2nd AI Sec Summit, London

Securing AI Sprawl

 

2nd December 2026, London, UK

 

The CISO's Al problem is no longer simply whether employees are using ChatGPT. It is Al sprawl across two fronts: user-adopted tools appearing outside approved channels, and Al being embedded-often opaquely-inside security platforms, SaaS products, developer tools and operational workflows. Every new copilot, browser extension, model endpoint, plug-in and autonomous security feature creates another path through which sensitive data can leave the organisation, permissions can be overextended, or decisions can be made without a clear audit trail. 

The result is a control problem: security teams may know which applications they have bought, but not which models those applications call, what data they retain, how prompts are logged, whether outputs are used to retrain systems, or what happens when an Al-enabled security tool takes action automatically. 

The number of incidents involving users sending sensitive data to generative Al applications has doubled over the previous year, with the average organisation now recording 223 GenAl-related data-policy violations each month. European research found that Al and personal-cloud violations most commonly involved regulated data, followed by source code, intellectual property, passwords and API keys. IBM's 2025 breach research found that one in five studied organisations experienced a breach linked to shadow Al, while organisations with high levels of unapproved Al usage incurred up to $670,000 in additional breach costs. Among organisations reporting an Al-related security incident, 97% lacked appropriate Al access controls.

The risk is also moving beyond accidental disclosure. One report found that risky Al prompts rose by 97% during 2025, with around 90% of organisations encountering risky prompts and approximately one in every 41 prompts classified as high risk during one observed period. More recent 2026 research found that indirect prompt-injection detections rose roughly fivefold between March and May, while some sectors were seeing serious data-exposure risk in close to one in every 17 Al interactions.

For CISOs, that means Al systems must now be treated as both a new data-egress channel and a new attack surface: models can be manipulated, agents can inherit excessive privileges, and Al-enhanced security products can propagate bad decisions at machine speed. 

The strategic challenge is therefore to make Al governable without making the business route around security. Blanket prohibition simply drives activity further into shadow Al. The more credible model is an enterprise Al control plane: discover every Al service and embedded model, classify the data flowing into it, bind access to identity and least privilege, assess vendors and model supply chains, log prompts and autonomous actions, and impose explicit human-approval thresholds for high-impact decisions. Most importantly, CISOs need visibility across both sides of the equation-Al used by the workforce and Al used by the security stack itself. Without that unified view, organisations risk buying Al to improve cyber defence while simultaneously creating an expanding layer of unmanaged cyber risk. 

Companies see Al as a critical tool for staying ahead of threats and managing increasingly complex digital environments. 

However, 94% of global businesses believe that Al will negatively affect their cyber risk exposure within the next three to five years. In the UK, 66% of businesses surveyed are concerned that Al-driven attacks will increase significantly in both complexity and scale during this period. 

 

Al Sec will look at how cybersecurity professionals can stay ahead of this rapidly evolving environment. Join our real-life case studies and in-depth technical sessions from the most sophisticated teams globally.

 

The AI Sec Summit will cover the critical topics in both securing organisational adoption of AI...

 

Data Protection, Privacy & Confidentiality Leakage Risks
Preventing unintentional data exfiltration into LLMs. Guardrails for prompt injection, retention, training-data exposure and shadow Al.

Secure Al Model Development & MLOps Hardening
Supply-chain risks in model weights, training pipelines, and open-source components. Securing feature stores, model registries, datasets and automated deployment paths.

Al-Augmented Cyber Attacks
Adapt detection and control frameworks for automated phishing, synthetic identities, deepfake authorisation, and other offensive Al-enabled attacks.

Human-Al Interaction & Control Boundaries
Preventing automation bias, over-trust, and "rubber-stamping" of AI outputs. Designing human-in-the-loop vs human-on-the-loop architectures.

Operational Resilience & Al Failure management
Al as a potential single point of failure. Resilience testing for autonomous agents, chain-of-thought suppression, fall back modes and kill-switch design.

Regulatory Landscape, Compliance & Liability
EU Al Act high-risk controls, UK principles-based approach, US AI EO, NIS2, DORA, GDPR. Mapping these into control frameworks, RCSAs, and testing cycles.

 

…and the critical topics around AI in security including:

 

Al-Driven Identity Security & Insider Threat Detection
Models flagging impossible travel, anomalous privilege escalation, sensitive-data access, Al-agent misuse. Detection of compromised API keys and model-to-model interactions.

Al-Powered Vulnerability Discovery & Code Security
Models that scan codebases, laC, and microservices for exploitable patterns. AI accelerated fuzzing and automated patch recommendation.

Al Anti-Phishing & Social Engineering Defences
Real-time detection of Al-generated phishing, deepfake voice/video attacks, and synthetic identities. Behavioural biometrics and intent modelling for high-risk approvals.

Al for Supply-Chain & Dependency Risk
Detecting malicious libraries, poisoned datasets, adversarial model weights and compromised training pipelines. Al-driven analysis and anomaly detection.

Al-Enhanced SOC Operations
Triage copilots, incident-response assistants, and automated enrichment of alerts. Natural language correlation across logs, chats, tickets, detections and threat intel.

Intelligent Threat Detection & Behavioural Analytics
ML models learning normal vs anomalous identity, access, network and API patterns. Adaptive baselining for LLM usage.


Venue

Park Plaza Victoria, London

vpp

Location:
Park Plaza Victoria
239 Vauxhall Bridge Road, London, UK, SW1V 1EQ
Telephone: 0333 400 6140

Directions:
Please click here