Mindstone Lisbon September AI Meetup header image
Mindstone Lisbon September AI Meetup

Welcome to the biggest Practical AI Meetup in Lisbon!

Join us once a month as we explore the world of artificial intelligence, its cutting-edge practical applications, and the astonishing projects that are shaping our future.

Why should you attend?

  • Get up close and personal with the AI projects that are redefining the boundaries of technology and human potential.
  • Learn from the brightest minds in the field and gain valuable insights into the ever-evolving AI landscape.
  • Unleash your curiosity, fuel your creativity, and expand your network as you connect with fellow AI aficionados and pioneers.

What you can expect?

This Mindstone event consist of three talks covering different aspects of AI, followed by a panel discussion:

  • Best Practices in AI Agent Development: Learn how enterprise-grade AI agents are built, deployed, and scaled, with practical insights from real-world implementations across leading organizations.
  • The 93% Problem: When Your AI Detects Attacks but Doesn't Clean Them Up: Explore the emerging security risks of memory-based prompt injection, why "detect but don't remove" creates hidden vulnerabilities, and what practical defenses organizations should adopt.
  • From Vibe Coder to PM: Running an AI Teammate Like a Real Hire: Discover how treating AI as a true team member—with tickets, sprints, workflows, and accountability—can unlock greater autonomy and productivity than traditional prompting.
  • Panel Discussion: A moderated discussion with all speakers, diving deeper into the topics covered and opening the floor for audience questions and perspectives.

After the talks we'll have pizza, drinks, and time to connect with everyone around you.

Don't miss the opportunity to see what's really happening in AI - you'll be surprised at what's already possible today.

We have limited spots available, so get your ticket ahead of time to avoid disappointment!

Agenda
Doors Open
Welcome to the event
Introduction
Welcome and event introduction
Best practices in AI Agent Developement by Benedikt Sanftl
How we built reliable Enterprise Agents for companies like Linde, Volkswagen, etc... and how we merge all of this into one coding agent factory.
The 93% Problem: When Your AI Detects Attacks but Doesn't Clean Them Up A practical look at stored injection in MCPs and Agents, with the receipts. by Blessed Uyo
Abstract Prompt injection just grew a stored variant. A University of Washington study this year found something worse than models acting on malicious instructions: whether a model acts on a poisoned memory is uncorrelated with whether it cleans it up. Their strongest model had the lowest attack-success rate and the highest persistence — it detected the injection, refused it, asked the user to delete it, and left it in the file 93% of the time. Your safest model becomes a delivery mechanism for your weakest one. This is a practical, evidence-first talk. From real testing of production MCP servers and AI agents. SQL injection and stored XSS reaching live backends through tool-call arguments, cross-tenant reach by chaining "safe" tools, memory injections accepted because they're dressed as a user preference. I'll show the gap between "detected" and "removed" is not hypothetical. Then the receipts: a production dashboard where 25 of 25 critical alerts sit unactioned and 77,000+ incidents stay open, while the only things cleaned up were the ones that didn't matter. The second half is what to do about it: snapshot the surface your agents can write to, diff it after every session, and treat "detected but not removed" as its own failure mode plus the deterministic rails (a signed-token check that stopped 178 of 178 write attempts; an interlock that blocked 58 of 58 destructive commands) that work because they don't rely on the model's judgment. The autonomy is theirs; the blast radius is yours. What you'll leave with - A new attack class: stored injection in your agents and MCP tools, and how to spot your own exposure. - Why your strongest model can make it worse, with production data. - A defense you can ship Monday: snapshot, diff, and fail the run on "detected but not removed."
From vibecoder to PM: running an AI teammate like a real hire by Tahi Gichigi
Tahi will walk through how Mooch stopped prompting AI and started managing it. Moochbot isn't an agent that gets a prompt, it's treated like a team member: it gets written tickets, works sprints, and is held to a status flow just like a person would be and it even joins the weekly sprint retro. The shift from vibecoding to writing specs and running process is what unlocks more capability, more flexibility and more autonomy from the same AI, and it moves faster than prompting ever did. Practical, not theoretical: the simple stack, what the tickets look like, how sprints run, and what changed when Mooch started managing AI instead of chatting with it.
What I Learned Building With LLMs
A technical talk breaking down the process for building a product using AI with real-life learnings and insights.
Wrap Up
Closing remarks and next steps
Pizza, Drinks & Networking
Casual networking with food and drinks
Speakers
Attendees
Location
Get involved in Lisbon

Help bring more practical AI events to your city.

Become a Mindstone Associate

Help us grow your local community.

Volunteer at an event

Lend a hand on the night — no commitment.