Sydney AI Security Summit 2026
Unlock the strategic imperative of AI security. A gathering of forward-thinking leaders, practitioners and security teams to confront the "AI security chasm" head-on and build a foundation of trust for AI initiatives.

Defend your AI future with expert insights, real-world strategies, and interactive sessions on model security, adversarial defence, and compliance.
This November, we’re bringing together security leaders, AI practitioners, and industry innovators to address the fast-emerging risks of AI adoption.
Discover best practices for securing AI models, defending against adversarial threats, and ensuring compliance as AI moves from pilot to production. Dive into how organisations are tackling challenges from deepfakes to model poisoning, and learn what’s needed to build resilient, trustworthy AI systems. Engage in interactive sessions, technical demos, real-world case studies, and expert debates to stay ahead of the latest threats.
Key Themes
- Securing AI Models in Production
- AI Supply Chain Risks
- Detecting and Preventing Model Poisoning
- Defending Against Adversarial Attacks
- Guarding Against Deepfakes and Synthetic Media
- Regulatory and Compliance Requirements for AI Security
- AI Identity & Access Risks (Shadow Access, AI Agents)
- Building Trustworthy and Resilient AI Systems
Who Should Attend?
CISOs, security leaders, AI engineers, IT leaders, risk managers, and anyone eager to understand and solve the security challenges of the AI era while networking with peers facing the same pressures.
Agenda
AI agents are no longer experimental. They are calling tools, accessing data and taking actions inside real workflows. That creates a new problem for security teams: it is not just about who is using AI, but what an agent can do once it is running. This keynote shares what one Australian enterprise has learned securing agents in production, including what worked, what failed and what they would do differently.
We'll cover:
- Identity and access for agents: How teams are limiting what agents can access, do and trigger in production
- Guardrails that hold up: The controls that actually stop agents going off-script
- Lessons from the rollout: What they would keep, change and fix earlier next time
TBC
Most incident response playbooks were built for systems that behave the same way every time. AI systems don't. When a model leaks data, an agent takes an action it shouldn't, or a chatbot says something it shouldn't, the usual investigation toolkit falls short. This session covers what a modern AI incident response capability looks like and how to build one before you need it.
We'll cover:
- The new evidence: What logs, traces and signals you actually need to investigate an AI system
- Reproducing the unrepeatable: How to do root cause when the same input gives different outputs
- Practical capability building: What to put in place now so your IR team isn't starting from scratch on day one
An interactive session where attendees work through realistic AI security scenarios, from agent access decisions to vendor AI risk, data exposure and incident response. Attendees discuss options with peers, weigh up the trade-offs and choose their course of action.
Results are tallied live and shape how the group moves through the activity.
Will we collectively choose the right course of action?
TBC
AI security programs have moved past the whiteboard. Most large organisations now have something running. Some of it is working, some of it isn't, and most leaders are quietly rebuilding parts of what they started with. This panel brings together senior leaders to compare notes on what they've actually deployed, what they've abandoned, and what they wish they'd done sooner.
We'll cover:
- The controls we kept: What's earned its place in the program after 12 to 18 months in the wild
- The controls we dropped: The ideas that looked good on paper and didn't survive contact with the business
- What changes next: Where teams are tightening ownership, testing and accountability in 2026 and 2027
As organisations rush to deploy generative AI features, copilots and agents, traditional application security testing is failing to catch many of the risks they introduce.
In this session, Srinivas Karthik Putlur from the Commonwealth Bank shares lessons from penetration testing, code reviews and architecture assessments of real AI systems. He'll explore the vulnerabilities that appear most often from prompt injection and excessive agency to insecure retrieval pipelines and MCP-related risks, and the practical controls that help address them.
Key takeaways:
- Why traditional AppSec testing misses AI-specific risks
- The most common vulnerabilities found in real AI applications
- How to secure AI systems without slowing development
When an AI security tool gives the wrong answer, we often blame the model or the prompt. But frequently, the real problem is the data. Security questions can require information from multiple systems that use different names, identifiers and formats, connections that document retrieval cannot reliably make.
This session explores how to build a practical security knowledge graph, including the data sources, entity matching, early schema mistakes and time involved. It then compares the graph with document retrieval using the same questions, model and prompts showing where the graph improved results, where it made no difference and where it performed worse.
The goal is not a complex enterprise ontology, but the smallest useful graph that can answer real security questions and clear evidence of whether it was worth building.
Key takeaways:
- Why document retrieval struggles with questions that require connecting multiple systems.
- Why matching the same assets across inconsistent data sources is the hardest part.
- How to compare retrieval and graph-based approaches fairly, including where the graph falls short.
Choose one roundtable topic to join on the day. Each table is hosted by a peer practitioner and runs as a structured discussion. No slides. No vendor pitches. Just senior leaders comparing notes on what they're doing about the problems on the agenda.
We'll cover:
- Securing AI agents and copilots in production
- Guardrails and testing: what is actually holding up in production
- Shadow AI: where policy is breaking in the real business
- Securing AI-generated code at developer speed
- Third-party AI risk: vendor features on by default
- Identity and access for AI agents
- Building an AI security program when AI is already in use
- AI incident response: when the system doesn't behave the same way twice
Our event sponsors

Past Speaker Highlights
Past Sponsors
Event Location
Doltone House Hyde Park

About Clutch
Hyper-Niche Content
Our conferences are specific to niche sub-sets of the technology industry, drilling down into the biggest issues, challenges and market trends facing tomorrow's leaders.
Collaboration first
Enjoy ample networking opportunities, roundtable discussions, interactive group sessions and real-world case-studies that arm attendees with actionable insights.
Dynamic & Bite-Size formats
No more death-by-PowerPoint. Our events are short, sharp and collaborative with a variety of session formats and a 3/4 day commitment to ensure returns on your time investment.
Get In Touch
Contact our event team for any enquiry

Danny Perry
For sponsorship opportunities.

Lili Munar
For guest and attendee enquiries.

Steph Tolmie
For speaking opportunities & content enquiries.

Taylor Stanyon
For event-related enquiries.
















