Securing autonomous AI agents: regulatory risk and governance for modern AppSec
Autonomous AI agents writing and executing code at machine speed present an urgent compliance challenge for modern software organizations. As global regulations tighten, engineering leaders must establish clear governance layers over agentic workflows, external tool calls, and Model Context Protocol integrations to ensure full accountability.
In this session, Mend.io experts Asaf Saar and Ben Goldberg unpack the intersection of AI compliance, software supply chain security, and enterprise risk management. Learn how to bridge the accountability gap without sacrificing development velocity.
Timestamps:
00:04 - Introduction and Speaker Overview
02:09 - Defining AI Agents
03:22 - Market Patterns: Adoption vs. Governance
06:06 - Shift in Responsibility and Content Ownership
09:08 - AI Regulation and Framework Landscape
11:27 - Real-World Impact and Safety Considerations
13:58 - Accountability Failures and AI Security Incidents
16:28 - Compliance Failures in Action
20:34 - Frontier Lab Breaches and Agent Autonomy
23:02 - Environmental Visibility and Sub-Agent Proliferation
26:56 - Runtime Security vs. Traditional Application Security
29:43 - Organizational Ownership and Hot Potato Risk
34:04 - Model Governance vs. Agent Accountability Questions
37:20 - Essential Evidence for Auditors
38:58 - 30-Day and Quarterly Recommendations to Get Started
41:01 - FAQ: Mapping In-House Agents and Discovery
43:26 - FAQ: Agent Identity and Identity Aliases
46:37 - Closing Remarks
Watch the full webcast on-demand: https://www.brighttalk.com/webcast/15811/673202
Learn more about securing AI-native software at https://www.mend.io/