Videos 1EZdpEhwmNc
Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk
Scene timeline
64 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 315
- whisperx 315
- chunks
- 42
- from 315 cues
- keyframes
- 33
- kept of 64 captured
- frames with text
- 33
- 736 lines read
- chapters
- 18
- from the source metadata
- keyframe bytes
- 7.8 MB
- word timings on 315 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-09 23:43 | 0s |
stt |
done | — | 2026-08-09 14:59 | 29s |
chunk |
done | — | 2026-08-09 15:00 | 0s |
text_embed |
done | — | 2026-08-10 19:42 | 1s |
keyframe |
done | — | 2026-08-09 15:00 | 6m 07s |
ocr |
done | — | 2026-08-09 15:06 | 35s |
frame_embed |
done | — | 2026-08-10 19:42 | 5s |
Frames, and what the machine read
-
- AlEngineer0.96
- World's Fair0.97
-
- AlEngineer0.95
- World's Fair0.99
-
- LAB & PLATINUM SPONSORS0.98
- Amazon AGI Lab0.98
- ANTHROP\C1.00
- Google DeepMind1.00
- MINIMAX0.94
- OpenAI0.92
- Akamai1.00
- arize1.00
- aws1.00
- Braintrust bright data0.99
- B1.00
- Browserbase1.00
- docker1.00
- :neo4j0.93
- ORACLE1.00
- PayPal1.00
- qodo1.00
- reducto1.00
- Sonar1.00
- Makers of0.99
- togetherai1.00
- Unblocked1.00
- WorkOS1.00
- SonarQube1.00
-
- C3.0.95
- AlEngineer0.99
- World's Fair0.99
-
- 23.40.82
- AlEngineer1.00
- World's Fair0.98
-
- World's Fair0.99
-
- AlEngineer0.99
- World's Fair0.99
-
- AlEngineer0.96
- snyk1.00
- KEYN0TE·20260.94
- World'sFair1.00
- SNYK· AI ENGINEER WORLD'S FAIR0.98
- Security isn't a track at this0.99
- PRESENTED BY1.00
- Microsoft1.00
- conference by accident.0.99
- Cut through the Al Fog: Security is fundamental to Al.0.99
- Manoj Nair0.98
- CTO & CHIEF INNOVATION OFFICER · SNYK0.98
- gon0.63
- World'sFair1.00
- Engineering the future of Al0.98
-
- AlEngineer0.97
- snyk1.00
- KEYNOTE· 20260.93
- World'sFair1.00
- 40.96
- SNYK· AI ENGINEER WORLD'S FAIR0.99
- Security isn't a track at this0.99
- PRESENTED BY1.00
- Microsoft1.00
- conference by accident.0.99
- Cut through the Al Fog: Security is fundamental to Al.0.99
- Manoj Nair0.99
- CTO & CHIEF INNOVATION OFFICER · SNYK0.98
- World'sFair0.99
- TRACK 5· JUNE 30, 20260.95
- Security1.00
-
- AlEngineer0.98
- SNYK AI SECURITY PLATFORM1.00
- World'sFair1.00
- 40.96
- Independent validation for the software1.00
- Al writes and the agents that run it.1.00
- Three problems define Al security in 2026.1.00
- World's Fair0.97
- TRACK 5· JUNE 30, 20260.96
- Security1.00
-
- AlEngineer0.99
- THREE PROBLEMS DEFINING AI SECURITY IN 20260.99
- World's Fair0.97
- 40.95
- 01 · THREATS0.96
- 02 · WORKFORCE0.96
- 03 · GOVERNANCE0.94
- Automated Al0.99
- Untrusted1.00
- Ungoverned Al1.00
- Attacks1.00
- Agentic1.00
- Applications1.00
- Development1.00
- Machine-speed threats1.00
- No inventory, no policy0.98
- eliminate the luxury of1.00
- Agents write insecure1.00
- enforcement, no audit trail.1.00
- backlog. AppSec now1.00
- code, use unvetted0.99
- You can't govern what you0.99
- operates at Al speed.1.00
- tools, and operate with0.98
- can't see.0.99
- excessive access.1.00
- World's Fair0.99
- TRACK 5· JUNE 30, 20260.94
- Security1.00
-
- AlEngineer0.99
- PROBLEM 01· AUTOMATED AI ATTACKS0.96
- World'sFair0.98
- Backlog pressure1.00
- NEW ISSUES INTRODUCED ACROSS 4,800+ CUSTOMERS0.99
- is mounting.0.96
- +108.1%1.00
- PRESENTED BY1.00
- Issue volume is outpacing remediation — time-to-0.99
- +40.3%1.00
- exploit keeps shrinking.1.00
- +31.3%1.00
- Microsoft1.00
- Attackers chain "low severity" issues into1.00
- critical exploits.1.00
- base1.00
- -3.5%1.00
- +12.1%1.00
- They target the architectural and business-logic1.00
- flaws scanners miss.1.00
- 24-Q41.00
- 25-Q11.00
- 25-Q21.00
- 25-Q31.00
- 25-Q41.00
- 26-Q11.00
- SOURCE · SNYK PRODUCT DATA, 20260.96
- "Al will bypass cybersecurity systems in months, not years."1.00
- FIVE EYES ALLIANCE (US, UK, CA, AU, NZ) JOINT ADVISORY - JUNE 20260.98
- World's Fair0.98
- TRACK 5· JUNE 30, 20260.93
- Security1.00
-
- AlEngineer0.99
- PROBLEM 02 · UNTRUSTED AGENTIC DEVELOPMENT0.98
- World's Fair0.97
- Untrusted output, environment, and behavior.0.99
- TOXICSKILLS1.00
- GITHUB MCP1.00
- 40.99
- 011.00
- OUTPUT1.00
- 48%1.00
- of Al-generated code is vulnerable1.00
- The code Al writes0.99
- WE FOUND IT IN THE WILD1.00
- TOXICSKILLS: 36.82% carried a flaw, 76 confirmed malicious.0.99
- 021.00
- ENVIRONMENT1.00
- Where agents run1.00
- GITHUB MCP EXPL0IT: A single malicious issue can make an agent leak a private repo.0.97
- 1 IN 12 developers with MCP servers have a HIGH or CRITICAL finding today.0.98
- BEHAVIOR1.00
- 031.00
- PocketOS — 9 seconds. Production wiped. The agent knew the rules.0.98
- How agents act1.00
- BUILDING AGENTS AND RUNNING THEM SAFELY ARE TWO DIFFERENT SKILLS1.00
- SOURCE. SNYK INSIDE THE AGENTIC DEVELOPMENT SUPPLY CHAIN REPORT0.99
- gorb0.56
- World's Fair0.98
- TRACK 5·JUNE 30,20260.97
- Security1.00
Transcript
315 cues· 3,933 words· 21,074 chars
- 0:12 What's up, everyone?
