Insecure Agents is a podcast that curates the most important conversations and trends in AI security. AI engineers, CISOs, and security practitioners listen to learn how to give their agents the security they need to reach higher levels of capability and autonomy.

Allie Howe

ALLIE HOWE HOST

Allie Howe is a Member of Technical Staff at Keycard and has a background in security engineering. She is a core contributor to the OWASP Agentic Security Initiative and has spoken at AI Engineer World's Fair and AI Agent Security Summit.

𝕏 @vtahowe in /allisonhowe

Upcoming

Events coming up — RSVP to join us.

  • August 3, 2026

    Las Vegas, NV

    One prompt can fan out across fourteen repositories before you have finished your coffee, which is exactly why securing coding agents is so hard. This session explores how coding agents can operate autonomously while staying inside organizational boundaries, and the trilemma every team runs into: security, capability, and autonomy. We walk through a reference architecture from Snyk, Docker, and Keycard that lets agents run governed rather than unchecked, covering identity attribution across agent fleets instead of shared API keys, sandbox best practices like micro-VMs and default-deny networking, and supply chain security for AI-generated code. Aimed at engineers and security leaders running or overseeing coding agents. Hosted by Allie Howe during Black Hat with the Insecure Agents podcast community.

    RSVP
  • October 15, 2026

    San Francisco, CA

    AAuth Night is back. After a great turnout during AI Engineer World's Fair in July, we are keeping the conversation going this fall. Connecting agents to company tools means rebuilding the identity layer from scratch: short-lived credentials, per-user delegation, audit trails, scoped access, and secure multi-agent handoffs. AAuth is a new auth protocol designed for agents, built by the author of OAuth, Dick Hardt. It lets you run your agent without API keys and bounds an agent's authority to its mission, re-checked at every step. Join us for talks, live demos, and a panel Q&A.

    RSVP

Most Recent

Our latest event — catch the recap.

  • July 1, 2026

    AAuth Night Moving Beyond OAuth

    Premier Community Event

    111 Minna Gallery, San Francisco

    Authentication built for AI agents — how an agent can call resources without an API key. Lightning talks and live demos from Dick Hardt (AAuth creator, OAuth author), Jared Hanson (Keycard CTO, Passport.js author), and engineers shipping AAuth in production, closing with a panel Q&A moderated by Allie Howe.

    View details

Past

Past Insecure Agents events.

  • May 14, 2026

    Building Internal AI

    AI Council Side Event

    Dirty Habit, San Francisco

    How companies deploy AI agents internally across Slack, GitHub, and Google Workspace — covering credential management, agent permissions, memory isolation, and adoption metrics. Moderated by Allie Howe with David Cramer (Sentry), Paul Klein IV (Browserbase), Brendan Irvine-Broque (Cloudflare), and Ian Livingstone (Keycard).

    View details
  • November 20, 2025

    Pensar, NYC

    Fresh off Day 1 of swyx's AI Engineer Code Summit, our NYC community descended on Pensar's offices for a live recording of Insecure Agents, hosted by Allie Howe. Kerem Proulx (Pensar), Samuel Colvin (Pydantic), Ian Livingstone (Keycard), and Leonard Tang (Haize Labs) explored how to build AI agents people can actually trust.

    View details