIDIA and an incoming Assistant Professor at Nanyang Technological University in Singapore. His research interests lie at the intersection of AI, security, and programming languages, with a particular focus on evaluating and mitigating the cybersecurity risks of frontier AI. His work,...
- **Karl McGuinness (Advisor, Independent)**
- **Ken MacAskill (CEO, Snyk)**: Ken MacAskill is CEO of Snyk, the AI security platform that helps organizations secure the code AI writes, the agents it runs, and the applications it builds, enabling the safe adoption of AI across the software lifecycle. Ken is a CPA and since the early 2000s he has served as the CFO of emerging and high-growth,...
- **Liran Tal (Senior Director, Developer Relations, Snyk)**: Liran Tal is Senior Director of Developer Relations at Snyk. A developer and security researcher in the JavaScript and Node.js community, he is a GitHub Star and received the OpenJS Foundation's Pathfinder for Security award. He contributed to OWASP, CNCF and OpenSSF initiatives and wrote O'Reilly's "Serverless...
- **Manoj Nair (CTO & Chief Innovation Officer, Snyk)**: Manoj Nair is Chief Technology Officer and Chief Innovation Officer at Snyk, leading R&D, the company's AI engineering transformation, and strategic partnerships with frontier AI labs including Google, Anthropic, and OpenAI. He recently led the creation and launch of Evo by Snyk (a purpose-built product line for...
- **Maximilian Baader (Staff Research Engineer, Snyk)**: Max Baader develops methods to secure AI agents and evaluate the security of AI-generated software. His research spans attacks and defenses for large language models and AI agents, alongside interpretability and provable robustness. His work has appeared at NeurIPS, ICML, ICLR, and PLDI. He earned his PhD and...
- **Punit Shah (Frontier Red Team, Anthropic)**: Punit Shah is on Anthropic's Frontier Red Team, the group that studies what frontier AI models can do in high-stakes areas like cybersecurity. He leads the team's work to secure the open-source ecosystem, helping maintainers and projects with finding and fixing vulnerabilities to hardening code. Before joining the...
- **Sebastian Duesterhoeft (Partner, Lightspeed Ventures)**: Sebastian Duesterhoeft is a Partner at Lightspeed Venture Partners, focused on growth-stage enterprise software investments. He joined Lightspeed in 2023 after time at Silver Lake and Coatue, where as a General Partner he helped lead investments in Snowflake, Databricks, Confluent, GitLab and Snyk. He began his career...
- **Tony Kim (Managing Director, BlackRock)**: Tony Kim is a Managing Director at BlackRock and Head of the Global Technology Team within Fundamental Equities, and lead portfolio manager of the BlackRock Technology Opportunities Fund. He joined BlackRock in 2013 and has about 30 years of technology investing experience, including at Artisan Partners, Credit Suisse...
- **Vyas Sekar (Tan Family Professor of Electrical and Computer Engineering, Carnegie Mellon)**: Vyas Sekar is the Tan Family Professor of Electrical and Computer Engineering at Carnegie Mellon University. He is a member of CMU Cylab, where he codirects the Cylab Cyber Autonomy Initiative. He is also co-founder and Chief Technologist at Rockfish Data, and the Chief Scientist at Conviva. His research is at the...

## Venue: Westin St. Francis

335 Powell St, San Francisco, CA 94102

A San Francisco landmark on Union Square, open since 1904. The event spaces have the bones to match: grand ballrooms with carved ceilings and gilt pillars in the historic Landmark Building, and floor-to-ceiling views of the Bay Bridge and Golden Gate from the 32nd floor. The kind of venue where the room does some of the work for you.

