All sessions
AI EngineeringTalk (30 min)
Prompt Injection Is a Solved Problem (If You Do These Five Things)
Amara Diallo
- When
- Tuesday, September 151:15 PM – 1:45 PM · 30 min
- Where
- Main StageFort Mason Center, San Francisco
About this session
Provocative title, sober content: capability scoping, output mediation, and the three-layer defence we run in production. Includes live demos of attacks that still work against naive agents in 2026.
Speaker
Amara Diallo
Security Researcher, Halcyon Labs
Amara leads red-team work on agent systems at Halcyon. Her disclosure of the tool-confusion class of prompt injections is why several vendors now scope tool permissions per call.
More in AI Engineering
- Test Data Is a Product: Fixtures for Nondeterministic SystemsTime to be announced
- Context Engineering in Production: What Actually Survives Contact With UsersTuesday, September 15 · 9:45 AM – 10:30 AM · Room 2A
- Your AI Pair Programmer Is Lying to You: Verification Patterns That ScaleTuesday, September 15 · 10:30 AM – 11:00 AM · Main Stage
- Multi-Agent Systems Are Just Distributed Systems (And That's Good News)Tuesday, September 15 · 11:15 AM – 11:45 AM · Main Stage
- Reading Eval Traces Like a DetectiveTuesday, September 15 · 1:35 PM – 1:45 PM · Room 2A
For developers: this programme is open data — JSON, iCal, schedule XML and an MCP endpoint.Show endpointsHide
- JSONEvery published session and speaker, in one request./ai-builders-summit-2026/feed.json
- iCalSubscribe in Google, Apple or Outlook Calendar./ai-builders-summit-2026/feed.ics
- Schedule XMLfrab / pentabarf — the format conference apps import./ai-builders-summit-2026/feed.xml
- MCP + RESTPoint Claude at the programme. OpenAPI 3.1 included./agents
No key, no signup, CORS open. Everything here is generated from the same data the organisers edit.