Cyd La Luz
Select Speaker Type
Zero Trust and AI: Preparing for Attacks from AI Agents
Cyd La Luz is an experienced Software Engineer specializing in AI, cloud security, and full-stack development. With a strong background at leading companies such as Google, Meta, and Tesla, Cyd has contributed to scalable backend systems, AI moderation technologies, and data analytics platforms. Cyd has hands-on expertise in AI-driven solutions, including developing computer vision and NLP applications, and has worked extensively with technologies such as Python, Java, Kubernetes, and OpenAI tools. Holding multiple GIAC cybersecurity certifications, Cyd brings a unique blend of AI innovation and security-focused engineering to complex, large-scale systems. Reference: This talk presents a practical framework for applying Zero Trust security principles to environments increasingly defined by Artificial Intelligence. As generative AI systems and autonomous agents begin assisting analysts and engineers, interacting with APIs, and orchestrating cloud resources, they effectively become new actors inside enterprise systems. Treating these systems as implicitly trusted productivity tools introduces significant risk, and bad actors may be actively using them in attacks. Therefore, organizations must assume that AI systems—like human users or external services—can be manipulated, misconfigured, or compromised. Zero Trust principles such as strong identity, least privilege, continuous verification, and segmented execution environments provide a valuable model for governing how AI systems interact with infrastructure, data, and development pipelines. The framework discussed in this session draws on established guidance from multiple security communities, including the NIST AI Risk Management Framework (AI RMF), the NIST Secure Software Development Framework (SSDF), and the Zero Trust architecture principles described in NIST SP 800-207. It also incorporates emerging research and guidance from organizations such as OWASP’s Top 10 for Large Language Model Applications, the Cloud Security Alliance (CSA), the Center for Internet Security (CIS), and other cybersecurity initiatives addressing AI-enabled threats. While much attention has focused on the risks of AI-generated code, a growing concern is the use of AI by adversaries themselves. Attackers can use AI agents to accelerate reconnaissance, generate exploit code, craft highly targeted phishing campaigns, or probe cloud infrastructure at machine speed. By examining both defensive and adversarial uses of AI, this talk outlines practical governance and architectural strategies that help organizations adopt AI capabilities while also preparing for a future in which attackers increasingly leverage AI agents as part of their offensive toolkit.