Resources / Talk

Security Drift: What happens when you let different AI agents build your APIs

ISRA Chapter Meetup Kochi · Talk

Kochi, Kerala, India ยท 25 July 2026

At the ISRA Kochi Chapter Meetup, Fahad Faisal from our team talked about Cross-Agent Security Drift, what happens to API security when several AI coding agents work on the same codebase.

ISRA, the Information Security Research Association, is a non-profit community of security professionals in India. It runs local chapters in different cities and each chapter holds regular meetups where people come together to share research and talk about new cyber security concepts.

This talk was about how API security quietly weakens across a normal development cycle. Developers start with one AI agent and may use multiple agents for the development, switching between them for a new feature, a quick inline edit or for fixing bugs. The gap is that in between the agents, the security context does not copy with the code, so authorization rules or the documented security requirements may get quietly edited or dropped. An agent that is asked only for functionality will read the surrounding code and follow the patterns it finds there and once a bug is introduced it becomes the convention the next agent copies. None of this looks like a failure so the endpoints still work and no review flags a change.

Fahad walked through five common stages of development to show where security can be overlooked when the right context isn’t provided. He showcased why the instruction file alone is not enough for a secure development cycle and talked about the developer’s responsibility when giving context to each agent and also covered how this can be properly fixed before it reaches production by making use of authorization checks and similar rules. The venue was filled with curious minds and the talk was followed by a good round of questions from the audience.

Slides

Open the slides (PDF) if they do not display above.

Event photos

Fahad Faisal presenting the Security Drift talk at the ISRA chapter meetup in Kochi
Fahad Faisal receiving a certificate of appreciation at the ISRA chapter meetup in Kochi


Make sure your APIs are still as safe as you think

BreachSimRange runs red teaming, threat-led breach and adversary simulation that mirror how modern threat actors operate, so you find the gaps before they do.

Talk to us about Consulting