Companion links for the talk Securing AI Agents on Kubernetes: Identity, Sandboxes, and MCP Tool Governance Code Europe 2026, Warsaw · Dr. Roland Huß, Red Hat
The one-sentence version: put the controls in the environment, not in the prompt, and start at the bottom, because everything above the sandbox is advisory if the sandbox leaks.