INVITE-ONLY EXECUTIVE ROUNDTABLE

Agentic DevSecOps in a Regulated Enterprise

From AI-generated code to regulatory accountability, are your controls keeping pace?

📅 Tuesday, 27 October 2026
⏰ 12:00 PM – 2:00 PM
📍 Melbourne (venue TBC)


AI is changing how software gets built. Development teams are already using AI agents to write code, generate tests, review pull requests and automate remediation, while regulators raise the bar on software supply chain transparency, vulnerability reporting and demonstrable governance.

The question isn't whether AI becomes part of the development lifecycle. It's how you maintain accountability, auditability and trust when software is increasingly created and managed by autonomous systems.

Held under Chatham House Rule. What's said in the room stays in the room, so the conversation can be direct.

WHY THIS MATTERS NOW

Regulators are asking questions your controls may not be able to answer

APRA and ASIC have both issued strongly worded guidance on AI use, with a specific focus on the risk introduced when AI writes code. Neither is legislation yet, both are a clear signal of where scrutiny is heading, alongside emerging obligations under the SOCI Act and comparable requirements overseas.

Expect a direct conversation with peers navigating the same shift, not a product pitch.

  • Development teams are already using AI agents to write, test and review code, often faster than governance processes have adapted to.

  • When an AI agent contributes to a change that causes an incident, accountability doesn't automatically follow, it has to be designed in.

  • Most organisations can't yet say, with evidence rather than assumption, exactly what's running in production.

  • Segregation of duties, built for human-only development, doesn't automatically hold up in an agent-driven SDLC.

  • The gap between "we have controls" and "we can prove our controls worked" is where regulatory exposure actually lives.

WHAT THIS DISCUSSION WILL COVER

Four areas the room will work through together

1. Where accountability sits
When AI agents write, review and deploy code, who's actually accountable when something goes wrong, and how that answer changes as agents take on more of the workflow.

2. Segregation of duties in an agent-driven SDLC
How a control built for human-only development teams needs to evolve when some of those "team members" are autonomous.

3. What's actually running in production
How mature your software supply chain visibility really is, and whether you could identify affected components within hours of a critical vulnerability, not days.

4. Evidence over assumption
What it actually takes to give a regulator or auditor a evidence-based answer, rather than a confident one, when they ask what's running and why it's trusted.

WHAT YOU’LL TAKE AWAY

Leave with more than notes

A clearer view of where accountability actually breaks down
How governance built for human-only development holds up, or doesn't, once AI agents are writing and reviewing code.

A sharper read on regulatory direction
What APRA and ASIC's recent guidance signals about where scrutiny is heading, ahead of it becoming formal obligation.

Perspectives from peers
How other regulated organisations are actually approaching software supply chain visibility and evidence-based governance.

A benchmark for your own maturity
How your organisation's software supply chain visibility compares with peers facing the same regulatory pressure.

A sense of what "audit-ready" actually requires
Beyond having controls on paper, what it takes to prove they worked when a regulator asks.

WHO WILL BE IN THE ROOM

A curated group of senior security and technology leaders

The value of this discussion comes from hearing how peers across energy, utilities, banking, superannuation, insurance and critical infrastructure are actually approaching this shift, not from a single point of view.

Drawn from Australia's leading regulated and digitally-led organisations, including:

Security Leadership
CISO · Principal Security Architect

Application Security & Engineering
Director of Application Security · Director of Application Engineering · Director of Security Engineering

DevSecOps & Platforms
DevSecOps Director · GM, Platforms and Engineering

Risk & Compliance
CRO · Head of Compliance

Participants are selected to ensure a high-calibre, peer-level discussion, held under Chatham House Rule.

The Programme

12:00 PM: Arrival and networking
A chance to meet the room before the discussion starts.

12:15 PM: Welcome and discussion framing
Setting the scope and ground rules for the conversation ahead.

12:20 PM: Setting the scene(speaker + title to confirm)
Industry context and customer perspective opening the discussion.

12:35 PM: Moderated discussion
The core of the session, an open, peer-led conversation across the four discussion areas.

1:50 PM: Closing reflections and key takeaways
Pulling the threads of the discussion together.

2:00 PM: Close
Attendees are welcome to stay on for informal discussion.

The conversation is accompanied by a three-course lunch at Bambini Trust, a Sydney institution since 1997, set inside the heritage-listed St James Trust Building opposite Hyde Park. Classic French-Italian fine dining, a marble bar, chandeliers, the kind of room built for a long lunch, not a corporate one.

Entrée, mains and dessert are woven through the discussion itself, giving the room a natural rhythm rather than a formal agenda.

Reserve Your Seat

Participation is limited to a select group of senior security, engineering and risk leaders to ensure a high-quality, peer-level discussion.

If you're responsible for application security, software delivery, cyber risk or regulatory compliance within a regulated or critical infrastructure organisation, this discussion will be directly relevant.

To maintain the integrity of the discussion, we ask that confirmed participants make every effort to attend, or provide advance notice should their availability change.

📅 Date: Tuesday, 27 October 2026
Time: 12:00 PM – 2:00 PM AEST
📍 Location: Melbourne (venue TBC)