Black Hat 2026: Security leaders weigh in on AI, vulnerability management and cyber resilience

At Black Hat USA 2026, security leaders focused on growing challenges including AI governance, identity, software supply chain risk and vulnerability management. One shift stood out: security teams are gaining more visibility into risk, but turning that visibility into action is becoming harder.

As AI agents gain access and autonomy, the challenge is deciding what matters most, applying the right controls and responding quickly enough to reduce exposure.

The perspectives below come from cybersecurity leaders who were on the ground at Black Hat and reflect how challenges are playing out across the security landscape:

Shira Sagiv, VP, Product Portfolio, Radware

“Black Hat USA 2026 is reinforcing how quickly AI agents are becoming part of the enterprise environment. As organizations adopt these tools, security teams need to discover which agents are operating in their environments, understand their access and permissions, govern their activity, and identify risky or unintended actions at runtime. With only 17% of organizations reporting full visibility into their AI agents and AI-driven processes, the ability to discover, govern and protect these agents at runtime is becoming a fundamental requirement for enterprise security.”

Srinivas Mukkamala, CEO of Securin

“Days before Black Hat, hackers shut down water treatment controls in a small Minnesota town most people couldn’t find on a map. That attack didn’t take months to plan. It took hours. Nothing about thatsurprised anyone inside Black Hat – security teams have been warning about this exact scenario for years. Whatshould surprise everyone else is how far behind they still are.

AI didn’t create this problem – it just spun up the clock speed on a fight that was already underway. The people at BlackHat already know the answer isn’t piling up more warnings and reports. It’s knowing which threats can actually hurt you, and fixing that fast enough to matter. 

Small towns are now front-line combatants in a geopolitical cyber war. Governors, mayors, utility boards – whoever’s in charge – don’t have the luxury of catching up on their own timeline anymore. The rest of the country needs to start thinking like the people who saw this coming.”

Kara Sprague, CEO, HackerOne

“Coming out of Black Hat, one message was clear. The resolution rate for critical vulnerabilities on the H1 Platform fell from 85% to 44% over the past twelve months. Not because teams got slower. Critical fix times improved 53% over the same period. Teams are fixing faster than they ever have and still losing ground, because confirmed findings arrive faster than they can close them. The unresolved critical backlog is up 29 times in a single year. Finding vulnerabilities is no longer the hard part of security. Closing them fast enough to matter is.

Three of the four alarms I identified coming into the summer have gone off. The fourth alarm hasn’t rung, and what’s holding it is not capability. That bottleneck is logistics, and logistics is the part of this that automates most easily. Getting through it takes far more AI on defense than most organizations are running today.”

Richard Bird, CSO2 Singulr AI

“As Black Hat brings the industry together to debate agentic AI, one question deserves more attention: what replaces segregation of duties when a single AI agent can request, approve, execute and review the same action?

Enterprise governance has traditionally relied on separating those responsibilities. Agentic AI collapses them into a single system operating at machine speed. Governance can no longer be measured by whether a policy exists or an approval was granted before deployment. Approval is a point-in-time event. Governance happens at runtime.

Organizations need evidence thatcontrols are actively changing an agent’s behavior: what data it accessed, which tools it invoked, when it was blocked or required additional authorization, and who had the authority to intervene. As agents move onto employee endpoints and deeper into enterprise workflows, the new control boundary is the agent’s runtime decisions.

If governance does not produce observable changes in an AI agent’s behavior, it is not governance. It is documentation.”

Garrett Gross, Field CISO, Portnox 

“What I heard at Black Hat and saw firsthand at DEF CON is that AI has moved beyond the hype cycle and is becoming part of the security environment we actually have to defend. You could see it playing out in real time on the show floor. At Black Hat, nearly every conversation was either about securing AI or ad+ding AI to the tools we already use, while DEF CON gave autonomous AI agents a proving ground of their own. But underneath all of that, the fundamentals haven’t changed. 

Every autonomous agent is another identity with access to your environment, and if you can’t identify it, authenticate it, govern its privileges and control what it can reach, you’ve created a new version of an old security problem. 

As AI matures, it doesn’t replace security fundamentals. It makes them more consequential for every connected identity type – human and non-human. Locking in the basics matters more than ever.”

Javed Hasan, CEO and Co-founder, Lineaje 

“Coming out of Black Hat and Ai4, one reality is undeniable: AI asset governance is no longer optional.

As autonomous agents gain direct access to source code, APIs, sensitive data, and critical infrastructure, they inherently become part of the enterprise attack surface. Every time a developer pulls in a new skill or runtime agent, they introduce new risk. Our data shows 2.1% of these runtime skills are suspicious. When an enterprise deploys hundreds of skills, thatsmall percentage becomes a massive enterprise vulnerability.” 

These perspectives point to a security environment where visibility alone is no longer enough. The challenge is determining which risks matter most, applying the right controls and acting quickly enough to keep exposure from becoming impact.

As AI agents, identities, vulnerabilities and software dependencies become more interconnected, security teams will need to bring governance, prioritization and response closer together. The takeaway is that effective security will depend not just on seeing risk, but on acting with enough speed and context to make a difference.

Join our LinkedIn group Information Security Community!

No posts to display