AI dominated the conversation at Black Hat USA 2026, from wide-ranging explanations of risks faced today through to a vast array of presentations claiming that AI was, in some way, responsible for the cyberthreats plaguing us.

Black Hat USA 2026: AI is racing ahead of cybersecurity controls

Opening Keynotes

The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials. First up was Sean Cairncross, the White House National Cyber Director, who set out the case that regulation of AI would both stifle innovation and development and struggle to keep pace with the speed at which AI is currently moving. It was clear from the discussion that there is an AI ownership race, with Cairncross claiming that “AI is a tremendous story of American innovation” and making various other comments on how America leads the world in this field.

The internet at large is a global resource that no individual or group of people can claim as their invention or innovation — and this is certainly true also for the rise of AI. During the opening talks there was even mention of some companies that have been instrumental to the innovation of “AI made in America.” One of the companies mentioned is based in London, which made the claim even more preposterous. Cairncross also noted that the US government is looking at ways to build a US open-source infrastructure that the rest of the world can benefit from. The future is one where all of us pull together to create a robust vision and strategy on how emerging AI functionality can be used safely, efficiently, responsibly, and without risk.

Government Panel

The second part of the opening keynote included Nick Andersen, Acting Director of CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman, Assistant Director of the Cyber Division at the FBI. The FBI pointed to the success of Operation Riptide, which resulted in the arrests of over 200 people allegedly engaged in cybercrime.

In a wider discussion, the panel examined the fast-paced situation we face as vulnerabilities are being discovered by AI-powered systems in vast quantities and at speed. This prompted the CISA representative to call for “ruthless prioritization” and stress the importance of industry collaboration. Without some form of regulation, however, the boundaries on the use of AI remain blurred.

The Assistant Secretary of War for Cyber Policy offered a pointed analogy when pressed on the struggles regarding resourcing in the cybersecurity industry: you don’t want a pediatrician performing heart surgery. The point is well made — cybersecurity teams around the world lack the granular specializations needed, especially in this AI moment, to protect against the sophisticated threats being unleashed by cybercriminals. Overall, the keynotes felt like a party-political speech ahead of the forthcoming mid-terms.

Conference Highlights

The conference highlights included numerous discussions on the fast-growing numbers of vulnerabilities being uncovered in current and legacy software with the help of AI, as well as detailed insight delivered by the OpenAI team into the Hugging Face incident.

The Core Takeaway: Accountability

The main takeaway is a view that several presenters at Black Hat echoed clearly. David Weston from Microsoft summarized it well: AI agents authenticate, invoke tools, and inherit permissions in the same way a human employee does, but without the oversight, policy, and governance needed to make them accountable.

This message is an important one. We talk about autonomous AI attacks and how AI “did” something, but behind AI are humans setting the tasks and guardrails. The technology is within our control, and we need to take full responsibility for it. If it is not under control, there is a straightforward solution: switch it off and re-task it with the correct controls in place to hold both the technology and the humans behind it accountable.