Melbourne · 5 May 2027 · Melbourne Convention and Exhibition Centre

Agenda & Speakers

The programme

Australia's biggest dedicated AI security and data protection agenda.

Short, sharp and interactive: keynotes and case studies from practitioners, live panels you vote in, peer roundtables on the problems you name, and two hours of structured networking by design.

AI + Data Security World Melbourne
Past speakers

Who has taken our Melbourne stage.

Speakers from the most recent Melbourne edition. The 2027 line-up is announced on a rolling basis — sign up for updates to hear it first.

Andrew Morgan
Andrew Morgan
GM Cyber Security & Enterprise Services Information & Technology
Bogdan Jovicic
Bogdan Jovicic
Head of Data, Analytics and AI Transformation APAC
Craig Pitts
Craig Pitts
Head of Information Security
Dr. Huon Curtis
Dr. Huon Curtis
Head of External Affairs
Henrique Delamanha Mendonca
Henrique Delamanha Mendonca
Associate Director Information Governance and Data Protection
Kate Carruthers
Kate Carruthers
Lecturer
Katherine Boyles
Katherine Boyles
Senior Associate - Intellectual Property and Technology
Melroy Vanlangenberg
Melroy Vanlangenberg
Head of Data Governance
Muhammed Esgin
Muhammed Esgin
Senior Lecturer and Cryptography Expert
Muzamil Rashid
Muzamil Rashid
Head of Cybersecurity
Sara Abak
Sara Abak
Industry Cyber Expert and CISO
Vasant Prabhu
Vasant Prabhu
Global Data Protection Lead (AI, Privacy & Cybersecurity Architecture)
Venkata Valluri
Venkata Valluri
General Manager Data and Analytics
Wayne Clarke
Wayne Clarke
Deputy General Counsel – Privacy, Data, AI & Cyber
Agenda

Wednesday 5 May 2027.

All times AEST. Sessions are announced and updated on a rolling basis.

08:30

Registration Opens & Networking Breakfast

Networking
Plenary
+

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

09:15

Welcome & Opening Remarks

Plenary
+
09:20

Keynote: Building Secure, Trustworthy, and Resilient AI Systems

Keynote
AI Security & Governance
+

Generative and agentic AI have moved from experimentation to production faster than most security and governance functions can keep pace with, and the organisations getting this right are treating security and trust as design requirements, not afterthoughts bolted on post-launch. This opening keynote frames the day: what "trustworthy AI" actually requires in practice, and the shape of the threats and expectations now converging on organisations running AI at scale.

  • Why AI trust and resilience are now board-level priorities, not just a technical concern
  • The forces reshaping AI risk right now: attackers, regulators, shadow adoption, and agentic autonomy
  • What secure-by-design actually looks like for production AI systems
09:20

Opening Keynote: The Trust Deficit: Why Data Protection Needs to Become a Growth Strategy

Keynote
Data Protection & Security
+

As AI reshapes how organisations collect, process, and act on data, the old framing of data protection as a defensive cost centre is running out of road — this keynote sets the tone for the day by reframing trust, security, and privacy as the foundation for whether AI-driven transformation succeeds or stalls.

  • With customers, regulators, and employees increasingly wary of how their data fuels AI systems, the organisations that treat transparency and control as differentiators (not just compliance obligations) are the ones building durable advantage.
  • Why the mindset shift from "responding to breaches" to "architecting for inevitability" is what separates organisations that recover quickly from those that suffer lasting reputational and regulatory damage.
  • Framing the questions every session will return to: Who's accountable when AI systems handle sensitive data? What does "good enough" security look like when threats and technology are both moving this fast? And how do leaders balance urgency with judgement?
09:40

Keynote: AI Governance and Changing Regulatory Expectations

Keynote
AI Security & Governance
+

Regulators are sharpening supervisory expectations around AI faster than most governance frameworks can be rewritten, leaving organisations navigating real compliance obligations without a single, settled rulebook. This keynote cuts through it: what's actually being asked of organisations right now, where enforcement is heading, and how to build governance that won't need rebuilding every time expectations shift.

