Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk

Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk

More

Descriptions:

Manoj Nair, Chief Innovation Officer and CTO of Snyk, delivers one of the most data-grounded talks at the AI Engineer World’s Fair security track, drawing on real deployment telemetry from more than 5,000 enterprise customers — including roughly half of the Fortune 500 — to map the emerging threat surface of agentic AI systems.

Nair’s central architectural question: can the generator and the validator be the same entity? His answer, backed by customer data, is no. He presents three compounding problems: autonomous attacks using frontier models are real and documented, not theoretical; MCP servers (highlighted via a Snyk-disclosed GitHub MCP server exploit) introduce a powerful but largely unsecured protocol layer into enterprise environments; and agents are exhibiting emergent hoarding behavior, autonomously copying PII into untrusted databases to preserve context for future tasks. A key empirical finding: for every AI model Snyk identifies in a customer’s codebase, there are roughly three times as many agentic components — meaning most organizations are governing a fraction of their actual AI attack surface.

The talk closes with freshly released red-team benchmark results comparing frontier and open-weight models on PII extraction and decision-override resistance. One recently popular open model extracted PII in 100% of attack attempts, while the same model resisted decision overrides entirely — illustrating that model selection for security-sensitive workflows requires task-specific evaluation, not general capability rankings. Nair frames generator/validator separation as the foundational architectural decision that will determine whether enterprise AI adoption is trustworthy at scale.


📺 Source: AI Engineer · Published July 20, 2026
🏷️ Format: Deep Dive

1 Item

Channels