Maxim Salnikov
AI Dev Tools & Platforms Solution Engineer, Microsoft
Oslo-based tech community enthusiast with more than two decades of experience as a developer. He shares his knowledge of the web platform, cloud and AI through talks and training for developer communities around the world.
In his day job as a Senior Solution Engineer at Microsoft, he supports development teams across Europe, focusing on AI-powered developer tools and platforms. He is also an active builder of developer tooling, creating and maintaining resources for AI agents that help engineers adopt AI-assisted development more effectively.
In the evenings, he organizes events for Norway’s largest web, AI and cloud communities. He is passionate about the possibilities of generative AI, with a particular focus on developer productivity. He founded and runs Prompt Engineering Conference, a key global event devoted entirely to prompting from an engineering perspective.
Thursday, July 2, 2026 · 11:00 CEST · 60 min EN
From Assistant to Actor: The New Security Risks of Coding Agents
Over the last year, AI coding assistants have evolved into agentic systems that plan, act, and make changes across the developer workflow. These agents do not just suggest code anymore. They run tools, modify configs, manage dependencies, open pull requests, and sometimes fix issues end to end with minimal human input. This shift dramatically expands the attack surface. Prompt injection now targets agents instead of chat boxes, poisoned repositories influence multi step decisions, and a single compromised instruction file can steer an agent into leaking secrets, weakening security controls, or introducing backdoors while appearing helpful and correct.
This session looks at what agentic AI means for developer security in practice. We will break down how autonomous and semi autonomous coding agents fail, where trust in automation goes too far, and why traditional secure coding guidance is no longer enough. The focus is on concrete scenarios teams are already facing and on pragmatic guardrails that keep agents useful without giving them unchecked power. The goal is to help security and engineering teams work with agentic AI in a way that scales productivity while keeping control, visibility, and accountability firmly in place.