Enable · Workshop

    Teach your engineers to think like the attacker of their own agent

    A hands-on day for people who build with AI, not for people who write policy about it. Your team leaves with a working mental model of how AI systems fail and break in practice.

    Sound familiar?

    • Developers ship AI features without ever having seen a prompt injection succeed.
    • Security teams review AI code with a checklist built for classic web apps.
    • Nobody in the room can explain the difference between a jailbreak and a data exfiltration attack.
    • Vendors sell tools before your team can even evaluate whether the tools work.

    What we do

    Attack the model, live

    Participants run real prompt injection, jailbreak and data exfiltration attempts against a sandboxed system — not slides about them.

    Agent and tool-call risks

    How an agent with tool access turns a text-generation bug into a system compromise, and where that boundary actually sits.

    Defence patterns that hold up

    Input and output filtering, sandboxing, permission scoping and monitoring — what actually reduces risk versus what only reduces paperwork.

    Bringing it back to your stack

    A closing session mapping the day's attacks to your own architecture, so the workshop produces a punch list, not just an experience.

    Framework

    Duration
    1 day (approx. 7 hours incl. breaks)
    Group size
    8-12 participants
    Format
    In-house at your site or remote
    Prerequisites
    Basic familiarity with how your team ships software; no security background required.
    Who it's for
    Engineers, ML practitioners and technical product owners building AI features
    Investment
    on request (fixed in-house day rate)

    Agenda

    1. Morning: live prompt injection and jailbreak attempts against a sandboxed system
    2. Data exfiltration and model extraction walkthrough
    3. Agent and tool-call risk: from text bug to system compromise
    4. Defence patterns — input/output filtering, sandboxing, permission scoping
    5. Monitoring and detection for AI-specific attacks
    6. Closing session: mapping attacks to your own architecture and next steps

    Questions we get

    Do participants need a security background?

    No. We ask for people who build or ship AI features — engineers, ML practitioners, technical product owners. Security experience helps but is not required.

    Is this the same content as your Agent Security service?

    No. The workshop builds skill and intuition in your team. Agent Security is us doing the assessment and hardening on your actual system.

    Can you run this in a language other than English?

    Yes, we run this workshop in English or German depending on your team.

    Tell us what's running in production.

    We'll tell you what we'd check first — and what we wouldn't bother with.

    Book a call
    Related
    More in Enable