Full transcript
0:08Hi everyone, thanks for coming today. So
0:10my name is Juan and yes, so today we're
0:12going to be talking about secure human
0:15in the loop interactions for AI agents.
0:18So we'll explore what that is. Uh we'll
0:21also explore why it is important and
0:23we'll cover a little bit of how you can
0:25implement it, but we're going to keep it
0:27to the basics.
0:29Um before we start with the
0:31presentation, you can also check me out
0:32on social medias with VHC Martinez or
0:36you can scan that QR code that will take
0:37you to my website and yeah, we can
0:40connect and continue the discussion
0:41about secure security in the space and
0:44other cool things uh online. But let's
0:49let's get started. Uh but before we
0:51start exploring the topic of AI agents,
0:53I think it's important to start from the
0:55beginnings, right? So to what where
0:57everything started and what we are all
0:59familiar with which is simple chat bots
1:02right in a way we all have sometimes
1:05played a little bit with chatp we
1:07probably all have that experience with
1:09cloud or with any other of the popular
1:11providers now and it basically goes
1:13something like this where you say hi to
1:16a chatbot and then he replies hey there
1:19right and now we take that as granted
1:21but if you ask someone 10 years ago this
1:23was kind of like magical right like you
1:25can be able to talk to a computer and it
1:26replies and it sounds kind of like a
1:28human being. I mean that is fantastic.
1:30And yeah, so this is where this is where
1:32we started. And if it if you think a
1:35little bit about how a chatbot works in
1:38this very sophisticated diagram that I
1:40created, uh you can see that we have
1:42this very fancy gentleman here that
1:44sends a message to the AI and the AI
1:47sends back a response, right? Pretty
1:49straightforward, very simple. There's no
1:52state management. The AI has no
1:54knowledge of what happened in the past.
1:56Every time that we want to carry a
1:58conversation with the chatbot, we need
2:00to send them the whole message list,
2:03right? So that it can re-evaluate all
2:05the messages and all the conversations
2:07that we had before so that it can reply
2:09with some context. So they are a
2:11stateless uh stateless entities and they
2:15are cool but a little bit boring. We use
2:17them all the time. We confess our
2:20darkest secrets to the AI and and we are
2:22cool with that but sometimes we want a
2:25little bit more
2:27um because
2:29stateless for chat was just simply not
2:32cool. It cannot do too many things
2:34because every time we want to do
2:36something with them we need to remind
2:37them what we were talking about and it's
2:39kind of tedious and they forget and so
2:41we want some kind of states and that's
2:43when AI agents come into piece. AI
2:46agents bring state into the AI world and
2:50so they are stateful. They can remember
2:52goals. They can remember steps where
2:54they are in the part of the thinking
2:56process and uh they can do partial
3:00results, stop the execution and come
3:03back later. So they are much more
3:04interesting. They are really really
3:06really cool to play with. And if you
3:09have ever used something like a cursor
3:12or windsur to do this vibe coding thing
3:15everybody likes to do now. I was playing
3:16an ad and a dance but I was told not to
3:18move from the podium so you'll miss on
3:19that. Sorry. Uh but yeah so agents are a
3:23little bit more like humans but they are
3:25also way harder to control. Kind of like
3:28humans in a way. Um otherwise ask one of
3:31my kids. Right.
3:34All right. So I made another very
3:36sophisticated uh here diagram of how an
3:39AI agent works. And we can see that
3:41there are a little bit more moving parts
3:43for an AI agent. First we got rid of the
3:45human, right? Because that's the that's
3:48the end goal, right? That we don't we
3:50are not helpful anymore in this world.
3:52AI will take over. But we still have
3:54some kind of input in this picture,
3:56right? But the input doesn't necessarily
3:58needs to be a human. It can be another
4:00system. It can be another agent. And
4:02this is an important distinction that we
4:04need to make. So we have some input
4:06that's going to go into the AI agent and
4:08the AI agent goes some kind of planning
4:10phase. This is where it's thinking right
4:12that now we like to call it thinking or
4:14reasoning or or planning creating that
4:16plan for execution. And then he has some
4:18tools as it disposal right. So it can
4:21interact with tools and we can use these
4:23tools to gather context from other
4:26applications from third parties from
4:28things that are stored in your computer.