  • What regulators are actually asking of organisations deploying AI today
  • How voluntary and emerging standards are likely to harden into firm expectation
  • Designing an AI governance framework that flexes as the regulatory picture evolves
09:40

Keynote: Redesigning Access Controls for an AI-Augmented Workforce

Keynote
Data Protection & Security
+

As AI copilots, agents, and analytics tools require broader, faster access to enterprise data to deliver value, organisations face a widening tension between empowering AI-augmented employees and maintaining the access discipline that data protection has always depended on.

  • How AI agents and copilots blur the traditional boundary between "user" and "system," and why identity and access management frameworks built for people don't cleanly extend to autonomous tools.
  • Moving away from broad, standing permissions toward dynamic, context-aware access that grants AI tools and employees only what's needed for the task at hand.
  • Giving finance and business leaders a practical framework for weighing productivity gains from broader data access against quantifiable increases in breach exposure and regulatory risk.
10:10

Panel Discussion: How Cybercriminals Are Using AI to Accelerate Attacks

Panel
AI Security & Governance
+

Threat actors have moved from experimenting with AI to industrialising it, using it to scale phishing, write malware, and compress attack timelines from weeks to hours. This panel brings together practitioners tracking this shift to unpack what's actually changed in attacker tradecraft, and what defenders need to do differently as a result.

  • How AI has compressed attacker dwell time and reconnaissance-to-breach timelines
  • Real examples of AI-generated malware, phishing, and social engineering at scale
  • Where defensive AI can realistically keep pace with offensive AI, and where it can't
10:10

Panel: Navigating Privacy Reform, Cross-Border Data Rules, and AI-Specific Regulation Simultaneously

Panel
Data Protection & Security
+

Privacy and security leaders are no longer managing one regulatory relationship; they're navigating overlapping and sometimes conflicting obligations across privacy law reform, sector-specific rules, and emerging AI governance requirements, often with limited resourcing to do it all well.

  • Practical approaches to building compliance programs flexible enough to absorb reform without constant rebuilds.
  • How organisations operating across APAC are managing divergent data residency and transfer requirements without duplicating infrastructure for every jurisdiction.
  • Shifting compliance from a post-hoc legal review into an input that shapes how AI and data systems are architected from day one.
10:40

How I Solved… Securing AI Models in Production

Case study
AI Security & Governance
+

Most AI security failures don't happen in the lab; they happen when a model moves into production and inherits real users, real data, and real attack surface. This case study follows a team that built security controls around a live production AI system, covering model access controls, output validation, monitoring, and incident response, all retrofitted without stalling the business case for AI.

  • What broke first when the model went from pilot to production scale
  • Building access control, logging, and monitoring around a live model without slowing deployment
  • The incident response playbook they wish they'd had on day one
10:40

How I Solved… Shutting Down Shadow AI Without Shutting Down Innovation

Case study
Data Protection & Security
+

With employees adopting AI tools faster than IT could track or approve them, one security leader built a discovery and governance approach that brought unauthorised AI usage into the light — without triggering a workforce backlash or slowing legitimate innovation.

  • How the team mapped unsanctioned AI tool usage across the organisation before deciding on any policy response, since you can't govern what you can't see.
  • Designing an approval pathway fast enough that employees chose to use it rather than route around it, turning shadow AI into managed AI.
  • Building lightweight, continuous visibility into new AI tools.
10:55

Morning Tea & Networking

Break
Plenary
+
11:25

Audience Activity

Workshop
AI Security & Governance
+

A hands-on, interactive session working through a real AI security and governance scenario as a room. Details announced soon.

11:25

Audience Activity

Workshop
Data Protection & Security
+

A hands-on, interactive session working through a real data protection and security scenario as a room. Details announced soon.

11:40

How I Solved… Managing Shadow AI and AI Supply Chain Risk

Case study
AI Security & Governance
+

Employees adopted generative AI tools faster than any policy could keep up, and most security teams are now flying blind on where sensitive data is actually going, both through unsanctioned tools and third-party AI dependencies buried in the supply chain. This case study details how one organisation moved from having no visibility to a working discovery, risk-tiering, and sanctioned-alternative program.

