- Black Hat 2026 put AI security front and center. In just a few years, the conversation has shifted from whether to use AI to how to control it.
- Agentic AI is expanding the attack surface. Agents can now reach credentials, code, data, browsers, and business systems.
- One big takeaway from the event: Attackers and defenders are both moving faster, making runtime visibility and control increasingly important.
Black Hat USA 2026 took over Las Vegas last week and AI was definitely one of the most-used words in the Business Hall. But we saw another, much more interesting story underneath AI. AI security is struggling to catch up as AI moves from just generating answers to starting to take action. The question on everyone’s mind seemed to be: How do we maintain control when AI agents can browse, use credentials, access data, and take actions on someone else’s behalf?
That focus showed up in sessions on AI browsers and agent security, autonomous security, and products designed to monitor agents at runtime. After several days at the conference, five things stood out to us, including the company we think captured the bigger story better than anyone else.
1. AI wasn’t just part of the show. It was the show.
Technically, Black Hat had a dedicated AI Summit. In reality, AI permeated every part of the event. From the Briefings to the Business Hall, presenters and vendors focused on AI as both a defensive capability and a way for attackers to move faster,1 with topics ranging from AI identity and exposure management to remediation and application security.
2. Agent security is becoming a runtime problem.
One thing that was very clear at Black Hat was that AI agents are creating a new attack surface. Security teams can only get so far knowing who authenticated an agent or which model it uses. They also need visibility into what the agent is doing: what instructions it was given, which credentials it found, and whether data was moved.
Researchers also highlighted weaknesses in the relationships between AI agents and the components around them, especially as more organizations connect agents to real systems and workflows.
3. Criminals are operationalizing AI faster than most people realize
The criminal side of AI at Black Hat was less futuristic than you might think. Instead of scary stories about fully autonomous cyberattacks, much of the focus was on fraud happening right now.
Criminal operations are already combining AI voice cloning, deepfakes, and automated translation to make scams more convincing and easier to scale.2 That makes this bigger than a traditional cybersecurity problem. It’s a trust problem.
How do you know that was really your CEO was really on the video call, or that the person asking finance to change payment information is actually the supplier?
4. The AI arms race may eventually be agent against agent.
One of the more fascinating ideas around the conference was using offensive AI agents to make defensive AI agents better. In other words, if autonomous systems are going to probe and exploit other systems, defenders may need their own autonomous systems that can be trained against them and keep pace. Some of the work we saw is still emerging, but it points toward a future where humans may no longer be the only ones attacking and defending systems.
5. Our standout: AgentKeeper
There was no shortage of impressive technology at the conference this year, but AgentKeeper kept coming back to us because it connected directly to the conversation happening across the event.
AgentKeeper by RAD Security is built around a simple question: what is an AI agent actually doing once you give it access to your environment?
The platform monitors AI coding agents such as Claude Code, Cursor, Windsurf, and Copilot at runtime, giving security teams visibility into critical actions such as file access and credential use, along with policy controls that can evaluate and block risky activity.3
Coding agents are a good example of the shift attendees were wrestling with all week.
AgentKeeper was also an interesting Black Hat story because it shows how quickly the market is moving. RAD Security was recognized in Black Hat’s Startup Spotlight competition in 2024 and earned the People’s Choice award. Just two years later, the company is back with a product aimed directly at one of the industry’s fastest-growing security challenges.4
The Bigger Takeaway from Black Hat 2026
It was clear at the conference that AI is moving faster than many expected. As agents gain access to browsers, credentials, code, and business systems, the distance between AI development and security is shrinking fast.
Everything we saw at the event seemed connected by that thread as the AI conversation has moved from experimentation to execution. Now security has to keep up.
A: At Black Hat USA 2026 (Las Vegas, August 1-6), AI agents were one of the biggest themes, especially the challenge of security systems that can browse, access data, user credentials, and take actions on their own. The conversation has moved from whether organizations should use AI to how they control what AI is allowed to do.
A: Traditional AI tools mostly generated answers. Agents can interact with real systems and workflows. That creates more opportunities for misuse, compromised credentials, malicious instructions, and unauthorized actions.
A: Runtime security focuses on what an agent is doing while it’s activity working. That includes monitoring the files, tools, credentials, and systems it accesses and enforcing policies before a risky action is completed.
- Black Hat, The AI Summit at Black Hat USA 2026, accessed August 2026
- Dark Reading, AI Sends Global Crime Syndicates Into Fraud Nirvana, August 2026
- AgentKeeper.dev, Built by the runtime security team behind RAD Security, accessed August 2026
- Black Hat, Black Hat USA 2024 Announces Startup Spotlight Competition Finalists, July 2024