4:30Right? So tools is what makes AI agents
4:32a lot more interesting because now it's
4:35not just interacting with a model that
4:37knows nothing about us that knows
4:38nothing about our environment. Now we
4:40can start getting all this environment
4:43uh context and now we can also start
4:45introducing change because so far we
4:47were able to talk to it but we weren't
4:49able to do anything with it but now
4:51tools allow us to call thirdparty APIs
4:53allow us to call us the file system
4:56allow us to modify files.
4:58it gets a lot more interesting and
5:00finally it produces an output and AI
5:04agents are like fascinating right so
5:06they are they are really really good and
5:09let's explore an example of what you can
5:12do potentially with an AI agent like we
5:15want we saw before again we have this uh
5:19kind of like chatbot AI agent now where
5:21we say hey AI I want to go to the beach
5:23to relax to relax and enjoy the water
5:26right very simple prompt
5:28And the AI responds, "Sure, I'll book
5:30you a trip." And then the AI goes into
5:33the background wall where it's
5:34processing all the data and churning and
5:38coming up with an ideal uh trip for us
5:41with an ideal destination looking for
5:43the best prices because he has access to
5:44everything that is to know about in the
5:47internet. It has all the tools that he
5:48needs at his disposal and
5:52eventually will come back to us with a
5:56proposal or perhaps it even does the
5:58booking for us. And while we are packing
6:01all our uh summer closes and we are
6:04getting ready with our sand toys and we
6:07go on a we pack on a plane and we go to
6:09the destination the AI selected for us
6:11and oh I mean that's a really cool
6:15looking dude. Certainly that's something
6:17I will wear to the beach. But he is not
6:19happy because
6:21what what what went wrong with our
6:23plans, right? Everything was going well.
6:26They executed, he booked everything for
6:28us and he's not happy. He's not happy
6:30even though he got everything he
6:32prompted for. He has there his very
6:34German looking uh sandals. He has his
6:37Santos. He has the water he wanted to.
6:40Maybe a little bit too much, right? But
6:43yes, we can feel that something even
6:45though technically correct is not what
6:48we were hoping for when we designed that
6:51prompt. Right?
6:53So we were not very smart when we tell
6:55the what to do. But the AI also wasn't
6:57very smart in confirming
7:00anything that we wanted to do or even
7:02confirming before we did any booking or
7:04any sorts. Right? So we delegated to uh
7:07the AI. the AI acted uh autonomously
7:10but without the right context without
7:12any oversight at all and it produced
7:15terrible results right and that's kind
7:17of like a funny scenario where we just
7:19went to the beach but imagine in a world
7:21where AI controls a lot more important
7:24things like where it has access to your
7:25banking account where it makes uh
7:27purchasing decisions for you where it
7:29influates uh where influences the stock
7:33market or things where stakes are high
7:36like in medicine or things like that
7:37where they are making decisions for us.
7:40We don't really want an AI to make
7:41decisions for us, right? Uh or hopefully
7:44not because we'll see kind of like what
7:46will happen. What we want is we want AI
7:49to augment our abilities but not to
7:52replace our judgment, right? So we as
7:55humans, we have a lot of history, we
7:57have a lot of understanding of how the
7:59world works. We know what we want. We
8:01are the ultimate decision makers and we
8:03don't want to delegate that to any AI
8:05system. We want to be the ones that have
8:08the final saying. And I think that's a
8:11pretty good pretty good remark that I
8:14came up totally on my own and I felt
8:15like I had my own I am Iron Man moment.
8:18So yeah, it's cool.
8:23All right. Um, so with great powers come
8:26great responsibility. I couldn't create
8:28all the lines in this slide. Sorry, I
8:30had to steal a few. But we have Spidey
8:32there to keep us in check. So human
8:35oversight is the key to wieldings the
8:38AI's immense powers and responsibilities
8:41and that's what we want to enter into
8:44this AI world. Right? So let's go back a
8:48little bit to our AI agent where we
8:52started with this picture where we have
8:54our input where we have our planning
8:58where we have the tools for execution
9:01and output. What do you think is missing
9:04here in this picture?
9:06Well, what we remove in the first time,
9:08right, we remove the humans and the
9:10humans as are what makes things matter.
