Skip to content
Code To Cloud
6 min read

Whose Job Is AI Security? Notes from YYC DataCon, Anthropic's Latest Report, and What's Next at Prairie Dev Con

I was on the AI security panel at YYC DataCon on a Friday. The following Monday, Anthropic published exactly the report that backs up what we argued onstage.

By Kevin Evans

Four panelists seated in armchairs on the YYC DataCon 2026 stage, three holding microphones mid-discussion, in front of a teal curtain backdrop

Friday afternoon, September 11, I was on Stage 1 at YYC DataCon in Calgary's BMO Centre for a panel called "Whose job is it anyway? Security responsibility in the age of AI" — alongside Michael Moores, Brad Avery, and Dean Turner. The panel description opened with an Andrej Karpathy line that's stuck with me since: AI is "a powerful alien tool... it comes with no manual and everyone has to figure out how to hold it and operate it, while the resulting magnitude 9 earthquake is rocking the profession."

The following Monday, Anthropic put out a report that reads like the technical footnote to that exact conversation.

The Panel: Nobody Fully Owns This Yet

The honest answer we kept circling back to onstage is that "whose job is it" doesn't have a clean owner yet. Security teams are being asked to secure tools they didn't choose and don't fully understand. Developers are shipping agentic workflows faster than governance can review them. Leadership is signing off on AI adoption without always knowing what "adoption" is actually touching under the hood. Everyone has a piece of the responsibility, and pieces are exactly how things fall through the cracks.

That's not a Calgary-specific problem — it's the same gap I wrote about recently on shadow AI inside small businesses: the tools work, adoption is real and accelerating, and the accountability question is almost always the thing nobody assigned on purpose.

Then Anthropic Published the Data Behind the Question

Anthropic's September 2026 threat intelligence report, published September 10 — one day before our panel — covers malicious use of Claude that its own Threat Intelligence team disrupted between December 2025 and August 2026, across seven harm categories:

  • 20+

    Ukrainian/European orgs targeted (GTG-20006)

  • 1.8M

    Android APKs harvested for credentials

  • ~50

    Orgs hit in a single zero-day campaign

  • 9

    Influence-op cases, 4 countries, 6 continents

A few specifics stood out to me as directly on-topic for the panel:

  • GTG-20006, a Russian espionage operation, targeted more than 20 Ukrainian and European government and defense organizations, stealing drone technology data and credential records tied to over 300,000 national identity records.
  • GTG-10007, attributed to Chinese state-linked actors, targeted roughly 50 organizations globally and produced "more than a dozen possible zero day findings in a single month" — a pace of vulnerability research that would have needed a much larger team two years ago.
  • Nine separate influence-operation cases spanning Russia, Iran, Turkey, and Gulf states targeted six continents, including election-related campaigns in Malaysia and Moldova.

Anthropic's own framing is the line that ties straight back to Friday's panel: AI has "collapsed the labor and tooling gap" that used to separate a nation-state team from a single operator. The report documents autonomous agents doing reconnaissance, exploitation, and data exfiltration with minimal human oversight — on the attack side. Their recommended response for organizations is just as relevant on the defense side: treat AI API keys with the same seriousness as production credentials, buy AI access only through authorized channels, and manage and rotate keys rigorously.

The Uncomfortable Symmetry

The same agentic capability that makes a legacy-app modernization demo possible in an hour on a conference stage is the capability a threat actor used to run zero-day research at a pace that used to require a whole team. It's the same tool. That's exactly why "whose job is this" doesn't have an easy answer.

What's Next: Prairie Dev Con, September 21–22

I'm carrying this thread to Prairie Dev Con in Winnipeg later this month, where I'm presenting "Modernizing Applications with Agentic DevOps" — Monday, 3:30 PM, Track A3. It's a live demo, not a slide deck: modernizing a legacy application with agentic tooling in front of the room, covering containerizing, CI/CD, and re-platforming, and being upfront about the guardrails and failure patterns that come with letting an agent touch a real pipeline.

If the YYC DataCon panel was about who's accountable when agentic AI goes wrong, the Prairie Dev Con session is the practical half of that same conversation: how to actually build with these tools without pretending the failure modes don't exist. I'd rather show the guardrails breaking live than pretend the technology is further along than it is.

If you're at Prairie Dev Con, come find me after — Track A3, Monday afternoon. And if your team is somewhere in the middle of adopting agentic tooling and isn't sure who owns the security side of that decision, that's exactly the conversation a fractional CTO engagement is built to have before it becomes an incident report instead of a panel topic.

Book a Free Conversation →

Frequently Asked Questions

What panel did Kevin Evans speak on at YYC DataCon 2026?

Kevin joined Michael Moores, Brad Avery, and Dean Turner on Stage 1 (Room 210–211) on Friday, September 11, 2026, for a panel titled "Whose job is it anyway? Security responsibility in the age of AI," part of YYC DataCon's "From Insight to Impact" program at Calgary's BMO Centre.

What is Kevin speaking about at Prairie Dev Con?

At Prairie Dev Con Winnipeg (September 21–22, 2026), Kevin is presenting "Modernizing Applications with Agentic DevOps," Monday at 3:30 PM in Track A3 — a live demo of modernizing a legacy application with agentic tooling, covering containerizing, CI/CD, re-platforming, and the guardrails and failure patterns that come with letting an agent touch the pipeline.

What did Anthropic's September 2026 threat intelligence report find?

Published September 10, 2026, the report covers malicious use of Claude disrupted between December 2025 and August 2026 across seven harm categories, including a Russian espionage campaign against 20+ Ukrainian and European defense organizations and a Chinese campaign producing over a dozen possible zero-day findings in a single month. Anthropic's own framing: AI has collapsed the gap between what a lone actor and a state-sponsored team can pull off.

Why does an AI security panel matter for a small or mid-sized business, not just enterprises?

Because the report's core finding — autonomous agents doing reconnaissance, exploitation, and data exfiltration with minimal human oversight — doesn't require an enterprise budget on either side. The tools that make that possible for attackers are the same tools your team is adopting for legitimate work, which is exactly the tension the panel spent an hour on.


About Code to Cloud

We're based in Alberta and show up at events across Western Canada — and beyond — because the best technology conversations happen face to face, not just in a contact form. Disclaimer: This article provides general information only and does not constitute legal, financial, or professional advice. Every business situation is different. Consult with qualified professionals for advice specific to your circumstances. Code to Cloud is not liable for any actions taken based on this content.

Have a technology decision to make?

Book a free 30-minute strategy call — no pitch, just a straight conversation.