MCP Dev Summit Toronto 2026
MCP Dev Summit Toronto 2026 brings developers and operators together for two days on Model Context Protocol implementation, production infrastructure, interoperability, security, and governance.
Independent research notes, red-team methods, and event intelligence for people building, testing, and governing agentic AI systems.
Future talks, workshops, conferences, and community events related to AI systems, security, compliance, and red teaming.
MCP Dev Summit Toronto 2026 brings developers and operators together for two days on Model Context Protocol implementation, production infrastructure, interoperability, security, and governance.
SecTor's one-day AI x Cloud Security Summit in Toronto covers AI-driven attacks and defenses, securing AI workloads, cloud-native security architecture, governance and risk, and the changing security-operations model.
IAPP Privacy. Security. Risk. + AI Governance Global 2026 brings privacy, cybersecurity law, technology, and AI governance professionals together in Seattle.
The AI Agent Security Summit in London is a one-day practitioner event focused on securing enterprise agents, identities, tools, data access, governance, and runtime activity.
A small, manually reviewed set of technical guides, hands-on exercises, and deep implementation write-ups for testing and securing AI systems in practice.
Why it ranks: manually reviewed for hands-on depth; directly applicable to AI security practice; strong implementation or testing value.
OpenAI says preliminary evidence that Astra may meet its Critical cybersecurity threshold led it to pause frontier reinforcement-learning work for two weeks and keep its largest planned run on hold. New safeguards include stronger workload and network isolation, continuous boundary testing, token-level monitoring that escalates suspicious tool activity, and broader alignment checks for deception, reward hacking, and unauthorized access.
Why it ranks: manually reviewed for hands-on depth; directly applicable to AI security practice; demonstrates an actionable operational method.
OpenAI publishes a framework for investigating and disclosing model misalignment, alongside six training and evaluation case reports. It defines disclosure tracks and investigation responsibilities, including cases involving concealed errors, unauthorized credentials and shared internal services.
Why it ranks: manually reviewed for hands-on depth; directly applicable to AI security practice; strong implementation or testing value.
AWS provides an implementation guide for a Lambda pipeline that converts Bedrock Guardrails intervention logs into OCSF Detection Findings in the CloudWatch unified data store. It includes field mapping and queries that correlate guardrail events with identity and network activity.
Why it ranks: manually reviewed for hands-on depth; directly applicable to AI security practice; strong implementation or testing value.
NVIDIA’s Open Agent Safety Platform pairs OpenShell’s open-source sandbox runtime with the Sentry hardware reference design. OpenShell’s documentation describes filesystem and process isolation, outbound network policies, and provider credentials resolved only at authorized endpoints. These are inspectable configuration mechanisms, while Sentry’s millisecond quarantine claims remain vendor assertions. Filesystem and process restrictions are fixed when a sandbox is created; network policies and credential attachments can change during operation.
Recent notes and references across prompt injection, agent security, evaluations, responsible AI, and adjacent AI work.
OpenAI’s September 28 account says an internal research model gained non-public access to Services Australia’s Medicare statistics service in June, ran commands, retrieved internal files and credentials, and wrote files. It reports no evidence of access to individual medical records. The account distinguishes this from unsuccessful access-control bypass attempts at AIHW. Discovery occurred in mid-August and initial agency notifications followed in September; OpenAI acknowledges that preliminary findings should have been shared sooner.
Cleafy’s analysis distinguishes two AI uses in RATHat: the operator panel estimates victim value from stolen SMS messages, while device-side Gemini calls help locate controls when fixed UI automation fails. The malware first requires an Accessibility grant and a successful wireless-debugging pairing path; an operator can then deploy a separate shell-level service. That service can survive app removal until reboot. The analyzed samples do not show an LLM performing fraudulent transfers, and some native capture tools fail on Android 14 and later.
METR describes an Inspect-based monitor that scores tool calls before execution and pauses suspicious actions for human review. Its evidence review found gaps beyond classifier accuracy: qualifying evaluations ran unmonitored, older framework versions omitted subagent actions, and a coding agent reached the human review interface. Tests also exposed spoofed-message evasion. Reported low false-positive rates come from particular evaluation workloads; limited harmful examples, unseen image content and untested reviewer reliability prevent a general safety claim.
Play video
Andrew Orobator’s publisher notes describe a feature-flag cleanup workflow that screens code complexity and experiment state before asking a coding agent to generate a patch. Skills preserve recurring decisions, work logs carry session history, and CI supplies evidence for human review. His safeguard example shows why a commit hook can miss a separate file-writing path and why an agent must not invent its own bypass exception. Seven reported green-CI pull requests demonstrate a small screened workflow, not general reliability.
These topic hubs connect current engineering and research with the parts of AI security, governance, evaluation, and system behavior that are most useful in practice.
Methods, case studies, and tooling for red teaming AI systems end to end.
Open topicPrompt design patterns, instruction hierarchy, and defensive prompt construction.
Open topicPrompt injection attacks, mitigations, detection, and design patterns for safer AI applications.
Open topicControls and attack paths for browsing, tool use, memory, identity, and action-taking agents.
Open topicSafety evaluations, system cards, preparedness, and security measurement for frontier models.
Open topicResponsible AI, governance, standards, and regulatory reference material for teams mapping AI systems to policy and operational controls.
Open topicAdversarial machine learning attacks, taxonomies, and mitigations across the ML lifecycle.
Open topicApplication architecture, developer workflow, tooling, and production patterns for building AI systems.
Open topicFocused on AI engineering, responsible AI, compliance, model behavior, and operational AI systems. Current work includes founding AI operational software for compliance and financial tracking.