Rowan Udell, AWS Security Hero AWS Summit Sydney 2026
Treat them like software.
Traditional App
Deterministic execution
AI Agent
Probabilistic outcomes are a feature, not a bug
are not reliable enough.
Simon Willison, 2025
An AI agent that helps Australians with tax returns, deductions, and financial planning
It has access to financial records, processes documents from users, and takes actions with the ATO and banks
Any concerns?
Sensitive Data
Untrusted Content
External Actions
is still your best friend.
The trifecta is only lethal with all three.
Pick a leg to remove
memoryStrategyId
actorId
sessionId
bedrock-agentcore:namespace
SchemaDefinition
forbid
when
Secure them like software.
Questions? No time for questions! Happy to chat after
I help teams move agents from prototype to production
reveal: on