BEGIN:VCALENDAR
PRODID:-//Google Inc//Google Calendar 70.9054//EN
VERSION:2.0
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:44CON 2026
X-WR-TIMEZONE:Europe/London
BEGIN:VEVENT
DTSTART:20260917T130000Z
DTEND:20260917T135000Z
DTSTAMP:20260624T151157Z
UID:0unjj72sreaejenm8nfi48pmad@google.com
CREATED:20260624T102115Z
DESCRIPTION:Most defences for agents sit at the edges: input filters\, guar
 drails\, output classifiers\, system prompts hardened against the last jail
 break someone posted on Discord. Nobody is watching what the agent is actua
 lly thinking.\nOpenAI and DeepMind set out to test this. Their thesis: mo
 nitoring an agent's chain of thought catches misbehaviour that monitoring i
 ts actions (tool calls\, API usage\, etc.) alone cannot. When you watch wha
 t an agent is thinking rather than just what it does\, a whole category of 
 nuanced compromise becomes visible: indirect prompt injection\, tool poison
 ing\, goal drift\, subtle exfiltration patterns dressed up as legitimate to
 ol use. Their thesis was right - the research found that it improve detecti
 on accuracy by 35% and was 4x more likely to catch nuanced attacks.\n\nMax Corbridge\, ethical hacker and red teamer\, turned that research into 
 the first open-source runtime security monitoring system for agents\, watch
 ing not just what an agent does but what it's reasoning about while it does
  it. This talk covers the attack surface\, what edge defences miss\, and in
 cludes live demos of Adrian (the OSS detection system https://github.com/secureagentics/Adrian) catching and stopping real attacks against production agents.
LAST-MODIFIED:20260624T150831Z
LOCATION:Track 1
SEQUENCE:0
STATUS:CONFIRMED
SUMMARY:The Agent’s Inner Monologue: Catching Compromise in the Reasoning T
 race – Max Cobridge
TRANSP:OPAQUE
END:VEVENT
END:VCALENDAR