As infrastructure gets more complex, "inside the network" is no longer enough. Users, devices, and AI agents need their own identity and only the access they need.
After five years in a codebase I knew by heart, I suddenly found myself back at square one in customer-facing native iOS development, and AI became my lifeline.
I first met Benoit Schillings, VP of Research at Google DeepMind, in San Francisco to talk about what engineers do when AI writes more of the code. His answer: make sense of the massive systems we inherit. Now, he’s bringing that perspective to Zadar for Infobip Shift 2026.
I set out to see how easily an AI agent could be manipulated by harmless-looking spreadsheets, so I kept escalating the prompt injection until it either caught on or took the bait.
We make many mistakes with MCPs, but one of the biggest is treating them like a 1:1 REST API mapping - when in reality, an MCP tool should be a capability, not just another endpoint.
Everyone is busy asking how big the model is, but the real question is what you fed it first - because if your PDFs are mangled and your OCR is sloppy, even the smartest LLM starts from the wrong answer.
Jordan Topoleski (COO, Cursor) and Pallavi Mahajan (CTO, Nokia) made the case that the next real breakthrough in AI development is agent orchestration.
AI agents are already being trusted with real work, but handing them raw credentials is a dangerous shortcut. That's why the next security challenge is controlling what an agent can do once it gets access.
Dana Lawson argues that AI has lowered the barrier to software development so much that the best way to learn is by building, shipping imperfect apps, and improving them along the way.