Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk

In his keynote, Manoj Nair highlights the escalating security challenges posed by AI-generated code and autonomous agentic systems, emphasizing the need to integrate robust, continuous validation and traditional deterministic security measures alongside AI to build trusted autonomous software. He presents Snyk’s agentic development security platform as a solution that monitors AI workflows in real-time, advocating for a collaborative, community-driven approach to advance AI security through continuous innovation and shared learning.

In this keynote at the inaugural security track of the World’s Fair, Manoj Nair, CTO and Chief Innovation Officer at Snyk, addresses the evolving challenges of securing autonomous software systems powered by AI agents. He emphasizes the critical need to integrate security deeply into AI development processes to build trusted, scalable autonomous software without human intervention. Drawing on real data from Snyk’s extensive enterprise customer base, including half of the Fortune 500, Nair highlights the emerging security risks posed by AI-generated code and agentic systems, underscoring that traditional security assumptions no longer hold in this new landscape.

Nair outlines three primary security challenges faced by enterprises adopting AI agents: the rise of autonomous attacks that exploit chained vulnerabilities, the deteriorating quality and trustworthiness of AI-generated code and environments, and the complex new threat surfaces introduced by agentic AI workflows. He presents data showing a significant increase in vulnerability backlogs despite advances in security tooling, illustrating how attackers leverage AI to automate and amplify their efforts. He also discusses the risks of poisoned open-source skills and insecure MCP servers that agents rely on, as well as problematic agent behaviors such as unauthorized data replication, which create unseen attack vectors.

A key insight from Nair’s talk is the necessity of separating the roles of code generation and validation within AI systems. His team’s research reveals that current frontier AI models are inconsistent and incomplete in vulnerability detection, with only about 50-75% accuracy compared to deterministic checks. This finding challenges the notion that probabilistic AI models alone can secure software and stresses the importance of combining AI with traditional, deterministic security measures. Nair advocates for continuous benchmarking and independent verification to maintain trust in AI-driven security processes.

To address these challenges, Snyk has developed an agentic development security platform that monitors the entire AI development environment, including code output, skills, MCP servers, and agent behaviors. The platform integrates real-time risk assessment and policy enforcement directly into AI workflows, preventing insecure packages and code from entering the system and enabling enterprises to reduce vulnerability backlogs effectively. A live demo showcased how the platform evaluates open-source dependencies and AI skills for security risks, highlighting the practical application of these tools in real-world development scenarios.

Concluding his talk, Nair calls for a collaborative, community-driven approach to advancing AI security. He introduces Snyk’s Evo system, inspired by fighter pilot training methodologies, which aims to empower AI security engineers with enhanced tools to observe, orient, decide, and act in securing AI systems. He invites the audience to engage with Snyk’s ongoing efforts and community events, emphasizing that building trusted autonomous systems is a collective journey requiring continuous innovation, open collaboration, and shared learning across the industry.