AI Applications Security Puzzle
Someone tells your AI assistant to ignore its instructions. It does. Someone asks it a question it was never supposed to answer. It answers. Someone crafts a message that makes it act outside its intended scope. And it doesn't push back.
These are patterns from live products, already deployed, already used. And in most of the teams where they happened, there was no test for it. Not because anyone was careless, but because nobody asked the right questions.
This talk is a grounded look at how AI systems get exploited in practice. We'll work through public cases, use the OWASP AI Testing Guide as our map, and name the failure patterns clearly enough that you'll recognize them when you see them in your own product.
As AI gets added to more products, the attack surface significantly grows. 44% is the year-over-year increase in the exploitation of public facing software. Most teams are focused on whether AI integration works: Does it give good answers? Does it feel right? Is it biased? The harder question: "What happens when someone tries to manipulate it?" — gets pushed to later. But later rarely comes.
AI security issues are not always caught by security specialists. They're caught by people who think critically, ask questions, and dig a level deeper to find the answer.
You may not walk out of this talk as an AI security expert. But you will walk out knowing what questions to ask and why asking them is already your job.
Key Takeaways:
Why knowing your app architecture is essential to see possible attack vectors.
How to use the OWASP AI Testing Guide to identify and prioritize AI-specific vulnerabilities.
Which failure patterns to look for in products you're already testing.
What questions to bring back to your team to start closing the AI security gap.
About the speaker
Maryia Tuleika:
Maryia is a Quality Engineering Leader who leads teams, creates testing strategies, drives education programs and actively contributes to the testing community. As a mentor, speaker and podcast host, she helps new test professionals build their skills and confidence. With experience spanning multiple industries, she brings a broad perspective on testing and risk-based decision-making. She believes that great testing brings both technical excellence and knowing what to prioritize, think critically and enjoy the process. Maryia takes an active role in conferences around the globe. In recent years, she has spoken at several international events, has been a program chair, program committee and review member. She is a podcast host and a co-founder of Beyond Quality community of practice.
About
TestMu Conf
Testμ (TestMu) is the world’s largest virtual conference on agentic engineering and quality, built by the community, for the community. As AI reshapes how we build, test, and ship software, Testμ Conf is where you connect, grow, and lead: agentic workflows, autonomous quality, battle-tested AI playbooks, hands-on workshops, and the engineering culture driving it all.