← All speakers

Bio, Work & Ideas

Keiji Kanazawa

Conference affiliation: Principal Product Manager · Microsoft · 2026

Keiji Kanazawa is a principal product manager at Microsoft working on Microsoft Foundry, where he helps developers deploy advanced models, including Anthropic’s Claude, in production. His career spans foundational research on probabilistic reasoning, early autonomous vehicles, cloud-scale machine learning, and the security of modern AI agents.

Kanazawa earned a bachelor’s degree from Bennington College in 1985, a master’s degree from Brown University in 1988, and a doctorate in computer science from Brown in 1992. His doctoral research on temporal and probabilistic reasoning explored how intelligent systems anticipate changing conditions and make decisions under uncertainty.

He subsequently worked as a research scientist at the University of British Columbia and completed a postdoctoral appointment at the University of California, Berkeley, in 1994–95. With Daphne Koller and Stuart Russell, he studied simulation algorithms for dynamic probabilistic networks; at Berkeley, he also worked on the Bayesian Automated Taxi, an early vision-guided autonomous-driving project.

Kanazawa later joined Microsoft and moved into Azure Machine Learning. His work encompassed cloud-scale reinforcement learning by 2020 and business applications for foundation models by 2021. More recently, he has worked on automated safety testing in Azure AI Foundry and production deployment of Claude through Microsoft Foundry.

  • Automated AI red teaming: Kanazawa helped bring Microsoft AI Red Team expertise and the open-source PyRIT framework into hosted evaluation tools that developers can use to probe applications for adversarial vulnerabilities. His joint AI Engineer session with Nagkumar Arkalgud distinguished his product and safety framing from Arkalgud’s implementation demonstrations.
  • Application-level safety architecture: He treats model safeguards as only one layer of protection. Effective systems also require input and output filtering, defenses against prompt-based attacks, testing for sensitive-data exposure, and controls tailored to the application’s actual access and responsibilities.
  • Continuous agent evaluation: For systems that use tools, retrieve information, and act across services, he emphasizes ongoing quality checks, risk assessments, instruction-following evaluations, governance, and monitoring.

Kanazawa also builds independently: his public projects range from fast.ai course experiments to prompting and agent prototypes, and in 2026 he described developing a YouTube-and-X quick-take agent.

Read the topics behind these talks

1 conference talk

References