← All speakers

Bio, Work & Ideas

Michael Patterson

Conference affiliation: Coder

On this page

Michael Patterson focuses on enterprise coding-agent security: how organizations can adopt autonomous development tools while controlling their access to private data and outside services. At the AI Engineer World’s Fair in 2026, he was a staff solutions engineer at Coder.

The risk on developer laptops

Patterson applies Simon Willison’s lethal trifecta to coding agents: access to private data, exposure to untrusted content, and the ability to communicate externally. Agents such as Claude Code, Codex, and OpenClaw running on developer laptops can combine all three. Prompt injection connects these capabilities into a threat: malicious instructions encountered in content can redirect an agent that also has access to internal information and the internet.

His approach to securing coding agents puts controls around where they run, what information reaches the model provider, and which actions they can take:

  • Cloud development environments: Isolate the agent’s execution from the developer’s laptop.
  • Model proxy: Log model traffic and strip sensitive information before it reaches the LLM provider.
  • Agent firewall: Deny commands and network destinations that the organization has not allowed.

These controls address different parts of the problem: execution isolation, visibility and filtering of model traffic, and restrictions on agent actions.

Moving from individual use to enterprise adoption

Patterson also examines the organizational obstacles to rolling out agents at scale. Personal AI subscriptions can put usage outside company oversight; alert fatigue can overwhelm security teams; and skeptical senior engineers can resist new workflows. His emphasis is on making agent adoption manageable for both developers and security leaders, with architectural guardrails that address the risks already present in everyday laptop use.

Read the topics behind these talks

1 conference talk

Key ideas

Scroll to read ↓

Michael Patterson explains how private data, untrusted content and internet access combine inside coding agents—and how remote environments, model proxies and command controls can limit what a compromised agent can do.

  • The lethal trifecta connects private-data access, untrusted content and external communication. Prompt injection becomes consequential when malicious guidance can direct tools with real permissions.
    5:06 ↗
  • A prepared remote environment limits which resources the agent can reach and reduces dependency-installation decisions before development begins.
    15:35 ↗
  • Model proxies govern requests to providers; agent firewalls govern execution. Logging supports oversight, while prevention requires controls that act before data leaves or a command runs.
    18:05 ↗
  • An enterprise rollout needs approved workflows, repeatable environments and useful alerts. Blocking adoption without addressing demand can push agent use onto personal subscriptions outside organizational visibility.
    10:35 ↗
  • Take time to understand the infrastructure and make agent activity visible before scaling its access and autonomy.
    19:35 ↗

References