- 0:14 Good to see you all here in the very first ever security track at the World's Fair.
- 0:19 Pretty exciting day, honestly, because like all of you, I genuinely love this stuff.
- 0:25 And having looked through the agenda for the speakers we have today, it's going to be absolutely mind-blowingly useful and fun information.
- 0:33 So hopefully, if you stick around all day, by the end of the day, you'll be able to leave here, go back to your hotel rooms,
- 0:39 and build some genuinely cool software, hopefully without humans in the loop, because that's the ultimate goal, right?
- 0:45 Like, how do we build truly safe, autonomous software at scale?
- 0:50 And it's not something easy to do.
- 0:52 So, with that being said, I'm very excited to welcome my good friend and colleague, Manoj Nair.
- 0:58 He is Snyk's Chief Innovation Officer and CTO.
- 1:02 Before Snyk, he was the Chief Cloud Officer at Commvault.
- 1:06 He founded and ran Hypergrid.
- 1:08 He did product and security leadership at HPE, Dell, and RSA.
- 1:13 And he's got something like a dozen patents to his name.
- 1:15 So he's kind of a legend in the space.
- 1:18 He also personally had a hand in curating this entire track.
- 1:21 So if you like the talk today, please go up and say thank you to him after.
- 1:24 But if not, then just don't blame me, basically.
- 1:28 But yeah, welcome to the stage, Manoj.
- 1:29 MANOJ KUMAR- Thanks.
- 1:35 Thank you, Randall.
- 1:36 I was not expecting a bio.
- 1:38 Hi, everyone.
- 1:39 Really appreciate you all joining here right after those great keynotes up front.
- 1:45 I'm Manoj Nair, and I have the
- 1:49 Pleasure of leading an amazing team that is helping secure about 5,000 enterprise customers around the globe.
- 1:57 So I get to look good about all of that.
- 1:59 But some of what I'm going to show is real data from those customers.
- 2:03 Half of Fortune 500 runs on Snyk, and some of the data is from those learnings.
- 2:12 But before that, I also want to talk about this.
- 2:14 The title of the talk was Cutting Through the AI Fog, I think.
- 2:17 Well, the way we do that is by having tracks like this.
- 2:21 So last year, we stood here.
- 2:22 There were 3,000 people at the AI Engineer World's Fair.
- 2:26 And it really felt like security was missing in the room.
- 2:30 And thanks to SWIX and the amazing partnership with the AI Engineer organization, we created the AI Security Summit in partnership with them.
- 2:37 And we're creating this track.
- 2:39 So it is really good to see this and all the great speakers who are going to talk here today with some fantastic knowledge.
- 2:46 But that is, in our mind, that's how we cut to the fall.
- 2:50 Security needs to be very much part of the room.
- 2:53 We're very passionate about it, not slowing things down.
- 2:56 But really, that's how you build trusted systems.
- 3:00 One thing you're going to hear from me quite a bit in this, if you take one thing, it's this notion of our learning from this real life data and working with the biggest frontier labs in the world and the biggest companies in the world is this concept that has really been not questioned in security before, but it is being asked now.
- 3:23 Can, you know, the generator and the validator be the same?
- 3:27 And our point is, you know, in some of the data you'll show for all kinds of reasons, why not, right?
- 3:31 And almost like if you know Snyk, don't think about the supply chain security company that shifted left.
- 3:37 Like a lot of what you'll see is the last 18 months of what we have been doing with some of these very large enterprises and adopting, you know, these complex systems that we all enjoy and we love.
- 3:49 And what are we learning from that?
- 3:52 There are three problems that we hear when we talk to these customers.
- 3:58 And I want to share those, and I want to show some of the data behind that.
loading
Chapters
- 0:00 Welcome to the first AI security track
- 1:46 Manoj takes the stage: securing 5,000 enterprises
- 3:07 The core question: can the generator also be the validator?
- 4:25 Autonomous attacks and the attacker that never sleeps
- 5:43 Why AI generated code makes old problems worse
- 7:02 Real data: 108% more security backlog, quarter over quarter
- 8:04 The Five Eyes warning and chained exploits
- 8:34 Toxic skills and poisoned environments
- 9:27 MCP servers and the GitHub MCP exploit
- 9:53 When an agent squirrels away your PII
- 10:34 You can't govern what you can't see
- 11:16 Red team data: which models leak PII
- 12:08 The generator vs validator benchmark
- 13:38 What Snyk built: prevention and Snyk Studio
- 14:20 Remediation at scale: 16,000 critical issues
- 15:37 Live demo: package health in the coding loop
- 19:03 Live demo: assessing a risky agent skill
- 21:02 Building EVO with the AI security community