BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-bristol-2026//speaker//TRPMMU
BEGIN:VTIMEZONE
TZID:Europe/London
BEGIN:DAYLIGHT
DTSTART:20250822T000000
TZNAME:BST
TZOFFSETFROM:+0100
TZOFFSETTO:+0100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T020000
RDATE:20261025T020000
TZNAME:GMT
TZOFFSETFROM:+0100
TZOFFSETTO:+0000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T020000
RDATE:20270328T020000
TZNAME:BST
TZOFFSETFROM:+0000
TZOFFSETTO:+0100
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:The Silence of the LAMs: Detecting Rogue Language Models - Tasha A
 rmstrong-Godwin
DTSTART;TZID=Europe/London:20260822T100000
DTEND;TZID=Europe/London:20260822T104000
DTSTAMP:20260812T225217Z
UID:pretalx-bsides-bristol-2026-ZBGFFL@pretalx.com
DESCRIPTION:First principles: the most dangerous threats in your enterpris
 e aren't the ones making noise. They're the ones you've already let in.\nS
 hadow AI: the use of unapproved AI tools\, models\, and services without I
 T or security oversight  is now one of the fastest-growing sources of unco
 ntrolled data exposure in organisations of every size. Microsoft research 
 confirms that 71% of UK employees have used unapproved consumer AI tools a
 t work\, with 51% doing so every single week. Most security teams have no 
 visibility whatsoever. The transaction is frictionless\, the blast radius 
 is enormous\, and the perpetrator is probably your most productive employe
 e.\nThis talk is structured around the three questions: where is it hiding
 \, how do you find it\, and what do you do when you finally locate it in t
 he dark?\nWhere is it hiding? We'll map the Shadow AI attack surface: publ
 ic LLM APIs called directly from corporate devices\, AI-powered browser ex
 tensions intercepting clipboard and page content\, local models running en
 tirely on-device to evade network controls\, agentic automation workflows 
 quietly piping internal data to external inference endpoints\, and AI feat
 ures embedded inside approved SaaS tools with their own opaque data handli
 ng.\nHow do you find it? We'll look at detection across the stack. At the 
 network layer: DNS monitoring against a continuously updated AI domain blo
 cklist\, TLS SNI inspection without decryption\, and NetFlow anomaly detec
 tion for large sustained POST volumes. At the endpoint: EDR telemetry for 
 local LLM runtimes\, model weight file signatures\, and browser extension 
 enumeration. At the identity layer: OAuth consent grant analysis\, SSO byp
 ass detection\, and personal account usage on corporate devices. Tying it 
 all together with SIEM correlation rules that build high-fidelity Shadow A
 I alerts from low-fidelity signals.\nWhat do you do when you find it? Here
 's where most organisations struggle. Blocking doesn't work\, it just driv
 es the behaviour underground\, onto mobile hotspots and personal laptops. 
 We'll cover incident response for Shadow AI exposure events\, how to build
  an AI acceptable use policy employees will actually follow\, and how to c
 onstruct an approved AI programme that removes the incentive to go rogue i
 n the first place.\nAttendees will leave with an idea for a detection play
 book\, practical SIEM rules they can implement the following Monday\, and 
 a slightly unsettling awareness of what my be lurking in the dark.\n"You s
 till wake up sometimes\, don't you? Wake up in the dark?" Maybe hopefully 
 you can sleep soundly knowing you have a plan to stop the lams screaming.
LOCATION:Track 1
URL:https://pretalx.com/bsides-bristol-2026/talk/ZBGFFL/
END:VEVENT
END:VCALENDAR
