AGENDA
Maximize your time on the ground.
Navigate the full schedule of training sessions, peer-to-peer intelligence sharing, and uncompromising keynote presentations.
9:30 AM - 10:15 AM PST (45 MIN)
Function Over Form? Using “Least Capability” to Secure Modern AI
Modern AI presents us with a difficult "form versus function" paradox. It presents in the *form* of traditional software, yet carries out the non-deterministic *function* of a human worker. Securing AI strictly according to its form creates a dangerous control gap, leaving "overqualified" models capable of writing exploits or bypassing sandboxes even if they’re only assigned to simple administrative tasks. With motivations closely mimicking those of a human toddler and wide-ranging capabilities beyond the most brilliant prodigy, AI presents a unique sort of Insider Threat.
To address this security gap, this talk presents a Least Capability model. Least Capability builds on Least Privilege and Least Functionality by restricting what an AI tool inherently knows how to do. Grounded in Sounil Yu’s DIKW framework insights and in lessons from the history of training AI models, Least Capability aims to maximize AI's capacity for good while minimizing the possibilities of negative impact.
This session details how to operationalize Least Capability in practice in order to strip away unnecessary model capabilities and neutralize agentic threats by design. We will consider a variety of topics, including how to:
- Apply traditional Human Resources controls to AI
- Create "job descriptions" for purpose-built AI usage
- Deploy technical and structural controls such as Dual-LLM topologies, tool-limited AI Agents, and more
- Foster effective auditing and "reset" options for AI models
- Ask questions of vendors providing AI functionality
- Guide MSP customers through these same considerations
- Save money on AI implementation
- AI & Automation
- AI Strategy & Enablement
- Breakout Session
- CIO / vCIO / Technology Leader
- CISO / vCISO / Security Leader
- Governance, Risk & Compliance
- Legal / Risk / Compliance
- Risk, Compliance & Regulatory Readiness
- Security Architecture & Zero Trust
- Security Engineer / Analyst
- Security Engineering & Defense


