Uploaded May 2026 | Updated September 2026, 2 weeks ago
Thoughtworks x AWS Security Live Session | London Partner Summit
When AI agents move beyond chat and begin taking action in real systems, the security stakes change dramatically.
Jim Gumbley explores the emerging risks and architectural guardrails required for agentic AI systems operating in high-trust environments.
Using the “Trifecta” framework as a foundation, this session dives into real-world failure modes already appearing in early AI agent implementations — including prompt injection hidden in user-generated content, unauthorized data access, mass-action abuse, outbound data exfiltration, and fraudulent transactions.
Rather than blaming the model itself, the discussion focuses on a critical reality: the architecture becomes dangerous when untrusted language is translated directly into high-impact tool execution.
Topics covered include:
• Separating reasoning from action execution
• Treating user input as data, not instructions
• Enforcing least-privilege access controls
• Binding actions to authenticated user context
• Applying rate limits and approval workflows
• Instrumenting systems for auditability and anomaly detection
The session also explores how observability changes the game by tracing prompts, tool calls, and policy decisions end-to-end — enabling teams to detect misuse, validate safeguards, and continuously improve controls.
Whether your AI systems interact with records, money, messaging, scheduling, or operational databases, this session provides a practical framework for building useful AI agents without introducing unacceptable risk.
📍 Live from the London Partner Summit
🤝 Presented by Thoughtworks x AWS Security
Thoughtworks x AWS Security Live Session | London Partner Summit
When AI agents move beyond chat and begin taking action in real systems, the security stakes change dramatically.
Jim Gumbley explores the emerging risks and architectural guardrails required for agentic AI systems operating in high-trust environments.
Using the “Trifecta” framework as a foundation, this session dives into real-world failure modes already appearing in early AI agent implementations — including prompt injection hidden in user-generated content, unauthorized data access, mass-action abuse, outbound data exfiltration, and fraudulent transactions.
Rather than blaming the model itself, the discussion focuses on a critical reality: the architecture becomes dangerous when untrusted language is translated directly into high-impact tool execution.
Topics covered include:
• Separating reasoning from action execution
• Treating user input as data, not instructions
• Enforcing least-privilege access controls
• Binding actions to authenticated user context
• Applying rate limits and approval workflows
• Instrumenting systems for auditability and anomaly detection
The session also explores how observability changes the game by tracing prompts, tool calls, and policy decisions end-to-end — enabling teams to detect misuse, validate safeguards, and continuously improve controls.
Whether your AI systems interact with records, money, messaging, scheduling, or operational databases, this session provides a practical framework for building useful AI agents without introducing unacceptable risk.
📍 Live from the London Partner Summit
🤝 Presented by Thoughtworks x AWS Security










