14:00–14:20
| Master of Ceremony: Liang Wei, Vice Chair of ITU-T Study Group 17 (SG 17) I Vice President, China Academy of Information and Communications Technology (CAICT) Opening Remarks
- Ministry of Industry and Information Technology (MIIT)
- Chongqing Municipal Commission of Economy and Information Technology
-
Arnaud Taddei, Chair, ITU-T Study Group 17
-
Yuyou Sun, Deputy General Manager, China Inspection and Certification Group
|
14:20–14:40
| Group Photo (Hotel Lobby / 1st Floor)
|
| Master of Ceremony : Naying Hu , Associate Rapporteur Question 16/17, CAICT |
14:40–15:00
| Session 1: Security Risks and Attack Surface Analysis of Agentic AI
This session maps the distinctive attack surface of Agentic AI — unauthorized tool and action execution, cross-agent identity spoofing, behavioral deception and goal hijacking, supply-chain poisoning, and loss of autonomous control. Using the recent OpenAI–Hugging Face security incident and other red-team findings as starting points, the session will examine how autonomous planning and self-directed execution may enable AI agents to go beyond intended boundaries, combine multiple attack steps, access external systems, and take actions that are neither anticipated nor authorized by human operators. The aim is to turn these findings into a shared, evidence-based threat picture for SG17's later work.
Moderator: Heung Youl Youm, Soonchunhyang University, Korea (Rep. of)
- Wei Xu, Professor at College of AI, Vice Dean of Institute for Interdisciplinary Information Sciences, Tsinghua University
|
|
15:00-16:50 | Session 2: Security Mechanisms for Agentic AI This session examines security mechanisms built into the agent itself — secure-by-design architecture, policy-driven decision constraints, runtime self-inspection, chain-of-thought and behavioral monitoring, and secure update. It explores the standardization needs arising from these new situations, focusing on the gap between what Agentic AI now demands and what SG17's existing standards already cover. Moderator: Zhiyuan Hu, vivo Mobile Communication Ltd., WP4/17 Chair
- Xudong Pan, Associate Researcher (Xuemin Fellow), Fudan University; Full-time Mentor, Shanghai Innovation Institute
Topic: Towards Safe and Secure Agentic AI Systems with AgentGuard - Tian Tian, Senior security standardization and product expert, Head of the Security Platform Department at ZTE Corporation.
Topic: Security for Agentic AI:Threats and Mitigations - Feng Gao, Chief Cybersecurity Expert, China Unicom, ITU-T Q7/17 Associate Rapporteur
Topic:AI-Enabled Application Security Standards: What Should We Do? - Xiaojian Li, Founder and CEO of Fangcun AI.
Topic: The Agent's Own Control Plane: Decision-Time Security Enforcement and Emergent Misbehavior Evaluation
|
15:50-16:00
| Coffee Break |
16:00-16:50
| Session
3: Security
Evaluation and Verification Methods for Agentic AI
This session explores how to evaluate and verify the security of Agentic AI systems — security testing, formal verification, runtime audit and security metrics — within standardized assessment frameworks. It takes an integration-centric view: as agents are integrated into real ICT systems, evaluation must establish a verifiable baseline at the point of integration, and define what security evidence and assurances integrators should require from the suppliers of agents, tools and models.
Moderator : Kai Wei, ITU-T WP2/21 Vice-chair, Director of AI Institute, CAICT - Lin Shi, Engineer, Deputy Director, Security, Safety and Governance Department, AI Institute, CAICT
Topic: Analysis on Obsequiousness Assessment of Large Models and AI Agents - Xiaofang Yang, Head of Agent Security Operations at Alibaba Group
Topic: From Model Spec to System Spec: Building a Verifiable Security Baseline for Agentic AI - Clement Neo, Founder & Research Lead of Neo Research
Topic: Knowing When to Stop: Evaluating Overeagerness in Agents - Yu Tang, Senior Expert, China Automotive Engineering Research Institute Co., Ltd.
Topic: Agentic AI Trustworthiness Evaluation System: Establishing a Trustworthy Baseline for Intelligent Vehicle Integration
|
16:50-17:30
| Session
4:
What Frontier Developers Can Give Us — Securing Agentic AI in Practice
This session asks whether it is affordable in practice, and brings in the frontier model developers best placed to answer. The focus is on the trade-offs that only appear once a real model ships. How much capability does security cost? Where does assurance break down at frontier scale? Which of the requirements cannot yet be met? Developers from leading frontier model enterprises will give a frank verdict on what is easy and what is hard. They will also share what they can offer the wider ecosystem, including the practices and evidence ready to be reused, and the open problems where industry still needs support.
Moderator: Debora Comparin, Thales Group | WP1/17 Chair
- Shiqi Li, Alibaba, Lead of security standardization: ''Confidential computing based Agentic AI security''
- Dong Zhang, vivo, AI security researcher and AI governance practitioner: ''On-Device Trust Control Plane for Agentic AI''
- Junchen Shen, MiniMax, Executive Editor: ''From Perception to Permission: Preserving Goal Integrity in Multimodal, Long-Horizon Agents''
- Ze Shen Chin, researcher at the Singapore AI Safety Hub, a co-lead of the AI Standards Lab, and a research affiliate at the Oxford Martin AI Governance Initiative : ''What common agent ID protocols do and don't address (potentially from the perspective of the OpenAI Hugging Face incident''
|
17:30-17:40
| Future outlook and closing remarks
|