Stopping Rogue Agents in Flight: Real-Time Detection and Autonomous Containment for Enterprise AI

Tuesday, August 11, 2026
1:30 PM - 2:15 PM
AI Risk Summit Tech Track (Salon II)

About This Session

A compromised AI agent can execute ten irreversible tool calls in the time it takes a security log to reach your SIEM. By the time an analyst sees the alert, the data may already be gone.

At Salesforce, we defend large-scale autonomous agent deployments across thousands of organizations and millions of daily prompts. At AI Risk Summit 2025, I shared how we detect rogue agent behavior using unsupervised ML and engineered behavioral features over production telemetry. This year, I cover what comes next: detection alone is not enough.

This talk presents a runtime detection-and-response architecture for enterprise AI agents: an inline security service that subscribes to the agent event stream, scores each action against behavioral baselines in real time, and emits containment signals before the agent takes its next step.

The talk walks through the response taxonomy — session termination, per-tool restriction, retrieval redaction, step-up authentication, throttling, and egress blocking — and the hard part: deciding when each action should fire without creating more damage than the attack itself. Expect specifics on what broke, what remains unsolved, and the architectural tradeoffs every team deploying AI agents will eventually face.

Attendees will leave with a runtime detection-and-response reference architecture, a containment-action taxonomy ranked by blast radius and reversibility, and an opinionated deployment checklist to apply before their next agent ships.

Speaker

Millie Huang

Millie Huang

Principle Data Scientist, Detection and Response - Salesforce

Millie Huang is a Principal Data Scientist at Salesforce, where she leads application-layer security defenses for enterprise GenAI and agentic AI systems.

Millie has over a decade of experience applying machine learning, analytics, and security operations to high-scale production systems. She works cross-functionally with security, product, engineering, and AI research teams to translate emerging AI risks into practical platform controls, detection strategies, and response mechanisms. Her current work focuses on moving GenAI security beyond point-in-time reviews toward continuous monitoring, context-aware detection, and operationalized defense for autonomous enterprise agents.