AI dominated the conversation at Black Hat USA 2026, from wide-ranging explanations of risks faced today through to a vast array of presentations claiming that AI was, in some way, responsible for the cyberthreat plaguing us.

The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials. First up was Sean Cairncross, the White House National Cyber Director, who set out the case that regulation of AI would both stifle innovation and development and struggle to keep pace with the speed at which AI is currently moving. It was clear from the discussion that there is an AI ownership race, with Mr. Cairncross claiming that “AI is a tremendous story of American innovation” and making various other comments on how America leads the world in this field. I am sure there are many of you who, like me, read this point of view with a shrug of the shoulders.

The internet at large is a global resource that no individual, or group of people, can claim is their invention or innovation – and this is certainly true also for the rise of AI. During the opening talks there was even the mention of some companies that have been instrumental to the innovation of ‘AI made in America.’ One of the companies mentioned is based in London, which made the claim even more preposterous. Mr. Cairncross also noted that the US government is looking at ways to build a US open-source infrastructure that the rest of the world can benefit from. The future is one where all of us pull together to create a robust vision and strategy on how the emerging AI functionality can be used safely, efficiently, responsible and without risk.

The second part of the opening keynote included Nick Andersen, Acting Director, CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman Assistant Director, Cyber Division, FBI. The FBI pointed to the success of ‘Operation Riptide’ that resulted in the arrests of over 200 people allegedly engaged in cybercrime.

In a wider discussion, the panel examined the fast-paced situation we are faced with as vulnerabilities are being discovered by AI-powered systems in vast quantities and at speed. This prompted the CISA representative to call for “ruthless prioritization” and stress the importance of industry collaboration. I do agree with the ruthless approach, but without some form of regulation the boundaries on the use of AI remain blurred.

The Assistant Secretary of War for Cyber Policy made a fabulous analogy when pressed on the struggles regarding resourcing in the cybersecurity industry: you don’t want a pediatrician performing heart surgery. This drives an excellent point in that cybersecurity teams around the world lack the granular specializations needed, especially in this AI moment, to protect against the sophisticated threats being unleashed by cybercriminals. Overall, however, the keynotes felt like a party-political speech for the forthcoming mid-terms.

The conference highlights for me included the numerous discussions on the fast-growing numbers of vulnerabilities being uncovered in current or past software with the help of AI, as well as the detailed insight delivered by the OpenAI team into the Hugging Face incident.

The main takeaway for me is a view that I have mentioned in various presentations of my own in the past few months and that was also conveyed by several presenters at Black Hat. One of them, David Weston from Microsoft, said, in summary, that AI agents authenticate, invoke tools, and inherit permissions in the same way a human employee does, but without the oversight, policy and governance needed to make them accountable.

This message is an important one. We talk about autonomous AI attacks and how AI did something, but behind AI are humans setting the tasks and guardrails. The technology is within our control, and we need to take full responsibility for it. If it’s not under control, there is a simple solution: switch it off and re-task it with the correct controls in place to hold the technology, and the humans behind it, accountable.