Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue
Is your RAG system secretly leaking sensitive data to your LLM? Learn how to stop it with fine-grained authorization before it goes rogue.
#1about 4 minutes
Understanding the current state of AI security challenges
AI systems often have poor judgment, and the security domain is playing catch-up with the rapid evolution of AI agents and protocols.
#2about 3 minutes
Focusing on key OWASP Top 10 risks for developers
Application developers should focus on mitigating sensitive information disclosure and excessive agency, as these have a large attack surface under their control.
#3about 3 minutes
Why traditional RBAC fails for RAG systems
Traditional role-based access control (RBAC) is insufficient for RAG systems due to dynamic context and complex data relationships, necessitating a fine-grained authorization (FGA) approach.
#4about 5 minutes
Implementing OpenFGA to secure RAG data access
OpenFGA uses authorization models and relationship tuples to filter documents from a vector store, ensuring the LLM only receives data the user is permitted to see.
#5about 2 minutes
Mitigating excessive agency with zero trust tool access
Control an AI agent's tool access at the code level using zero trust principles, applying standard RBAC for simple cases and FGA for granular, user-dependent permissions.
#6about 1 minute
Securing third-party API calls using OAuth federation
Use OAuth 2.0 federation to allow AI agents to call third-party APIs on a user's behalf without handling raw credentials, using a broker to manage access tokens.
#7about 1 minute
Adding human guardrails with asynchronous authorization
Implement human-in-the-loop approvals for high-stakes actions by using the CIBA flow to send asynchronous authorization requests to users for confirmation.
#8about 5 minutes
Demoing step-up authorization and system architecture
A live demo showcases step-up authorization where an agent requests user consent before accessing sensitive data, followed by an overview of the application's architecture.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
05:16 MIN
Addressing security risks and guardrails for agentic AI
Unlocking Value from Data: The Key to Smarter Business Decisions-
02:46 MIN
Overcoming legal and security roadblocks for AI adoption
The AI Skills Gap: What Tech Leaders Must Get Right
03:19 MIN
The overlooked security risks of AI and LLMs
WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking
07:10 MIN
Managing the fear, accountability, and risks of AI
Collaborative Intelligence: The Human & AI Partnership
16:49 MIN
Q&A on AI adoption, tools, and challenges
Navigating the AI Wave in DevOps
01:40 MIN
Addressing AI limitations with human oversight and security
Make it simple, using generative AI to accelerate learning
01:51 MIN
Final advice on security and responsible AI usage
WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking
03:35 MIN
Understanding AI security risks for developers
The AI Security Survival Guide: Practical Advice for Stressed-Out Developers
Panel Discussion: Responsible AI in Practice - Real-World Examples and ChallengesIntroductionIn the ever-evolving landscape of artificial intelligence, the concept of "responsible AI" has emerged as a cornerstone for ethical and practical AI implementation. During the WWC24 Panel discussion, three eminent experts—Mina, Bjorn Brin...
Daniel Cranney
Stephan Gillich - Bringing AI EverywhereIn the ever-evolving world of technology, AI continues to be the frontier for innovation and transformation. Stephan Gillich, from the AI Center of Excellence at Intel, dove into the subject in a recent session titled "Bringing AI Everywhere," sheddi...
Chris Heilmann
Exploring AI: Opportunities and Risks for DevelopersIn today's rapidly evolving tech landscape, the integration of Artificial Intelligence (AI) in development presents both exciting opportunities and notable risks. This dynamic was the focus of a recent panel discussion featuring industry experts Kent...
Chris Heilmann
Dev Digest 116 - WWWAI?This time, learn how to un-AI Google's search results, what's new on the web, avoid a new security hole and go back to BASICS with us. News and ArticlesWhat a week. Google, Microsoft, OpenAI and many others had their big flagship events announcing th...
From learning to earning
Jobs that call for the skills explored in this talk.