Conference Description
Key Takeaways
- Technical conference addressing security challenges in autonomous AI systems
- Focus on design, verification, and deployment of privacy-preserving AI agents
- Aimed at security researchers, AI engineers, system architects, and academic professionals
- Organised by USENIX with committee members from leading research institutions and technology organisations
- In-person event at Hyatt Regency Santa Clara, California
Introduction
The USENIX Conference on Secure Agentic-AI Systems (SAIS ’27) convenes researchers, practitioners, and developers working at the intersection of artificial intelligence and cybersecurity. As AI models increasingly demonstrate the capacity to reason, plan, and execute actions autonomously, the security implications of deploying such systems in production environments have become a pressing concern across industries. This conference provides a dedicated forum for examining the technical foundations and practical methodologies required to build trustworthy autonomous AI.
About This Event
SAIS ’27 is a technical conference structured around peer-reviewed paper submissions, presentations, and facilitated discussions. The event takes place at the Hyatt Regency Santa Clara in California, offering an in-person setting designed to encourage direct collaboration between attendees. The organising committee draws from prominent institutions including DeepMind, Google, Snowflake, NVIDIA, ETH Zurich, and UC Berkeley, reflecting the cross-disciplinary expertise required to address challenges in this emerging field.
Securing Autonomous AI: Core Discussion Areas
The conference programme centres on the secure design, verification, and deployment of agentic AI systems. Unlike traditional software, autonomous AI agents make decisions and take actions with limited human oversight, introducing novel attack surfaces and failure modes that conventional security frameworks were not designed to address.
Verification presents particular difficulties when AI behaviour emerges from learned representations rather than explicit programming. Ensuring that an agent will behave safely across all possible states requires new formal methods and testing approaches. The conference examines principled techniques for establishing guarantees about agent behaviour before deployment and monitoring mechanisms for detecting anomalies during operation.
Privacy-preserving AI represents another significant thread, addressing how autonomous systems can process sensitive data while maintaining confidentiality. This encompasses technical approaches such as differential privacy, federated learning, and secure multi-party computation as they apply to agentic architectures.
Industry Context
The emergence of agentic AI as a distinct category reflects broader shifts in how organisations deploy machine learning. Where earlier systems provided recommendations for human decision-makers, contemporary agents increasingly execute multi-step tasks with genuine autonomy. This transition amplifies both the potential benefits and the risks associated with AI deployment.
Security considerations extend beyond protecting AI systems from external threats to ensuring that agents themselves do not cause harm through unintended actions. The challenge lies in maintaining meaningful human oversight without negating the efficiency gains that autonomy provides. Organisations deploying agentic systems must balance operational requirements against the need for robust safeguards, a tension that informs much of the research presented at SAIS ’27.
Who Should Attend
SAIS ’27 serves professionals working on the technical challenges of secure AI deployment. Security engineers evaluating how autonomous systems affect their threat models will find relevant research on attack vectors and defensive architectures. AI and machine learning engineers building agentic applications can engage with verification methodologies and privacy-preserving techniques applicable to their work. System architects responsible for integrating AI agents into existing infrastructure will benefit from discussions on deployment patterns and operational security. Academic researchers investigating the theoretical foundations of AI safety and security will encounter current work from leading institutions in the field.
Conclusion
As autonomous AI systems move from research prototypes to production deployments, the security community faces questions that existing frameworks cannot fully answer. SAIS ’27 provides a venue for developing the technical foundations and practical approaches necessary to deploy agentic AI responsibly, bringing together the expertise required to address one of the more consequential challenges in contemporary computing.