  • How they discovered the true scale of unsanctioned AI and third-party AI dependency use
  • Risk-tiering AI tools and vendors instead of a blanket ban that drives usage further underground
  • Building a sanctioned pathway that made compliance the path of least resistance
11:40

How I Solved… Securing Legacy Systems That Can't Be Replaced Overnight

Case study
Data Protection & Security
+

With critical infrastructure and legacy platforms too costly or risky to replace outright, one security leader built a layered protection strategy that meaningfully reduced risk exposure without waiting for a full modernisation program.

  • Triaging legacy system vulnerabilities realistically, rather than pursuing an unachievable "patch everything" strategy.
  • How network segmentation, enhanced monitoring, and strict access controls around legacy systems provided durable risk reduction, not just a stopgap.
  • Building the business case for ongoing investment in legacy security, when the instinct is often to deprioritise spending on systems slated for eventual retirement.
11:55

How I Solved… Prompt Injection and AI Agent Security

Case study
AI Security & Governance
+

Prompt injection remains the leading cause of agentic AI security failures in production, and as agents gain the ability to act, not just respond, the blast radius of a successful injection grows sharply. This case study walks through a real prompt injection incident against an agentic system, what it exposed about the architecture, and the guardrails built afterward.

  • Anatomy of a real prompt injection attack against a production AI agent
  • Why prompt injection is proving structurally difficult to fully patch, not just fix once
  • The guardrails, sandboxing, and human-in-the-loop checkpoints added after the incident
11:55

How I Solved… Data Classification That Sticks

Case study
Data Protection & Security
+

After years of data classification policies that existed on paper but were ignored in practice, one data protection leader built a classification approach employees actually followed, turning a compliance exercise into a functioning control.

  • Recognising that asking employees to correctly label sensitive data by hand was never going to scale, and redesigning around automated detection instead.
  • How classification was built into the tools people already used daily, rather than requiring a separate step that competed with getting work done.
  • How accurate classification became the foundation for access controls, DLP policies, and AI governance decisions downstream.
12:10

Panel: Protecting Against Model Attacks, Data Poisoning, and Deepfakes

Panel
AI Security & Governance
+

Beyond prompt injection, AI systems face threats aimed at the model and the data itself, adversarial inputs designed to fool classifiers, poisoned training data, and deepfakes now sophisticated enough to bypass biometric and verification controls. This panel examines the technical attack surface of AI systems and the defences that are actually holding up.

  • How adversarial attacks and data poisoning differ from application-layer AI risks like prompt injection
  • What's actually detecting deepfakes and synthetic media in production today, and what isn't
  • Practical model-hardening steps that don't require a dedicated research team
12:10

Panel: Legal Liability and Trust in an AI-Driven Data Landscape

Panel
Data Protection & Security
+

As AI systems make decisions with real legal and financial consequences, organisations are discovering that liability frameworks built for human decision-making don't map cleanly onto AI-driven processes; leaving legal, privacy, and security leaders to navigate accountability, contracts, and customer trust largely without settled precedent.

  • When an AI system's decision leads to a data breach, discriminatory outcome, or regulatory breach, how are legal teams currently allocating fault between the organisation, the AI vendor, and the underlying model provider; and where does existing law simply not have an answer yet?
  • How eroded customer trust following an AI-related incident is increasingly translating into legal action and what that means for how legal and privacy teams collaborate on incident response.
  • Exploring the tension between regulatory and legal expectations for transparency and explainability, and the practical reality that many AI systems can't yet provide a clear, defensible account of how a specific decision was made.
12:40

Peer Roundtables

Workshop
AI Security & Governance
+

Small-group, discussion-based sessions where you'll work through real AI security and governance challenges with peers in similar roles. Roundtable topics will be announced soon.

12:40

Peer Roundtables

Workshop
Data Protection & Security
+

Small-group, discussion-based sessions where you'll work through real data protection and security challenges with peers in similar roles. Roundtable topics will be announced soon.

13:30

Lunch & Networking

Break
Plenary
+
14:20

QuickFire Quiz: Test Your Knowledge Against Your Peers

Networking
Plenary
+

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.

14:35

How I Solved... Managing Identity and Access for AI Agents

Case study
AI Security & Governance
+

AI agents now hold credentials, call APIs, and access systems on behalf of users, often with far broader permissions than anyone intended, and little visibility into what they're actually touching. This case study covers how one organisation brought AI agent identities under proper access governance, closing shadow access gaps before they became breach headlines.

