At Black Hat 2026, safety leaders go deeper to get forward


Every August, the cybersecurity trade converges on Las Vegas for Black Hat USA, one of many 12 months’s largest gatherings of safety researchers, CISOs, know-how distributors, authorities officers and enterprise practitioners. The convention is understood for technical analysis displays, product bulletins and discussions across the threats and applied sciences shaping cybersecurity technique. For enterprise leaders, it affords a snapshot of the problems commanding the trade’s consideration — and sometimes the place safety funding is headed subsequent.

Unsurprisingly, AI is the defining theme of Black Hat USA 2026, formally and unofficially; this 12 months’s occasion features a devoted AI Summit and a brand new AI Zone, alongside keynote discussions targeted on AI-powered cyber operations and the altering dynamics between attackers and defenders.

“AI is in every single place; from signage if you land on the airport, to companion cubicles and the beginning of each consumer dialog,” mentioned Julie Talbot-Hubbard, vice chairman of safety companies at enterprise IT consulting and companies agency AHEAD.

Associated:The Week of July 27–31: What occurred, what issues, what’s subsequent

The quantity of AI messaging has additionally created a brand new problem for safety leaders: separating significant advances from advertising claims.

Chase Cunningham, chief technique officer at software program virtualization platform Demo-Drive, described AI as having “annexed the convention.”

“You can not stroll 20 toes with out encountering agentic, AI-powered or autonomous connected to a product that, in some circumstances, was apparently doing simply positive with out these phrases final 12 months,” he mentioned.

AI as a software, not a savior

Regardless of the flood of AI-related bulletins, attendees described a shift in tone: much less concentrate on AI’s potential and extra on the operational challenges of deploying it securely. “The dialog feels extra mature this 12 months,” as Talbot-Hubbard put it. Extra pragmatic.

Somewhat than debating what AI may ultimately allow a number of years down the road, safety leaders had been targeted on the right way to establish, govern and safe the AI programs at the moment getting into the enterprise.

“Persons are transferring previous the hype and specializing in the arduous operational questions round securing brokers, identities, permissions and the infrastructure that helps them,” mentioned Diana Kelley, CISO at Noma Safety, an agentic AI safety platform.

Talbot-Hubbard agreed, saying AI is now “a part of the broader safety working mannequin dialog, not a separate experiment.” Organizations are trying past particular person merchandise, to whether or not they have the foundational capabilities wanted to help AI securely, together with id controls, visibility, governance and resilience.

Associated:OpenAI’s hacking incident places enterprise AI boundaries to the check

“Essentially the most optimistic shock was how sensible the AI dialog has develop into,” Kelley mentioned. “There’s a lot much less endurance for generic ‘AI-powered’ claims and rather more concentrate on provable controls, observability, governance and whether or not these merchandise truly work in complicated operational environments.”

For some attendees, the sheer variety of AI-focused corporations at Black Hat highlighted each the extent of funding flowing into the area and the problem of evaluating which applied sciences can have an enduring affect.

“The variety of new, well-funded AI-first corporations on the ground with large cubicles [and] severe presence” was notable, mentioned Louis-David Mangin, CEO and co-founder of Confiant, a cybersecurity resolution for promoting. “It is a sign of how a lot capital is chasing this area, however it additionally creates noise at an occasion that was once simpler to navigate.”

Mangin mentioned the elevated industrial presence additionally modified the texture of the convention in contrast with earlier years. Whereas conversations about actual challenges and hard-won classes proceed, he famous they will typically really feel tougher to seek out amid the amount of vendor messaging.

AI raises the stakes for acquainted safety challenges

In these conversations, attendees repeatedly returned to longstanding safety challenges that stay unresolved whilst AI is launched. AI is each a safety software and an accelerant for attackers; the priority is much less that cybercriminals will develop totally new methods, and extra that AI will permit them to function extra effectively.

Associated:Cybersecurity past blocking: A name for collaboration

“The overarching concern is that offense is getting cheaper, sooner and simpler to scale,” Cunningham mentioned. AI can speed up reconnaissance, vulnerability evaluation, exploit improvement, social engineering, credential abuse and post-compromise exercise, he mentioned.

Kelley equally pointed to the velocity of assaults as a significant concern, noting that AI is compressing the time between discovery and exploitation whereas organizations proceed to handle current safety debt, together with overprivileged identities and software program provide chain publicity.

The higher capabilities of cybercriminals are additionally rising as enterprise architectures develop extra complicated and built-in. Mangin described a rising sense amongst attendees that organizations are more and more weak in consequence.

“The assault floor is not simply larger, it is extra interconnected,” he mentioned, pointing to dangers spanning enterprises, platforms, AI programs and infrastructure. “Attackers are searching for the gaps between them.”

That interconnectedness can be why safety leaders proceed to emphasise core practices. AI could speed up assaults, however it doesn’t get rid of the necessity for robust id controls, least-privilege entry, monitoring, segmentation and restoration planning.

“AI is an accelerant, not an exemption from doing the basics,” Cunningham mentioned.

The problem for enterprises

Throughout discussions at Black Hat, one theme emerged constantly: organizations are attempting to maneuver rapidly sufficient to seize AI’s advantages whereas avoiding the dangers created by deploying new capabilities with out ample controls.

Mangin described this as an ongoing imbalance between attackers and defenders. Cybercriminals can experiment and adapt with out the identical insurance policies, processes and governance necessities that enterprises should navigate. This naturally places enterprises on the again foot and locations higher stress on the safety selections they do make.

This problem is what motivated many IT leaders to attend Black Hat USA 2026, the place they will converse with their friends and study new concepts for the right way to get forward of the menace actors.

Talbot-Hubbard spoke of wanting a sharper learn on safety leaders’ priorities for the following 12-24 months, in addition to the hole between technique and execution — however she additionally emphasised the significance of connecting first-hand with the trade to check notes: “One of the best final result is not an inventory of recent applied sciences; it is insights that assist organizations make higher selections with extra confidence.”

Different attendees see Black Hat as a possibility to achieve higher oversight of an more and more complicated image.

“We got here right here to deepen and widen our view,” Mangin mentioned. “Nobody firm sees the whole image. Everybody has a unique piece of the puzzle. Black Hat offers us an opportunity to know what’s occurring past the a part of that chain we see instantly and study from individuals with visibility into different elements of it.”

After which there’s the need for readability. Cunningham mentioned he got here to Black Hat to differentiate those that have constructed instruments that ship measurable safety outcomes from those who merely put the phrase agentic on final 12 months’s structure diagram. He additionally needed to talk with practitioners coping with points in actual environments, problem distributors on product capabilities, and perceive the place analysis is transferring sooner than enterprise safety applications can adapt.

Merely put, he mentioned: “I’m right here to separate sign from noise.”

Had been you at Black Hat this week? Tell us what stood out for you: [email protected].



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles