Past event

On-demand webinar

The Normalization of Deviance in AI: Lessons From and Beyond the Month of AI Bugs

Virtual event
Feb 19, 2026 6:40 PM

Register today

Step 1 of 3

Key Takeaways
  • alert See how structured testing reveals agentic AI risksA repeatable methodology for evaluating coding agents and computer-use agents shows where security gaps hide in real deployments, so your team can assess these tools before they reach production.
  • identityMap the vulnerability classes that keep reappearingFrom RCE and credential exfiltration to persistent prompt injection and ZombAIs (agents that stay compromised across sessions), this research catalogs the specific flaw patterns that ship with agentic AI tools today.
  • userBuild your own evaluation capability for AI toolingWalk away with a practical framework for testing agentic AI systems internally, so your security team sets the bar for what ships rather than relying on vendor assurances.

About this webinar:

This session walks through original research from the Month of AI Bugs, a daily testing effort that put coding agents and computer-use agents through rigorous security evaluation. You will see exactly how a structured methodology surfaces vulnerability classes like RCE, credential exfiltration, persistent prompt injection, and ZombAIs in tools your teams may already use, including:

  • Learn a repeatable methodology for testing agentic AI systems before they reach your production environment.

  • See specific vulnerability classes found in real coding and computer-use agents, with concrete examples of how they manifest.

  • Recognize the "normalization of deviance" pattern where known flaws reappear release after release, and understand what that means for your risk posture.

  • Take home a practical framework for building internal AI security evaluation capability your team controls.

For those who are:

  • AppSec engineers and security researchers who need a tested methodology for evaluating agentic AI tools before their organization adopts them.

  • CISOs and security leaders who want to understand the real risk profile of coding and computer-use agents already in use across their teams.