No Logs, No Corpus: Why AI Incidents Go Unsolved
Wednesday, September 16, 2026, 2:00 PM - 2:45 PM
Amphitheatre

Corpus delicti — no body, no crime. Every IR professional knows the principle. But when you're called to investigate an incident involving an internally developed AI application, you may have the body and still have no case. Not because the evidence was destroyed. Because it was never created.


This session is not about prompt injection demos or jailbreaking commercial AI products. It is about the realistic AI application your internal development team shipped because leadership said "leverage AI" — built quickly, built with good intentions, and built without a single line of intentional logging.


OWASP LLM risks don't go undetected because attackers are clever. They go undetected because developers don't know what to instrument and IR teams don't know what to ask for before the incident. We'll use a real Vertex AI application to show exactly where the logging gaps live — and map them to who owns them: the vendor, the developer, or nobody.
Attendees leave with a clear framework for where logging is the vendor's responsibility, where it is shared, and where it falls entirely on the developer — and what to demand from your dev teams before the next call comes in.