9:14So, we need to bring the humans back in
9:16the picture. So, we could put the humans
9:18in the output for example and that's
9:22kind of like what we got. Not an ideal
9:25scenario. Uh we could put the humans in
9:27the planning, but then again, why do we
9:29need an AI then, right? if the humans
9:31are ruining the whole thing. So we want
9:34to keep the humans in the input and we
9:36want to keep the humans somewhere
9:39between the planning and the output
9:43and so we can add the human there for
9:45example. So there we have a very
9:47reasonable human being. Now when we have
9:50the input and the input can be coming
9:51from the same human right the input can
9:53be I still want to go on holidays to the
9:57beach and I want to see water right and
10:00and now goes through the AI goes through
10:02the planning phase and it starts
10:03thinking about all the different
10:04possibilities it comes up with a few
10:06suggestions right so these are the
10:08options that you have places where you
10:10can go on these times of the year and
10:13then the human can take a look into that
10:14and say like okay November in Ireland
10:17maybe not a great idea uh um August in
10:20Germany. Yeah, maybe that could work
10:22out, right? Um so the the human can use
10:25the experience and the knowledge that it
10:26has or it can Google it. Uh hopefully it
10:29doesn't ask the same AI for exactly the
10:31same input, but it has the opportunity
10:33now to double check the work of the
10:35agent before it goes and executes before
10:38it goes and does the tool calling uh to
10:41book the trip or or to continue with
10:43anything that it needs to be done to
10:45produce the output.
10:48And and this is very important
10:50especially at this stage of AI because
10:52the the way AI is working today is not
10:55the AI that we all think it is right
10:57it's not still general artificial
10:59intelligence it is pretty good and it is
11:01getting better but it's still producing
11:03mediocre results when the inputs are not
11:05correct or in situations that the AI u
11:08doesn't know uh we still have a lot of
11:11hallucilations hopefully doesn't even
11:12send us to a trip to a place it doesn't
11:14exist right so at least maybe can
11:16validate that but there still a lot of
11:18risks and until we have AGI and we just
11:21can relax and watch TV all day because
11:24there's nothing less for us to do. We
11:26need the humans in this equation and we
11:27need the humans in the picture because
11:29we are the drivers. We are in the seat
11:34and
11:36and this is what we call human in the
11:38loop, right? So now the the the human is
11:41not anymore the main protagonist.
11:44He is not the one that uh creates the
11:46story and and plans and does everything.
11:48Now he's just someone in the loop,
11:50someone who's been notified kind of like
11:52a manager for the AI, right? Can I take
11:55holidays? Yes. No. No, you can. And and
11:57we call that human in the loop in the
11:59industry. And this is where the human
12:01has oversight at decision decision
12:04points. And here are some examples,
12:06right? So there are different types of
12:09human oversightes. There's review before
12:11action kind of like what we did before
12:13where we need to approve to book a trip
12:16or not. And that's very basic. It's kind
12:18of like a boolean thing, right? So it's
12:20continue or pause whatever it is that
12:23you're doing AI. We can also collect
12:25human input like for example in the case
12:27before if the AI would have told us hey
12:30what do you mean by you want a lot of
12:31water? Do you want it to be rainy or you
12:33just want to swim in the water? Right?
