Description
Andrew Bullen, AI Security Lead, Stripe, speaks at [un]prompted 2026 on: Breaking the Lethal Trifecta (Without Ruining Your Agents).
Prompt injection remains the elephant in the AI Security room—there's no deterministic defense, yet the urgency driv...
Andrew Bullen, AI Security Lead, Stripe, speaks at [un]prompted 2026 on: Breaking the Lethal Trifecta (Without Ruining Your Agents).
Prompt injection remains the elephant in the AI Security room—there's no deterministic defense, yet the urgency driving AI adoption means many teams feel forced to either accept the risk or hobble their agents with overly restrictive policies. But there's a third path: containment. In this talk, I'll walk through the architectural guardrails Stripe adopted to protect our agent platform, showing how you can give agents powerful tools while ensuring minimal damage if prompt injection occurs. I'll cover strategies for preventing data exfiltration through controlled egress, share UI patterns for human confirmation flows to balance oversight with usability, and demonstrate how to enforce these guardrails at CI-time using tool annotations.
Read more