23 MBA Studierende, 7 Teams, 0 Coding Erfahrung – das Ergebnis? Großartig.
Between AI Security and Digital Sovereignty
Trending topics at the German OWASP Day 2026: In case you didn't make the trip to Karlsruhe in September, let me give you the gist of this conference. I took a lot of pointers to useful resources with me that I'd like to share with you.
AI Security takeaways
The OWASP community is deeply engaged
There are tons of resources that the OWASP community is creating around AI Security within the existing OWASP community pages. Their work – especially that of Rob van der Veer – also served as input for the EU AI Act and for the standard ISO/IEC 27090 on Cybersecurity regarding Artificial Intelligence that is currently under publication.
Training Material
OWASP AI Exchange – owaspai.org
OWASP GenAI Security Project – genai.owasp.org
Guides and Cheat Sheets
OWASP AI Agentic Security Cheat Sheet
OWASP Agentic Skills Top 10OWASP Top 10 for Agentic Applications for 2026
TIL: The Lethal Trifecta is a useful quick assessment
Many talks referred to the Lethal Trifecta, a security assessment model by Simon Willison (LinkedIn, GitHub), that states you should never equip an AI Agent with all of the three following:
- Access to your private data
- Exposure to untrusted content
- The ability to externally communicate
... because if an AI Agent is equipped with the Lethal Trifecta this will open an attack vector for malicious actors.
Understanding Security Engineering priciples is key
Many examples when people or organsiations fail to work securely with AI made me think that if they had followed established Security Engineering principles, they would have not run into these problems. So while AI is disrupting how we work, I'm convinced that Technical Excellence that was acquired pre-GenAI will enable secure adoption of Agentic Engineering and it is never in vain to learn foundational principles.
Agentic gateway at OS level: Wirken.ai
Davi Ottenheimer's talk about his enterprise gateway for autonomous agents was truly inspiring: keys stay in a vault – enforcing to minimize attack surface area – and the Agents' priviledges are constrained on OS level, thus enforcing the priciple of least priviledge. Also Wirken.ai creates three tiers of permission levels for actions – enforcing separation of duties – and a signed hash-chained audit log that can be verified offline.
Last but not least, Wirken.ai is build based on the understanding that an agent cannot be trusted, like laws are build on the assumption that an individual cannot be trusted. Don't trust services, more commonly known as Zero Trust, is a core Security Engineering principle that we need to keep in mind in Agentic Engineering as well.
Watch Davi's talk and check out his project.
Threat modeling for AI Agents
Similarly, Christian Schneider stressed the principle don't trust services, explaining how to benefit from the usage of attack trees when threat modeling for AI Agents.
Watch Christian's talk and check out his blog.
MCP Server Security
Maximilian Hildebrandt's talk how to hack MCP servers struck me especially: he proved that of 19 SQL MCP Servers 14 were not read only as they claimed, stressing the principle of defense in depth. Keep in mind that the security promise of an MCP Server (or any software component) might fail. In this case, connecting an SQL MCP Server with a database user that is limited to read only means applying the principle of least priviledge and will secure your data.
He provided pull requests with security fixes and did responsible disclosure. About half of the found vulnerabilities have been fixed by now.
Digital Sovereignty takeaways
Adding this section soon.
Also: Post Quantum Security
While there was no talk regarding this topic that I watched, Post Quantum Security is an important topic that we discussed by the side. People agreed: the time to get an inventory of all your secrets and rotate them regularly is now – or even better: yesterday.
Talks on media.ccc.de
Many talks were recorded – watch them here.
My biggest takeaway?
The connections and the community. Attending the OWASP Diversity PreCon and the German OWASP Day was really worth travelling from Hamburg to Karlsruhe and one of my best conference experiences of the last years.
I knew no one and was immediately approached and integrated. Usually it's me reaching out to strangers at such events. Within the OWASP community, conversations sparked naturally and everyone reached out to everyone.
The dinner event before the conference was a highlight and – as I learned – is an important tradition of the community. It was both fun and inspiring!