12:34like if you would have asked us a few
12:36more questions we we could have provided
12:38uh answers and that would have produced
12:40better results. Um so that's the second
12:43type of uh interventions and then the
12:46third one is to manually edit the agent
12:48state and and and this one is a little
12:52bit lesser known but remember when you
12:54are working with these agents at the at
12:57the part of planning and tool calling in
12:59each one of these steps
13:01state was saved like for example where
13:03was planning to go the the possible
13:06destination that maybe there was a
13:07variable with the price maybe there was
13:09a variable with the airline like there
13:11were all these different var variables
13:12and now the human can go in there and
13:14correct on the state so that when it
13:17continues the workflow execution it
13:19continue with the right uh set of data
13:23and and and I mean this this is this
13:25will be something fantastic but this is
13:26not really a novel idea uh can anyone
13:29think of any scenarios where we already
13:32have this kind of like in production and
13:33we don't even think about it so one for
13:37me or one of the first ones that came to
13:39my mind was when I'm driving so when I'm
13:41driving. Now, newer model cars will try
13:44to correct you to stay in the lanes. Uh
13:46sometimes they will start breaking in
13:48advance when they see a car coming um
13:51very close or things like that. But the
13:54car stops all autonomous functions the
13:57moment you press on the pedal or the
13:59brake or the moment you steer to adjust,
14:02right? Uh so my car always tries to
14:04correct me to stay in the lane, but most
14:07sometimes it's not correct. So I steer a
14:09little bit back. It fights me for a
14:11second and then it gives up, right? It
14:12automatically says, "No, the human the
14:14human has to be right because he's the
14:16one in control and let us continue." And
14:19this is exactly what we want when we
14:21talk about AI. We want to be the
14:23drivers. We we want to be the ultimate
14:26decision makers. We don't want to be uh
14:29just the ones that consume the output if
14:32it hasn't been checked because it's it's
14:35it's our lives. It's our stake. uh what
14:38is uh what is at stake here.
14:43So let's understand a little bit what
14:46how human in the loop workflows work.
14:50So, so when you have an AI agent, it
14:52goes through this planning phase, right?
14:55So, it executes maybe perhaps in
14:57multiple steps. Perhaps it thinks for a
14:59little bit, it comes up with some ideas.
15:01Then it goes thinking again to validate
15:02those ideas. Then it discards them. Like
15:04if anyone has been using cursor or
15:06something like that, the first thing it
15:08does it tries random code. Then it runs
15:10some tests. It doesn't work. Okay, types
15:13are wrong. Then it tries to fix the
15:14types. Then something else breaks. And
15:16then it traces and so it has all of
15:18these different iterations and in any of
15:20these iterations it can trigger a pause.
15:24I put pause here in quotes because this
15:26is a term that is not standard across
15:30different AI agent frameworks. Like for
15:32example, if you're using something like
15:34line chain, this is called an interrupt
15:36where the workflow basically pauses. it
15:38saves state as it currently is and it
15:41delegates uh the workflow execution back
15:45to the prompt.
15:47So after after we have a a pause or on
15:51an interrupt in the process then we have
15:54human reviewers that will receive all
15:56the necessary context. So everything
15:58that was in state, everything that has
16:00been uh planned in the AI any any piece
16:05of information that is relevant for the
16:06us for the human should received all
16:09that context.
16:11Um we talk about that state is process
16:13is uh preserved during the review
16:16process. So if you're using something
16:17like lang chain, it will save the state
16:20somewhere. Either it going to be in
16:22memory and wait for the user to
16:24interact. Maybe not an ideal scenario
16:25for production, but it's most commonly
16:28known that it will try to save into a
16:31database like radius where it will
16:33persist that information to come back to
16:35it at a later point. So after the user
16:38reviews the feedback and it's
16:40incorporated into the system, the
16:42workflow continues its execution from
16:44where it left. So it doesn't need to do
16:46all the previous steps again because
16:49state is a reflection of what happened
16:51before. it can continue from where it
16:53left off.
16:56And yeah, so that's those are kind of
16:58like the steps of uh human in the loop
17:00workflows.
17:02And now we can see it a little bit in
17:03action. I think I recorded this demo a
17:06little bit too fast. So if I don't catch
17:09up with the speed of the video, I'll go
17:10a little bit behind otherwise I'll speak
17:13too fast and I already speak way too
17:15fast. So let's go. So in here we have a
17:19chatbot um where we ask the chatbot to
17:22man to watch the stock market and if
17:25there's a good opportunity to buy some
17:27stock it will automatically buy it for
17:29us. Uh so the chatbot says like hold on
17:31you I'm not authorized to send you push
17:33notification so it asks me to uh it
17:36asked me for authorization and then I go
17:39home and at some point during the market
17:41I receive a push notification. I checked
17:43the notification that went too fast. But
17:45the notifications basically uh had the
17:49the question, I found this opportunity
17:52in the market. This is what I'm about to
17:54buy. I'm about to buy 10 stocks of SECO,
17:56I think it was for $15. And and then it
17:59asked me, do you want to continue? Do
18:01you want to approve this request or do
18:03you want to reject it? And the moment I
18:05click on approve this request, the AI
18:07agent continues the task, does the
18:10purchase for me, and hopefully in 10
18:12years I can retire, right? Because SECO
18:14is a great company
18:16probably working on human on the loop
18:17solutions.
