Harriet Farlow
AI systems are going into production faster than anyone is checking whether they can be attacked. A model can be poisoned during training or manipulated after deployment, and most security functions have no test for either. That risk sits between the data science team and the CISO, and neither owns it.
Harriet Farlow is an AI security researcher who shows organisations how their AI systems can be attacked, and what it takes to defend them, drawing on her work inside Australia’s signals intelligence agency and her company Mileva Security Labs.
Full Profile
Why organisations work with Harriet Farlow
- She held operational responsibility for AI security inside a signals intelligence agency, as Acting Technical Director of the AI Hub at the Australian Signals Directorate. Her stated purpose in going commercial is to transfer that standard of scrutiny to civilian organisations.
- The technical work is her own. Her DEF CON 32 main stage talk presented original research attacking computer vision systems, and Practical AI Security ships more than 30 runnable Python demos of the attacks and defences it describes.
- She has built the things she recommends: the first AI security framework in an Australian government department outside national security, and the first mandatory AI security training programme in an Australian organisation.
- She holds the same subject at two levels of technical depth, from work with organisations including HSBC, Mastercard, and Lenovo to main stage research talks at DEF CON and BSides Las Vegas.
Biography highlights
- Founder and CEO of Mileva Security Labs, Australia’s first dedicated AI security company, now operating from Australia and London
- Author of Practical AI Security (No Starch Press, 2026), a 392-page technical guide covering the AI attack lifecycle, red teaming, safety evaluation, and governance
- Former Acting Technical Director of the AI Hub at the Australian Signals Directorate, working with Five Eyes intelligence partners
- PhD in machine learning security, UNSW Canberra; Master’s in Cyber Security; BSc in Physics and Anthropology, ANU
- Main stage speaker at DEF CON 32, plus BSides Las Vegas, Black Hat MEA, and the Australian Cyber Conference
- Host of The AI Security Podcast; named a Vogue Codes Future Innovator finalist, December 2024, and profiled by Vogue Australia
Biography
The Australian Signals Directorate runs an AI Hub inside its national security remit, staffed to work with Five Eyes intelligence partners. Harriet Farlow served there as Acting Technical Director, after working across three teams at the agency. Her stated purpose in founding a company afterwards was to transfer that standard of scrutiny to civilian organisations running the same kinds of models.
Mileva Security Labs, which she founded in 2023, was built to move that standard across. Through it she developed the first AI security framework in an Australian government department outside national security, and the first mandatory AI security training programme in an Australian organisation. The company now operates from Australia and London, and she has led AI security assessments for Fortune 500 companies and government agencies.
The research underneath the commercial work is her own. Her DEF CON 32 main stage talk in 2024 covered her attacks on facial recognition and surveillance systems, run with the cooperation of Canberra Casino. A second talk that year examined how popular culture shapes what people expect of AI in national security. Practical AI Security followed from No Starch Press in June 2026. Its 392 pages cover data poisoning, model theft, prompt injection, red teaming, and governance, with more than 30 Python demos and threat modelling against MITRE ATLAS, OWASP, and MAESTRO.
AI Security Fundamentals, her course, runs eight weeks and pairs self-paced content with live instructor-led seminars. She also hosts The AI Security Podcast. In December 2024 she was named a Vogue Codes Future Innovator finalist, an unusual credential for someone whose research subject is breaking facial recognition systems.
Key speaking topics
- AI security and adversarial machine learning
- AI as an attack surface in enterprise deployment
- AI governance, standards, and regulatory obligation
- AI red teaming
- Nation-state threats to AI systems
- AI safety failures, bias, and alignment risk
- Human judgement and control in increasingly capable systems
Ideal for
- CISOs and security engineering leads whose remit now includes models they did not build
- Boards and executive committees signing off AI deployments they cannot personally assess
- Chief data and AI officers, and the ML engineering teams reporting to them
- Risk, audit, and compliance functions preparing for AI standards and regulation
Audience outcomes
- A working vocabulary for AI attacks, covering data poisoning, model theft, prompt injection, and evasion, and what each one does to a system in production
- The questions to put to a vendor or an internal team before an AI system reaches production
- A line between the AI risks that are live now and the ones that belong to a later decade
- Where AI security sits against existing controls, and the specific points at which cybersecurity practice does not transfer
- What national security practice assumes about adversaries, and which of those assumptions a commercial organisation should adopt
Talks
What leaders need to settle about securing AI systems before deployment.
Key takeaways:
- How models are attacked across the AI lifecycle, from data poisoning through to prompt injection and model theft
- What changes when models are wired into agentic AI systems
- Why AI red teaming is a different exercise from a conventional penetration test
What increasingly capable systems mean for human judgement, creativity, purpose, and control.
Key takeaways:
- How systems optimise for the measure rather than the goal, and what that produces in practice
- Why an AI causes harm by being competent, confident, wrong, and trusted, with no malice required
- Where human judgement remains the control of last resort inside an automated process