[Directions](https://maps.google.com/?q=Westin+St+Francis+San+Francisco)

## Side events

### The AI Security Panel: Unfiltered
- What: Panel the afternoon before the AISS flagship event. Hosted by Snyk.
- Date: Wednesday, October 14, 2026, 4:30 to 5:30 PM PDT
- Location: Golden Gate Room, Westin St. Francis, 335 Powell St, San Francisco, CA 94102
- Entry: Free. Separate registration on Luma.
- Panel:
  - Deirdre Bosa, Host, DB Live, Yahoo Finance (moderator)
  - Manoj Nair, CTO and Chief Innovation Officer, Snyk
  - Michael D'Angelo, Technical Lead, Cyber, OpenAI
  - John Hultquist, Chief Analyst, Google Threat Intelligence
  - Ed Sim, Founder and General Partner, boldstart ventures
- [Register on Luma](https://luma.com/snyk-y9pl)
### AAuth Night: Moving Beyond OAuth
- What: Official AISS after-party. Hosted by AI Security Summit with Insecure Agents, powered by Keycard.
- Date: Thursday, October 15, 2026, 5:30 to 8:30 PM PDT
- Location: 111 Minna Gallery, 111 Minna St, San Francisco, CA 94105
- Entry: Free. Separate registration on Luma.
- [Register on Luma](https://luma.com/insecure-rmm0)

## Upcoming events

### AI Security Summit San Francisco
- Date: October 15, 2026
- Location: San Francisco, CA
- Summary: The flagship event. One full day. One room. No filler.
- [Event details and registration](https://aisecuritysummit.com/)
### AI Security Summit Copenhagen
- Date: November 25, 2026
- Location: Copenhagen, Denmark
- Summary: Half a day, one room, for the leaders actually deploying AI.
- [Event details and registration](https://aisecuritysummit.com/copenhagen-26)
### AI Security Summit Sydney
- Date: November 25, 2026
- Location: Sydney, Australia
- Summary: AI security lands in APAC. Details coming soon.
- [Event details and registration](https://www.clutchevents.co/events/sydney-ai-security-summit-2026)

## Latest videos

- [AI Security Summit London 2026 | Agentic Development Security: The Three Problems Nobody Was Solving and the One That Matters Most for 2026 | Manoj Nair, Snyk](https://aisecuritysummit.com/videos/london-2026-agentic-development-security-manoj-nair): Three security problems in agentic development: the tools agents use, how they behave, and the code they produce.
- [AI Security Summit London 2026 | Autonomous Offensive Security: Hacking McKinsey, BCG, and Bain | Paul Price, CodeWall](https://aisecuritysummit.com/videos/london-2026-autonomous-offensive-security-paul-price): Paul Price presents autonomous offensive security research and what it means for enterprise threat models.
- [AI Security Summit London 2026 | Beyond the Chatbot: Orchestrating the Agentic Enterprise at Scale | Kevin Keller, Massimo Angelino & Oliver Neuberger](https://aisecuritysummit.com/videos/london-2026-beyond-the-chatbot-panel): Kevin Keller, Massimo Angelino, and Oliver Neuberger discuss orchestrating AI agents across the enterprise.
- [AI Security Summit London 2026 | How Agents Won Best Bug at a Live Hacking Event | Shlomie Liberow, Aisy](https://aisecuritysummit.com/videos/london-2026-how-agents-won-best-bug-shlomie-liberow): Shlomie Liberow explains how agents built around bug bounty methods won best bug at a live hacking event.
- [AI Security Summit London 2026 | A Practical Look at Insecure Agent Architectures | Joe Bollen, Snyk](https://aisecuritysummit.com/videos/london-2026-insecure-agent-architectures-joe-bollen): Joe Bollen examines unsafe paths between agents and how to test whether the controls around them hold.

## Partners

- Founding partners: [AI Engineer](https://www.ai.engineer), [AI Security Engineers](https://www.aiseceng.io), [Snyk](https://www.snyk.io)
- Founding sponsor: [Keycard](https://www.keycard.com)
- [All partners and sponsors](https://aisecuritysummit.com/partners)

## More resources

- [All videos](https://aisecuritysummit.com/videos.md)
- [Announcements](https://aisecuritysummit.com/announcements.md)
- [About AI Security Summit](https://aisecuritysummit.com/about.md)
- [Agent guide (llms.txt)](https://aisecuritysummit.com/llms.txt)
- [XML sitemap](https://aisecuritysummit.com/sitemap-index.xml)
