apisec University

apisec|con 2026 · Fall edition · Call for speakers open

The future of AppSec in the age of AI

Four hours, no vendor pitches. Practitioners on what changes when the code is written by models and the traffic is generated by agents.

Date
Wednesday, October 21, 2026
Time
12:00 – 4:00 PM ET · live and on demand
Venue
Virtual · join from anywhere
Admission
No costCPE credits
Speaking
Call for speakers · closes Sept 13

Register

Free, and every session is on demand afterwards. Registration is handled on our event platform, which sends your calendar hold, the reminder the week of, and the join link on the day.

On signup
Calendar hold
Oct 21
Join link · emailed that morning
After
Session recordings · within a week
Optional
CPE certificate

Registration is processed by RingCentral Events. No sponsor list sharing.

Why this year

The attack surface moved while everyone was writing policies

AI did not add a new category to application security. It changed the volume, the authorship, and the identity of everything already in it. Three shifts are driving this year's program.

Shift 01 · Authorship

Machines write the code now

Assistants ship endpoints faster than review can absorb them. The generated controller handles input validation well and object-level authorization badly, because authorization is context the model never had. Broken object level authorization was already the top API risk. Now it scales.

Shift 02 · Identity

The caller is not a person

Agents, tool-calling frameworks, and MCP servers authenticate as service accounts with standing privileges and no session. Non-human identities now outnumber human ones in most environments, and almost none of them have an owner, a rotation schedule, or a scope anyone can justify.

Shift 03 · Volume

Abuse at machine speed

Automated discovery maps an undocumented endpoint in minutes. Rate limits tuned for humans are trivial for agents. Detection has to work on behavior across a session, not on a signature in a single request.

Agenda shape

How the four hours run

The shape is fixed, the content is not. Sessions are filled from the CFP and published September 23.

12:00 PM ETOpening keynote30 min · Main stage
12:35 PM ETSession block oneTwo parallel tracks
1:35 PM ETHands-on lab40 min · Follow along
2:20 PM ETSession block twoTwo parallel tracks
3:20 PM ETLightning talksSix in thirty minutes
3:50 PM ETClosing panelWhere this goes next

Speaking

The program is not written yet

Sessions are filled from an open call. If you have working code, a real incident, or a method that failed in an instructive way, the call is open until September 13. Product pitches are rejected on sight, including ours.

Submissions close Sunday, September 13

 

Decisions sent by September 18 · Program published September 23

Track record

Who else is in the room

150k+Practitioners on apisec University
15k+AppSec pros in the Discord
50+Speakers, prior edition
$0To attend, always

Past apisec|con speakers include

Corey Ball Katie Paxton-Fear Ben Sadeghipour Tanya Janca Jason Haddix Colin Domoney

Prior editions have drawn practitioners from Kong, Akamai, Ford, Costco, and Axis Bank.

Two ways in

Attend, or help decide what is on it

Registration is open now and free. Want to be on the program instead? The call for speakers closes September 13.