Testing the Untestable: Turning OWASP AI/LLM Risks into Practical QA Checks
AI and LLM features are now entering products faster than most teams can test them. That speed creates a new quality gap: traditional test automation verifies APIs and UI flows, but it often misses prompt injection, data leakage, unsafe output, hallucinations, agent misuse and model behavior drift. This talk shows how testers can translate OWASP AI/LLM risk categories into a practical testing approach that fits real QA pipelines.
Attendees will learn how to think about AI systems as testable software components across the application, model, infrastructure and data layers. The session will demonstrate how to design test cases for prompt injection, indirect prompt injection, sensitive-data exposure, output safety and agentic behavior limits, then convert those into repeatable checks for regression, CI/CD, and release gates.
The focus is deliberately testing-first: what a QA engineer can observe, assert, automate and report. By the end, participants will leave with a tester's checklist for AI features, a simple risk-based framework for prioritizing test effort and ideas for integrating AI security verification into everyday quality engineering practice.
Key Takeaways:
Testers will learn how to convert OWASP AI/LLM risks into test cases that can be executed in QA workflows.
The audience will understand how to check for prompt injection, data leakage, unsafe output, hallucination, and agent misuse.
Attendees will see how to add AI risk checks into regression, CI/CD, and release gates.
The talk will help QA teams treat AI behavior as something measurable, assertable, and reviewable, not as a black box.
About the speaker
Thejes Sree Satheesh Kumar:
Thejes Sree Satheesh Kumar (She/Her) is a Quality Analyst - Consultant at Thoughtworks, specializing in application and AI security testing. She is a Certified Ethical Hacker and holds CompTIA Security+ and Google Cybersecurity Professional certifications. Thejes combines quality engineering and security practices to build resilient software systems. She is passionate about secure AI ecosystems and advancing defensive strategies for emerging technologies like the Model Context Protocol. Following deep-dive presentations at Nullcon Goa and TechXpresso, she is currently co-authoring the forthcoming book 'Breaking the Model Context Protocol: Agentic Attacks and Defenses for MCP-Powered AI Systems' (expected October 2026).
About
TestMu Conf
Testμ (TestMu) is the world’s largest virtual conference on agentic engineering and quality, built by the community, for the community. As AI reshapes how we build, test, and ship software, Testμ Conf is where you connect, grow, and lead: agentic workflows, autonomous quality, battle-tested AI playbooks, hands-on workshops, and the engineering culture driving it all.