18:20Um, but it is a developer conference
18:22after all. So we want to see a little
18:25bit of code. Unfortunately, I don't have
18:27a lot of time to go into all the details
18:29and and nuggets about how human in the
18:32loop interactions work, but this will
18:33give you a little bit of a picture of
18:35how it is implemented in one of the
18:36popular uh AI agent frameworks called
18:40Langchain or Langraph or Langmith, I
18:43don't know, they have multiple names for
18:44similar things. Uh but at the beginning
18:46we define a tool and for example that
18:48could be the risky action tool and
18:51inside that tool we simply raise an
18:53interrupt interrupt exception. Um
18:56sometimes this is also defined as an
18:57interrupt function uh within lang
19:00depending on the version that you that
19:01you are and how you plan to do things
19:03but we basically trigger an interrupt
19:05that says for example in this case human
19:07review required. That's the context that
19:09we are giving the human about this
19:12interruption. That's everything that is
19:13happening. Then we define the agent
19:16execution executor from all the tools
19:18and we pass an array of tools. In this
19:20case we only have the risky action tool.
19:23And finally we uh we invoke the executor
19:27and and we pass the prompt
19:30uh perform risky action. Right? So we
19:32make sure it triggers uh no matter what
19:34LLM you use. I think this is pretty
19:36straightforward. It should trigger that
19:38uh tool. And what is going to happen
19:40here is when when the LLM starts
19:43evaluating the tool call and it detects
19:45that the that the tool call is required
19:47and it detects the interrupt it will
19:49automatically save state at that point
19:52and it will raise an exception and the
19:54exception will be catched
19:57um below there and then it will in this
20:00case it's just printing the interruption
20:01into into the command line right but you
20:04can see like in this case you could
20:07instead of that print You could use this
20:10push notification and fancy system to
20:12collect information about the user and
20:13then continue the workflow. Right?
20:17Um again each framework does things
20:20differently. Even the same framework
20:22will change his minds every two three
20:23months. So you always need to be reading
20:25the latest documentation because things
20:26are always breaking at this point. Uh is
20:29it's the A life right? Uh we like buying
20:32we like breaking. So uh the internet uh
20:34the inter pattern is not baked into
20:36every single framework. Sometimes you
20:38need to do it like on your own. If
20:39you're a JavaScript somewhere here and
20:42you use Versail AI, I'm sorry, but you
20:44have to do this on your own. If you're
20:45on Python using Lchain, kudos to you. Uh
20:48you have that all that in uh integrated
20:52and well that's hard, right? Because I
20:54mean interrupts were easy, but what
20:56about all this notification and fancy
20:57thing and how do I put everything back
20:58in the workflow? Yeah, that's a lot of
21:00code that you will have to write.
21:01Unfortunately,
21:03um there's no other solution that I can
21:07think of that will quite solve that. Um
21:13unless you are familiar with all for
21:15genai. Sorry for the black here. Um but
21:18I am a developer advocate for all zero
21:21and all forgi kind of like solves this
21:23problem. So we cover four different
21:26pillars for security for AI agents for
21:28authentication and authorization for AI
21:30agents from user authentication token
21:32vault a synchronous authorization which
21:34is human in the loop interruptions and
21:36fga for rag and if you want to learn
21:39more about this I'm uh I'm going to be
21:42this three days in front of the size
21:45planetarium I think it is on E1 uh so
21:48you can come here and visit me and we
21:50can discuss more and we can see a little
21:52bit more code a little bit more action
21:53on how everything works because now time
21:55is almost up.
21:57You can scan the QR code there on the
21:59bottom uh right right left of the
22:02screen. I feel like when I'm live
22:04streaming I never know what is right,
22:05what is right, what is left. Uh you can
22:07scan that QR code over there and it will
22:09take you to the alto website where you
22:11can learn more about each one of these
22:12components.
22:14And with that said, I want to thank
22:15everybody for your time today and for
22:17joining. Again, let's connect. Let's
22:19start the discussion. Let's keep AI
22:21under control and let's keep AI secure.
