Contributing Analyst: Brian Maroney
AI is quickly becoming your best employee, your fastest analyst, and potentially your next insider threat. The question for executives isn’t whether your company will use it. It’s whether you’ll maintain control once it does.
Walking through Black Hat USA 2026 in Las Vegas, it was hard to miss where cybersecurity is heading.
AI was everywhere.
That’s hardly surprising. We’ve spent the last few years hearing that AI would transform cybersecurity, business operations and just about everything else.
But Black Hat 2026 felt different.
The conversation is moving beyond companies simply using AI. We’re entering a period where organizations are beginning to give AI authority.
Authority to access information.
Authority to investigate.
Authority to communicate with other systems.
Authority to make decisions.
And increasingly, authority to act.
For executives, that’s where the conversation needs to change.
This isn’t just another technology trend for the security team to figure out.
It’s a business risk discussion.
Your Best Friend and Your Worst Enemy
There’s a good reason companies are moving toward AI so aggressively.
Speed.
Security teams have spent years drowning in information. Thousands of alerts, millions of logs and an expanding collection of security products all generating more data than humans can realistically process.
AI changes that equation.
An investigation that once required an analyst to jump between several platforms can increasingly be assembled in seconds. Endpoint activity, identity events, network telemetry, threat intelligence and historical behavior can all be brought together before a human analyst even opens the case.
That’s a huge advantage.
Every minute saved during an investigation is another minute an attacker doesn’t have to move laterally, steal information, deploy ransomware or disrupt operations.
For executives, this is where AI can provide real value.
It’s not about replacing analysts.
It’s about giving your existing security team the ability to operate at machine speed.
But there’s a catch.
The same technology accelerating your defenders is accelerating everyone else too.
Attackers have access to AI as well.
Agentic AI Changes the Equation
Most executives are familiar with generative AI by now.
Agentic AI is where things get more interesting.
Traditional automation follows instructions.
If this happens, do that.
Agentic AI can potentially determine what needs to happen next.
A security agent might receive an alert, investigate the affected identity, query an endpoint platform, examine network activity, pull threat intelligence, review historical behavior and determine whether containment is appropriate.
The technology starts moving from assistant to participant.
That’s incredibly powerful.
But the moment AI can take action inside your environment, you’ve created something executives should understand very clearly: a new privileged identity.
Organizations have spent decades building controls around privileged employees and administrators.
Least privilege.
Access reviews.
Separation of duties.
Privileged access management.
Logging.
Approval processes.
Yet many companies are connecting AI platforms to sensitive corporate systems faster than they’re developing governance around those connections.
That’s where the risk begins.
AI Could Become Your Next Insider Threat
When executives hear “insider threat,” they usually think about people.
A malicious employee.
A compromised administrator.
Someone accidentally sending information somewhere it shouldn’t go.
AI changes that definition.
An AI system doesn’t need malicious intent to create insider-level risk.
It simply needs access.
Imagine an AI assistant connected to email, cloud storage, customer information, internal documentation and several business applications.
Each connection might make perfect sense individually.
Together, they create something extremely powerful.
Now ask a few uncomfortable questions.
Who approved those permissions?
Who reviews them?
What information can the AI retrieve?
What other systems can it communicate with?
Can it take actions?
Are those actions logged?
Can security teams identify when its behavior changes?
And most importantly:
Who owns the risk?
If the answer isn’t immediately clear, that’s a governance problem.
Companies shouldn’t wait for an AI-related breach before deciding who is responsible for AI security.
Trusted APIs May Become Trusted Attack Paths
There’s another part of the AI boom that deserves executive attention: APIs.
AI becomes exponentially more useful when it’s connected to other systems.
CRM platforms.
Cloud environments.
Email.
Security tools.
Ticketing platforms.
Financial applications.
Internal databases.
Those connections are frequently established through trusted APIs.
The problem isn’t necessarily that any individual platform is insecure.
The problem is transitive trust.
Your organization trusts Platform A.
Platform A trusts an AI service.
The AI service communicates with Platform B.
Platform B has access to sensitive information.
Attackers don’t always need to compromise the most protected system directly. They look for the easiest path through the trust relationships surrounding it.
As AI agents become connected to more business systems, those relationships become increasingly valuable targets.
An API token or integration account may not look particularly exciting on a risk dashboard.
But if that credential allows an AI agent to communicate with five other systems, its actual blast radius could be enormous.
Executives need visibility into those relationships before attackers map them first.
Behavior Is Still King
For all the new technology appearing across Black Hat, one of cybersecurity’s oldest ideas may become one of its most important.
Behavior matters.
A legitimate account can be compromised.
A legitimate API can be abused.
A legitimate AI agent can perform an illegitimate action.
Everything can authenticate correctly and still be wrong.
That’s why organizations need to understand what normal behavior looks like across users, machines, applications, APIs and now AI agents.
Did that service account suddenly start accessing different information?
Did an AI agent begin querying systems outside its normal workflow?
Did an employee account authenticate normally but immediately start behaving differently?
Did a trusted integration suddenly increase the volume or type of information it’s retrieving?
Those individual events might not trigger a traditional signature.
Behavior tells the larger story.
In an environment where identities and applications increasingly operate autonomously, behavioral analytics isn’t becoming less relevant.
It’s becoming foundational.
Speed Is Now a Business Metric
The cybersecurity arms race is increasingly becoming a race against the clock.
Executives already measure revenue, growth, customer acquisition, operational efficiency and dozens of other business metrics.
Cybersecurity needs to be viewed through a similar lens.
How quickly can your organization detect something unusual?
How quickly can you determine whether it matters?
How quickly can you contain it?
And how quickly can you recover?
Attackers are automating.
Defenders are automating.
AI is accelerating both sides.
That means a security program that requires hours to investigate something an attacker can exploit in minutes has a fundamental problem, regardless of how much money was spent building it.
The organizations that succeed won’t necessarily have the biggest cybersecurity budgets or the largest collection of tools.
They’ll be the organizations capable of turning information into decisions faster than their adversaries can turn access into impact.
Governance Can’t Be the Speed Limiter
There’s an understandable reaction to all of this:
Slow AI adoption down.
That’s probably not realistic.
Employees are already using it.
Vendors are embedding it into products.
Security teams are adopting it.
Business units are connecting it to workflows.
Trying to completely stop AI adoption could create another problem: shadow AI.
The better approach is to build guardrails capable of moving at the same speed as adoption.
Know what AI systems are operating inside the company.
Know what they’re connected to.
Know what information they can access.
Know what actions they can perform.
Apply least privilege.
Monitor their behavior.
Log their actions.
Have a way to revoke access quickly.
And establish executive ownership of the risk.
AI governance shouldn’t exist solely to tell people what they can’t do.
Good governance should allow organizations to use AI aggressively without losing visibility or control.
The Question Has Changed
The question coming out of Black Hat 2026 isn’t:
“Should we use AI?”
That decision has effectively already been made.
The better questions for executives are:
What authority have we given it?
What systems have we connected it to?
What happens if that trust is abused?
How quickly would we know?
And finally:
Can we shut it down without shutting down the business?
AI may become one of the greatest force multipliers cybersecurity has ever seen.
It can help small teams operate like much larger ones. It can reduce investigation times, correlate enormous amounts of information and allow defenders to respond at speeds humans simply can’t match.
But every capability we give it also creates responsibility.
Black Hat 2026 made one thing very clear: cybersecurity has entered the fast lane.
AI is your best friend.
AI can be your worst enemy.
And without proper governance, it might become the most trusted insider you never hired.
The accelerator is already down.
For executives, the job now is making sure someone still has their hands on the wheel.


