Friday afternoon, September 11, I was on Stage 1 at YYC DataCon in Calgary's BMO Centre for a panel called "Whose job is it anyway? Security responsibility in the age of AI" — alongside Michael Moores, Brad Avery, and Dean Turner. The panel description opened with an Andrej Karpathy line that's stuck with me since: AI is "a powerful alien tool... it comes with no manual and everyone has to figure out how to hold it and operate it, while the resulting magnitude 9 earthquake is rocking the profession."
The following Monday, Anthropic put out a report that reads like the technical footnote to that exact conversation.
The Panel: Nobody Fully Owns This Yet
The honest answer we kept circling back to onstage is that "whose job is it" doesn't have a clean owner yet. Security teams are being asked to secure tools they didn't choose and don't fully understand. Developers are shipping agentic workflows faster than governance can review them. Leadership is signing off on AI adoption without always knowing what "adoption" is actually touching under the hood. Everyone has a piece of the responsibility, and pieces are exactly how things fall through the cracks.
That's not a Calgary-specific problem — it's the same gap I wrote about recently on shadow AI inside small businesses: the tools work, adoption is real and accelerating, and the accountability question is almost always the thing nobody assigned on purpose.
Then Anthropic Published the Data Behind the Question
Anthropic's September 2026 threat intelligence report, published September 10 — one day before our panel — covers malicious use of Claude that its own Threat Intelligence team disrupted between December 2025 and August 2026, across seven harm categories:
20+
Ukrainian/European orgs targeted (GTG-20006)
1.8M
Android APKs harvested for credentials
~50
Orgs hit in a single zero-day campaign
9
Influence-op cases, 4 countries, 6 continents
A few specifics stood out to me as directly on-topic for the panel:
- GTG-20006, a Russian espionage operation, targeted more than 20 Ukrainian and European government and defense organizations, stealing drone technology data and credential records tied to over 300,000 national identity records.
- GTG-10007, attributed to Chinese state-linked actors, targeted roughly 50 organizations globally and produced "more than a dozen possible zero day findings in a single month" — a pace of vulnerability research that would have needed a much larger team two years ago.
- Nine separate influence-operation cases spanning Russia, Iran, Turkey, and Gulf states targeted six continents, including election-related campaigns in Malaysia and Moldova.
Anthropic's own framing is the line that ties straight back to Friday's panel: AI has "collapsed the labor and tooling gap" that used to separate a nation-state team from a single operator. The report documents autonomous agents doing reconnaissance, exploitation, and data exfiltration with minimal human oversight — on the attack side. Their recommended response for organizations is just as relevant on the defense side: treat AI API keys with the same seriousness as production credentials, buy AI access only through authorized channels, and manage and rotate keys rigorously.
The Uncomfortable Symmetry
The same agentic capability that makes a legacy-app modernization demo possible in an hour on a conference stage is the capability a threat actor used to run zero-day research at a pace that used to require a whole team. It's the same tool. That's exactly why "whose job is this" doesn't have an easy answer.
What's Next: Prairie Dev Con, September 21–22
I'm carrying this thread to Prairie Dev Con in Winnipeg later this month, where I'm presenting "Modernizing Applications with Agentic DevOps" — Monday, 3:30 PM, Track A3. It's a live demo, not a slide deck: modernizing a legacy application with agentic tooling in front of the room, covering containerizing, CI/CD, and re-platforming, and being upfront about the guardrails and failure patterns that come with letting an agent touch a real pipeline.
If the YYC DataCon panel was about who's accountable when agentic AI goes wrong, the Prairie Dev Con session is the practical half of that same conversation: how to actually build with these tools without pretending the failure modes don't exist. I'd rather show the guardrails breaking live than pretend the technology is further along than it is.
If you're at Prairie Dev Con, come find me after — Track A3, Monday afternoon. And if your team is somewhere in the middle of adopting agentic tooling and isn't sure who owns the security side of that decision, that's exactly the conversation a fractional CTO engagement is built to have before it becomes an incident report instead of a panel topic.
Frequently Asked Questions
What panel did Kevin Evans speak on at YYC DataCon 2026?
Kevin joined Michael Moores, Brad Avery, and Dean Turner on Stage 1 (Room 210–211) on Friday, September 11, 2026, for a panel titled "Whose job is it anyway? Security responsibility in the age of AI," part of YYC DataCon's "From Insight to Impact" program at Calgary's BMO Centre.
What is Kevin speaking about at Prairie Dev Con?
At Prairie Dev Con Winnipeg (September 21–22, 2026), Kevin is presenting "Modernizing Applications with Agentic DevOps," Monday at 3:30 PM in Track A3 — a live demo of modernizing a legacy application with agentic tooling, covering containerizing, CI/CD, re-platforming, and the guardrails and failure patterns that come with letting an agent touch the pipeline.
What did Anthropic's September 2026 threat intelligence report find?
Published September 10, 2026, the report covers malicious use of Claude disrupted between December 2025 and August 2026 across seven harm categories, including a Russian espionage campaign against 20+ Ukrainian and European defense organizations and a Chinese campaign producing over a dozen possible zero-day findings in a single month. Anthropic's own framing: AI has collapsed the gap between what a lone actor and a state-sponsored team can pull off.
Why does an AI security panel matter for a small or mid-sized business, not just enterprises?
Because the report's core finding — autonomous agents doing reconnaissance, exploitation, and data exfiltration with minimal human oversight — doesn't require an enterprise budget on either side. The tools that make that possible for attackers are the same tools your team is adopting for legitimate work, which is exactly the tension the panel spent an hour on.
About Code to Cloud
We're based in Alberta and show up at events across Western Canada — and beyond — because the best technology conversations happen face to face, not just in a contact form. Disclaimer: This article provides general information only and does not constitute legal, financial, or professional advice. Every business situation is different. Consult with qualified professionals for advice specific to your circumstances. Code to Cloud is not liable for any actions taken based on this content.