22:22Thank you.
22:25[Applause]
22:30So uh thank you everyone and if you have
22:33any questions feel free to post it in
22:35slido.
22:38So there are QR codes posted across the
22:41room. You can scan the uh that and they
22:44can post your question.
22:49I guess I confused everybody or I was
22:52very clear.
23:03Yeah.
23:05are using.
23:11So, I'm particularly fond of lang chain
23:14because it's uh kind of like the easier
23:16one for some of these situations. Not
23:18saying it's the best one, but is also
23:20one I'm familiar with the most and
23:23things are changing so fast that it's
23:25very hard to keep up with what
23:26everybody's doing. So, I kind of like
23:28picked one and went deep into one. Um if
23:31if if you follow for example we are
23:32doing with zero for python we are
23:35working with llama index and we are
23:37working with lang chain directly
23:40um because those are like seems to be
23:42like the two most popular in the in the
23:44industry right now but we are always
23:46listening like to developers like what
23:48what are you all using right so we can
23:50also try and experiment new things I'm
23:52always trying things but it's very it's
23:54very very hard to keep up with all the
23:56details um so I'm really focused on lang
23:58chain because it serves my purpose in in
24:00all the things that I have built. So
24:03So uh we have a couple of questions come
24:05up here. So first of all, thank you for
24:07the good input. How do you combine human
24:10in the loop and langraph?
24:13H what was the question? Sorry. How do
24:14you combine human in the loop and the
24:17langraph?
24:18Oh, you come in. Uh is that's the
24:21question? Okay. Um
24:25so I mean
24:27Lang graph has very good documentation
24:30for human in the loop and I really
24:32recommend that you go and check that uh
24:34documentation because it really provides
24:36a lot of details on how to trigger
24:38interrupts
24:40and which is this um this phenomenon
24:43that saves state and stops the workflow
24:46execution. After that what you do with
24:48interact is really up to the developers
24:50and this is something where I really
24:51feel like there's a lot of documentation
24:54missing because a lot of people now
24:55understand okay so I need to treat an
24:57interact but what do I do after it right
24:59and there's a lot of discussions and
25:01there's a lot of conversations that are
25:03going on because no one has it very
25:05clear what is the best approach how how
25:08do we continue after that right and
25:09everybody will have like different
25:10opinions and it will be like in
25:12different ways um
25:15but and I think it was takes some time
25:17until some of these things settle and
25:18standardize on on what are the best
25:20approaches but for now it's like there's
25:23a lot of improvisation in some of these
25:25things. Okay, thank you. The next
25:27question is what belongs to the state is
25:30it basically the messages from the chart
25:33so far?
25:34Um so that will depend on your agent
25:36right. So the messages are definitely
25:39always part of st uh of state but there
25:41could be a lot more things you could
25:43carry things like for example like we
25:44talk about in the case of the booking uh
25:47for the holiday trip you can have the
25:48destination as a variable state you can
25:50have the price as a variable state right
25:52so it will really be up to like uh your
25:55use case but there's a lot of things you
25:56can carry in state okay one last
25:59question we have uh can we use a second
26:01agent to verify the response of the
26:03first agent
26:05can use Uh yes yes yes you can um you
26:09may end up in a loop right because uh AI
26:12is a little bit unpredictable and it may
26:15end up contradicting but if you take a
26:17look to some things like there are
26:18examples even like if you take a look
26:20cursor corser kind of like does
26:21something like that they have like this
26:23agent that writes things and then
26:25there's the other that validates and
26:26sometimes you see that it tries one
26:28thing and then it validates and then it
26:29doesn't like it and then it tries again
26:31and it goes for like five minutes
26:33fighting on what is the best solution
26:34until it gives
26:35Uh so that's kind of like what you get
26:37when you try something like that as
26:40I think it's missing the point. I think
26:42the point is we want people to be the
26:44ultimate decision colors.
26:47Great with that uh we are out of
26:50questions and thank you so much once
26:52again uh JC Martins for your uh
26:55wonderful thoughts. Thank you everyone
26:56for participating. Uh once again please
26:59give him big round of applause for
27:00sharing his thoughts. Thank you.