TestMu Conf 2026
Ship Faster. Test SmarterJoin Now
Ship Faster. Test SmarterJoin Now
SESSION

Testing the Untestable: Turning OWASP AI/LLM Risks into Practical QA Checks

AUG 21, 202609:30 - 10:00 AM (PT)30 MINS

AI and LLM features are now entering products faster than most teams can test them. That speed creates a new quality gap: traditional test automation verifies APIs and UI flows, but it often misses prompt injection, data leakage, unsafe output, hallucinations, agent misuse and model behavior drift. This talk shows how testers can translate OWASP AI/LLM risk categories into a practical testing approach that fits real QA pipelines.

Attendees will learn how to think about AI systems as testable software components across the application, model, infrastructure and data layers. The session will demonstrate how to design test cases for prompt injection, indirect prompt injection, sensitive-data exposure, output safety and agentic behavior limits, then convert those into repeatable checks for regression, CI/CD, and release gates.

The focus is deliberately testing-first: what a QA engineer can observe, assert, automate and report. By the end, participants will leave with a tester's checklist for AI features, a simple risk-based framework for prioritizing test effort and ideas for integrating AI security verification into everyday quality engineering practice.

Key Takeaways:

  • Takeaway

    Testers will learn how to convert OWASP AI/LLM risks into test cases that can be executed in QA workflows.

  • Takeaway

    The audience will understand how to check for prompt injection, data leakage, unsafe output, hallucination, and agent misuse.

  • Takeaway

    Attendees will see how to add AI risk checks into regression, CI/CD, and release gates.

  • Takeaway

    The talk will help QA teams treat AI behavior as something measurable, assertable, and reviewable, not as a black box.

About the speaker

Thejes Sree Satheesh Kumar:

Thejes Sree Satheesh Kumar (She/Her) is a Quality Analyst - Consultant at Thoughtworks, specializing in application and AI security testing. She is a Certified Ethical Hacker and holds CompTIA Security+ and Google Cybersecurity Professional certifications. Thejes combines quality engineering and security practices to build resilient software systems. She is passionate about secure AI ecosystems and advancing defensive strategies for emerging technologies like the Model Context Protocol. Following deep-dive presentations at Nullcon Goa and TechXpresso, she is currently co-authoring the forthcoming book 'Breaking the Model Context Protocol: Agentic Attacks and Defenses for MCP-Powered AI Systems' (expected October 2026).

TESTMU-CONF 2026

GET YOUR FREE BOARDING PASS

I agree to TestMu AI's Privacy Policy, Conference Terms and Conditions.

About
TestMu Conf

Testμ (TestMu) is the world’s largest virtual conference on agentic engineering and quality, built by the community, for the community. As AI reshapes how we build, test, and ship software, Testμ Conf is where you connect, grow, and lead: agentic workflows, autonomous quality, battle-tested AI playbooks, hands-on workshops, and the engineering culture driving it all.

More Sessions

Join the builders, testers, and innovators shaping the next generation of web experiences.
Testμ Conf 2026 is where they meet.

Register Now