How Secrets Leak Through AI Agents (and How to Stop It) — Venice AI
A private model doesn't make a private product. The leaks happen in everything you build around it. Joshua Mo, lead developer relations engineer at Venice AI and previously lead maintainer of the Rust AI framework Rig, explains why privacy matters (one breach and users leave, and less stored data means a smaller blast radius) and how Venice approaches it: no stored prompts, anonymized requests to closed providers, models in trusted execution environments, and split-key encrypted storage. Then he shows where agent systems leak: logs that quietly capture prompts and secrets, and secrets fetched from a vault straight into the reasoning layer, where a tool call can exfiltrate them. His patterns: hashed IDs instead of personal data, split-key custody, revocable handles, narrow agent scope, a classifier in front of the agent to catch prompt injection, wiring the vault to the execution layer instead of the LLM, sandboxes plus permission monitoring, and confidential compute with verifiable attestations. He closes on the open problem of confidential tool calls. In this talk: • Why privacy is about blast radius, not just the model • How logs and secrets leak through a typical agent • Keeping credentials in the execution layer, never the LLM • Hashes, split keys, handles, narrow scope and confidential compute SPEAKER Joshua Mo, Lead DevRel Engineer, Venice AI LinkedIn: https://www.linkedin.com/in/joshua-mo-4146aa220/ X: https://x.com/joshmo_dev GitHub: https://github.com/joshua-mo-143 Website: https://joshmo.ooo LINKS Venice AI: https://venice.ai Venice API docs: https://docs.venice.ai Rig (Rust AI framework): https://github.com/0xPlaygrounds/rig CHAPTERS 0:00 Intro 0:55 What Venice is 1:40 Why privacy matters 2:35 How Venice handles privacy 4:15 Not all systems are private 5:05 The logging trap 5:54 How secrets leak through an agent 6:49 Patterns that work 7:54 Revocable handles 8:39 Narrow agent scope 9:29 Screening for prompt injection 10:44 Keep secrets out of the model 12:04 Sandboxes aren't a cure-all 12:54 Own your runtime 13:09 Confidential compute 14:49 Confidential tool calls Recorded at the AI Engineer World's Fair 2026 in San Francisco. Subscribe for more talks from the engineers building with AI. AI Engineer: https://ai.engineer YouTube: https://www.youtube.com/@aiDotEngineer X: https://x.com/aiDotEngineer LinkedIn: https://www.linkedin.com/company/aidotengineer/ #AIPrivacy #AISecurity #AIEngineer
More like this

AI Security Engineer Foundations + Certificate — Javier Garza, Snyk

Same Model, Different Speed: Why Your Inference Provider Matters — FriendliAI

SonarQube + OpenAI: Agentic Development — Killian Carlsen-Phelan, Sonar

Let Your Agent Cook: Using Skills to Evaluate and Improve Your App — Ankur Duggal, Arize AI
Join the discussion
Sign in to join the discussion
Sign in