Your AI Security Stack Can’t See What AI Agents Are Doing at Runtime
About This Session
Enterprises are rapidly moving from AI experimentation to AI execution. AI agents, copilots, LLM workflows, and MCP-connected tools are accessing sensitive data, calling APIs, and taking actions across production environments. Yet many organizations still focus on where AI is deployed instead of what it is doing at runtime.
This session explores why runtime AI behavior has become one of the biggest blind spots in enterprise security. Attendees will learn how AI is shifting security from static access controls to continuous execution governance, why AI security and API security are converging, and where today's cloud security and posture management tools fall short.
The session will examine how organizations can gain visibility into agent behavior, govern non-human identities, map agent-to-API interactions, detect sensitive data movement, enforce policy, and reduce shadow AI risk without slowing innovation. It will also discuss how these capabilities support emerging regulatory requirements, including the EU AI Act, where continuous evidence and auditability are becoming essential.
Attendees will leave with a practical framework for moving from AI visibility to runtime control, enabling security teams to monitor, govern, and intervene before autonomous AI actions become business risk.
This session explores why runtime AI behavior has become one of the biggest blind spots in enterprise security. Attendees will learn how AI is shifting security from static access controls to continuous execution governance, why AI security and API security are converging, and where today's cloud security and posture management tools fall short.
The session will examine how organizations can gain visibility into agent behavior, govern non-human identities, map agent-to-API interactions, detect sensitive data movement, enforce policy, and reduce shadow AI risk without slowing innovation. It will also discuss how these capabilities support emerging regulatory requirements, including the EU AI Act, where continuous evidence and auditability are becoming essential.
Attendees will leave with a practical framework for moving from AI visibility to runtime control, enabling security teams to monitor, govern, and intervene before autonomous AI actions become business risk.
Speaker
Craig Riddell
Global Field CISO - Wallarm
Craig Riddell is the Global Field CISO at Wallarm, where he works with enterprise security leaders on securing AI, cloud-native applications, APIs, and emerging runtime threats. With more than two decades of cybersecurity leadership experience, Craig advises organizations on modern governance strategies for AI adoption, application security, compliance, and operational resilience. He is a frequent speaker on AI security, cloud risk, and security transformation, helping enterprises navigate the intersection of innovation, regulation, and real-world cyber risk.