APIs Under Siege: Securing the Connective Tissue of AI Systems

When:  Wed, Aug 12, 2026 from 12:00 to 13:00 (PT)
Associated with  San Francisco Chapter

APIs have quietly become the backbone of the modern enterprise, and with that ubiquity comes an attack surface that is sprawling, often poorly inventoried, and growing faster than most security teams can track. This session opens by sizing the challenge: the sheer volume of APIs in production, the prevalence of shadow and zombie endpoints, and why business logic flaws, not just classic injection or misconfiguration, have become the defining risk. From there, we introduce a practical API Security Framework for reasoning about governance and protection across the full lifecycle, from discovery and inventory through authentication, authorization, runtime detection, and decommissioning.

 

The conversation then turns to how AI is reshaping the threat and the defense in equal measure. Frontier large language models can now interrogate public-facing APIs and surface business logic vulnerabilities at machine scale, compressing reconnaissance that once took skilled humans days into automated, tireless probing. At the same time, LLM and agentic AI systems increasingly depend on API integrations, either directly or through MCP intermediaries, which makes detecting API abuse more urgent than ever. The line between legitimate automated traffic and adversarial automation continues to blur. We will look at where API management and AI governance are beginning to converge, with enterprise API gateways now extending their platforms to offer AI gateway controls governing model access, prompt traffic, and tool invocation.

 

Finally, the session confronts what may be the thorniest problem of all: non-human identities. As AI agents, developer tooling, and enterprise applications proliferate, machine-to-machine credentials now vastly outnumber human ones, yet they are too often over-permissioned, long-lived, and weakly monitored. We will explore why NHIs sit at the heart of API security in an AI-driven workforce, and what organizations can do to bring identity, governance, and runtime detection together before the gap widens further. Attendees will leave with a clear mental model for thinking about API risk and a concrete sense of where AI raises the stakes, for attackers and defenders alike.

Location

Online Instructions:
Url: https://www.universe.com/events/apis-under-siege-securing-the-connective-tissue-of-ai-systems-tickets-R0CMYJ
Login: A zoom link will be sent to you approximately 30 minutes prior to the webinar. If you do not receive a code please check your spam or junk folder. If you still cannot find an email please email education@sfisaca.org.

Contact