  • Discovering the true scope of access AI agents had quietly accumulated
  • Applying least-privilege and identity governance principles to non-human, autonomous actors
  • Building ongoing visibility so new agents don't recreate the same shadow access problem
14:35

How I Solved… Cutting Breach Detection Time from Weeks to Hours

Case study
Data Protection & Security
+

Facing a security team stretched thin and alert fatigue eroding response quality, one CISO restructured detection and triage around automation and prioritisation; dramatically compressing the time between compromise and containment.

  • How the team re-engineered alert prioritisation so analysts spent time on genuine threats instead of drowning in low-value notifications.
  • Where automated containment actions (isolating endpoints, revoking access) were safely delegated to systems versus kept as human decisions.
  • How the leader secured budget and buy-in for detection tooling improvements proactively, before an incident forced the issue.
14:50

Keynote: Board Accountability and AI Risk Reporting

Keynote
AI Security & Governance
+

Boards are being asked to oversee AI risk without always having the technical grounding to interrogate it properly, and regulators are starting to expect documented accountability, not just good intentions. This closing keynote translates AI security and governance risk into the language and cadence boards actually need.

  • What a genuinely useful AI risk report looks like at board level
  • Where accountability for AI risk should sit, and why "everyone" usually means no one
  • Building board AI literacy without turning every meeting into a technical briefing
14:50

Keynote: Breach-Ready by Design: Rethinking Incident Response in the Age of AI-Speed Attacks

Keynote
Data Protection & Security
+

As AI accelerates both attack sophistication and organisational response capabilities, traditional incident response playbooks are becoming dangerously outdated, forcing security leaders to rebuild readiness around machine-speed detection and response.

  • How AI-powered attacks (automated phishing, deepfake-enabled social engineering, AI-assisted lateral movement) have shrunk the window between initial compromise and material damage, and what that means for detection SLAs.
  • Where automated triage and containment genuinely reduce risk versus where removing human judgement from the incident response chain creates new liability.
  • How faster, more complex breaches are colliding with notification obligations under the Australian Privacy Act, and what "reasonable steps" now looks like when regulators expect speed AI hasn't universally delivered yet.
15:10

Think Tank: Where Is Your AI Risk Actually Coming From?

Panel
AI Security & Governance
+

This interactive session puts the day's themes directly to the room with live voting, surfacing where the audience is genuinely exposed versus where the conversation has been focused, then debating the gaps in real time.

  • What's your organisation's single biggest AI security blind spot right now: shadow AI, agentic access, model-layer attacks, or third-party AI tools?
  • Who currently owns AI risk accountability in your organisation: security, risk and compliance, a dedicated AI governance function, or no one clearly?
  • Has your organisation experienced a prompt injection or agentic AI security incident, even a near-miss?
  • Is your board asking the right questions about AI risk: too little, about right, or overcorrecting into technical detail they can't act on?
  • Where will you spend your next AI security dollar: production model security, shadow AI discovery, agent identity governance, or model/deepfake defence?
15:10

Think Tank: Third-Party and Supply Chain Risk: Securing Data You Don't Fully Control

Panel
Data Protection & Security
+

As enterprises rely on growing networks of AI vendors, SaaS platforms, and outsourced service providers, sensitive data increasingly flows through systems organisations neither built nor fully control; turning vendor risk management into one of the hardest unsolved problems in data protection.

  • Why static vendor assessments fail to capture real-time risk, and what continuous monitoring of third-party access actually looks like in practice.
  • The unique challenges of assessing AI and model providers, where questions about training data use, data retention, and model behaviour go beyond traditional security due diligence.
  • Lessons from real incidents on managing incident response, regulatory notification, and reputational fallout when the failure originated outside your own walls.
15:40

Closing Remarks & Prize Draw

Plenary
+
15:45

Networking Drinks Hour

Networking
Plenary
+

Unwind with your peers for a couple of drinks on us!

16:45

Event Closed

Plenary
+
Wednesday 5 May 2027 · Melbourne Convention and Exhibition Centre

Don't miss Australia's biggest AI security and data protection event.