BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.ozsecurity.org//ozsec-2026//talk//YTFBSJ
BEGIN:VTIMEZONE
TZID:CST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T080000Z
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T090000Z
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-ozsec-2026-YTFBSJ@cfp.ozsecurity.org
DTSTART;TZID=CST:20261023T104500
DTEND;TZID=CST:20261023T113000
DESCRIPTION:AI agents are increasingly being given the ability to execute c
 ommands\, access infrastructure\, modify code\, and interact with real-wor
 ld systems. But instructions\, system prompts\, and skills are not securit
 y boundaries they influence what an agent **should** do\, not what it is a
 ctually **allowed** to do. This talk explores harness engineering as a mea
 ns of enforcing those boundaries through capability control\, tool authori
 zation\, validation\, isolation\, approvals\, and auditing. We’ll also e
 xamine the limitations and new attack surface introduced by harnesses them
 selves\, and why the harness should ultimately control what an AI agent ca
 n do.
DTSTAMP:20260920T122133Z
LOCATION:Redbud B
SUMMARY:Don't Trust the Agent: Enforcing Security Boundaries in AI Systems 
 - Travis Lowe
URL:https://cfp.ozsecurity.org/ozsec-2026/talk/YTFBSJ/
END:VEVENT
END:VCALENDAR
