Every August, the cybersecurity trade converges on Las Vegas for Black Hat USA, one of many yr’s largest gatherings of safety researchers, CISOs, know-how distributors, authorities officers and enterprise practitioners. The convention is thought for technical analysis shows, product bulletins and discussions across the threats and applied sciences shaping cybersecurity technique. For enterprise leaders, it gives a snapshot of the problems commanding the trade’s consideration — and infrequently the place safety funding is headed subsequent.
Unsurprisingly, AI is the defining theme of Black Hat USA 2026, formally and unofficially; this yr’s occasion features a devoted AI Summit and a brand new AI Zone, alongside keynote discussions centered on AI-powered cyber operations and the altering dynamics between attackers and defenders.
“AI is in all places; from signage once you land on the airport, to accomplice cubicles and the beginning of each consumer dialog,” mentioned Julie Talbot-Hubbard, vice chairman of safety providers at enterprise IT consulting and providers agency AHEAD.
The quantity of AI messaging has additionally created a brand new problem for safety leaders: separating significant advances from advertising claims.
Chase Cunningham, chief technique officer at software program virtualization platform Demo-Pressure, described AI as having “annexed the convention.”
“You can’t stroll 20 ft with out encountering agentic, AI-powered or autonomous connected to a product that, in some instances, was apparently doing simply advantageous with out these phrases final yr,” he mentioned.
AI as a instrument, not a savior
Regardless of the flood of AI-related bulletins, attendees described a shift in tone: much less concentrate on AI’s potential and extra on the operational challenges of deploying it securely. “The dialog feels extra mature this yr,” as Talbot-Hubbard put it. Extra pragmatic.
Relatively than debating what AI may finally allow a number of years down the road, safety leaders had been centered on find out how to determine, govern and safe the AI methods at the moment coming into the enterprise.
“Persons are transferring previous the hype and specializing in the laborious operational questions round securing brokers, identities, permissions and the infrastructure that helps them,” mentioned Diana Kelley, CISO at Noma Safety, an agentic AI safety platform.
Talbot-Hubbard agreed, saying AI is now “a part of the broader safety working mannequin dialog, not a separate experiment.” Organizations are trying past particular person merchandise, to whether or not they have the foundational capabilities wanted to assist AI securely, together with identification controls, visibility, governance and resilience.
“Essentially the most constructive shock was how sensible the AI dialog has develop into,” Kelley mentioned. “There’s a lot much less endurance for generic ‘AI-powered’ claims and way more concentrate on provable controls, observability, governance and whether or not these merchandise really work in advanced operational environments.”
For some attendees, the sheer variety of AI-focused corporations at Black Hat highlighted each the extent of funding flowing into the area and the problem of evaluating which applied sciences can have an enduring impression.
“The variety of new, well-funded AI-first corporations on the ground with large cubicles [and] critical presence” was notable, mentioned Louis-David Mangin, CEO and co-founder of Confiant, a cybersecurity answer for promoting. “It is a sign of how a lot capital is chasing this area, but it surely additionally creates noise at an occasion that was once simpler to navigate.”
Mangin mentioned the elevated industrial presence additionally modified the texture of the convention in contrast with earlier years. Whereas conversations about actual challenges and hard-won classes proceed, he famous they’ll typically really feel tougher to seek out amid the amount of vendor messaging.
AI raises the stakes for acquainted safety challenges
In these conversations, attendees repeatedly returned to longstanding safety challenges that stay unresolved whilst AI is launched. AI is each a safety instrument and an accelerant for attackers; the priority is much less that cybercriminals will develop solely new strategies, and extra that AI will enable them to function extra effectively.
“The overarching concern is that offense is getting cheaper, quicker and simpler to scale,” Cunningham mentioned. AI can speed up reconnaissance, vulnerability evaluation, exploit growth, social engineering, credential abuse and post-compromise exercise, he mentioned.
Kelley equally pointed to the pace of assaults as a significant concern, noting that AI is compressing the time between discovery and exploitation whereas organizations proceed to handle present safety debt, together with overprivileged identities and software program provide chain publicity.
The larger capabilities of cybercriminals are additionally rising as enterprise architectures develop extra advanced and built-in. Mangin described a rising sense amongst attendees that organizations are more and more susceptible because of this.
“The assault floor is not simply greater, it is extra interconnected,” he mentioned, pointing to dangers spanning enterprises, platforms, AI methods and infrastructure. “Attackers are on the lookout for the gaps between them.”
That interconnectedness can be why safety leaders proceed to emphasise core practices. AI might speed up assaults, but it surely doesn’t eradicate the necessity for robust identification controls, least-privilege entry, monitoring, segmentation and restoration planning.
“AI is an accelerant, not an exemption from doing the basics,” Cunningham mentioned.
The problem for enterprises
Throughout discussions at Black Hat, one theme emerged persistently: organizations try to maneuver shortly sufficient to seize AI’s advantages whereas avoiding the dangers created by deploying new capabilities with out ample controls.
Mangin described this as an ongoing imbalance between attackers and defenders. Cybercriminals can experiment and adapt with out the identical insurance policies, processes and governance necessities that enterprises should navigate. This naturally places enterprises on the again foot and locations larger stress on the safety choices they do make.
This problem is what motivated many IT leaders to attend Black Hat USA 2026, the place they’ll converse with their friends and study new concepts for find out how to get forward of the risk actors.
Talbot-Hubbard spoke of wanting a sharper learn on safety leaders’ priorities for the following 12-24 months, in addition to the hole between technique and execution — however she additionally emphasised the significance of connecting first-hand with the trade to match notes: “The most effective consequence is not a listing of recent applied sciences; it is insights that assist organizations make higher choices with extra confidence.”
Different attendees see Black Hat as a chance to achieve larger oversight of an more and more advanced image.
“We got here right here to deepen and widen our view,” Mangin mentioned. “Nobody firm sees the complete image. Everybody has a distinct piece of the puzzle. Black Hat offers us an opportunity to know what’s occurring past the a part of that chain we see immediately and study from folks with visibility into different components of it.”
After which there’s the need for readability. Cunningham mentioned he got here to Black Hat to tell apart those that have constructed instruments that ship measurable safety outcomes from those who merely put the phrase agentic on final yr’s structure diagram. He additionally needed to talk with practitioners coping with points in actual environments, problem distributors on product capabilities, and perceive the place analysis is transferring quicker than enterprise safety applications can adapt.
Merely put, he mentioned: “I’m right here to separate sign from noise.”
Had been you at Black Hat this week? Tell us what stood out for you: [email protected].
