MEET THE TEAM AT BLACK HAT - DEF CON 2026 Learn More

Where AI Breaks: Field Notes from GenAI and Agentic Testing

Date:
Tuesday, August 25
Time:
2 p.m. ET / 7 p.m. BST
Virutal Session on Where AI Breaks: Field Notes from GenAI and Agentic Testing.

AI is moving faster than most security programs can keep up with. Teams are shipping GenAI features, wiring up LLMs to internal data, and handing agents the keys to take real actions. The question that keeps surfacing is a simple one: what happens when someone decides to break it?

For the past year, Bishop Fox consultants have been answering that question in the field. They've assessed GenAI deployments, run penetration tests against LLM applications, and torn into the agentic systems teams are standing up right now. The findings are revealing, occasionally alarming, and genuinely useful if you're trying to build or defend any of this.

Join Bishop Fox consultants Derek Rush, Michael Cheng, and Katie Ritchie as they pull back the curtain on what they're seeing. Together they'll cover:

  1. The recurring weak spots showing up across GenAI assessments
  2. What a real LLM penetration test report actually contains, so you know what rigor looks like before you commission one
  3. How to embed security into agents while they're still in development, when fixing things is cheap
  4. How to put agentic solutions to work on your own security data
  5. What architecture reviews of agentic implementations reveal about where these systems quietly fall apart

Whether you're building with AI or racing to secure what your teams have already shipped, you'll leave with a sharper sense of where the real risk lives and what to do about it. Stick around for live Q&A at the end.


Derek Rush BF Headshot

About the speaker, Derek Rush

Managing Senior Consultant

Derek Rush, a Managing Senior Consultant, brings vast proficiency in application penetration testing and network penetration testing, both static and dynamic, to the table. With a wealth of experience, Derek has successfully performed dynamic testing for a range of high-profile clients in the healthcare, government, and logistics sectors.

His expertise is backed by a list of impressive certifications, including Certified Information Systems Security Professional (CISSP), Offensive Security Certified Professional (OSCP), Practical Web Application Penetration Testing (PWAPT), eLearnSecurity Web Application Penetration Tester (eWPT), and eLearnSecurity Certified Professional Penetration Tester (eCPPT).


Katie Ritchie BF Headshot

About the speaker, Katie Ritchie

Senior Consultant

Katie (Kat) Ritchie is a Security Consultant at Bishop Fox focused on Application Security. Katie is an accomplished penetration tester and holds several offensive security certifications including GIAC Security Essentials (GSEC), GIAC Certified Incident Handler (GCIH), and GIAC Web Application Penetration Tester (GWAPT). Katie graduated from James Madison University with a B.S. in Psychology and a Minor in Writing and Rhetoric.


Michael Cheng Bio

About the speaker, Michael Cheng

Senior Security Consultant

Michael Cheng is a Senior Security Consultant I at Bishop Fox, where he focuses on AI red teaming and AI penetration testing, helping organizations identify and mitigate emerging risks in AI-driven systems. He brings a blend of offensive security expertise and cross-functional program experience to complex security challenges. He previously served as a Security Consultant III at Bishop Fox, where he contributed to advancing AI-focused offensive security capabilities.

Michael holds a Master’s degree in Computer Science from Hofstra University, where his thesis focused on reverse engineering and binary analysis of Linux ELF executables. He is fluent in both Mandarin Chinese and English.

Ready to get started? We can help.

Contact Us