Skip to main content

Black Hat 2026 Trends: What Security Teams Should Do Next

What Black Hat revealed about AI agents, identity security, privileged access, and the controls security teams should review now.

Segura | Team

September 23, 2026 | 6 minutes read`

In this article
    Monthly newsletter

    No spam. Just the latest releases and tips, interesting articles, and rich materials in your inbox every month.

    What Security Leaders Saw at Black Hat 2026 

    AI was everywhere in Las Vegas.

    On vendor booths. In sessions. In security products. In attack research. In the questions CISOs and security teams were asking.

    After spending the week at this year’s Hacker Summer Camp, Joseph Carson and Edu Pereira unpacked the biggest Black Hat 2026 trends in Segura’s webinar, “The Black Hat 2026 Briefing: Translating Las Vegas’s Biggest Reveals into Action.”

    They came back with a more useful question than What’s trending?

    What should security teams do differently now?

    Across Black Hat, BSides, and DEF CON, the same issues kept surfacing in booth conversations, technical sessions, and hallway discussions: finding AI agents, understanding their access, reducing standing privilege, and keeping accountability when agents act on their own.


    Key Highlights

    - AI agents are becoming an identity problem.
    Teams want to know where agents live, what permissions they have, and which credentials they use.

    - Discovery kept coming up.
    Edu said finding and managing AI agents was a consistent question throughout Black Hat.

    - Standing privilege gives agents more room to act.
    Just-in-time access and clear authorization are becoming more important.

    - Accountability is still unresolved.
    Teams need to know who approved an agent, what identity it used, and who owns the outcome.


    The Question Security Teams Kept Asking: Where Are the AI Agents?

    Joseph counted more than 84 AI-native vendors on the Black Hat floor. AI showed up in SOC tools, penetration testing, supply chain security, governance, automation, and autonomous workflows.

    But some of the most useful conversations had very little to do with the booth signage.

    Edu spent the event talking with hundreds of people at the Segura booth. He said one of the most common questions was how security teams are supposed to keep track of AI agents as the numbers grow.

    “One engineer can handle… more than 200 agents. One person has more than 200 agents out there. So how do we know all this? How do we discover all this? Where are those agents? … How can we find those agents? How can we manage those agents?”

    The problem starts with visibility. Security teams need to know which agents exist, where they run, which identities and credentials they use, what they can access, and who owns them.

    Black Hat 2026: What to Act on Now

    Infographic mapping six AI agent changes to security team actions, titled What to Act on Now.

    Agentic AI Makes Privileged Access More Urgent

    Agentic AI changes what happens after a user gives AI a task.

    Traditional generative AI often returns an answer. An agent can receive an objective, choose how to complete it, use available systems, and take action.

    Joseph described conference sessions where speakers shared examples of agents moving outside their intended workflows, including attempts to obtain credentials or access systems.

    “Some of the companies that were doing sessions… [talked about] agentic AI that they’re deploying themselves [that] has become rogue and started actually stealing credentials and getting access to systems… It is looking to gain access to data, and it is abusing its privileges.”

    His takeaway was simple:

    “We shouldn’t be giving AI agents too much access. They should be getting back to just-in-time privilege.”

    IBM’s 2026 Cost of a Data Breach research found that roughly 1 in 5 organizations reported an AI-related breach, and 92% of those organizations lacked proper AI access controls. 

    Before an AI agent gets production or privileged access, security teams should be able to answer these eight questions:

    1. Where does the agent run? Identify the host, cloud environment, application, or platform.
    2. What identity does it use? Determine whether it acts through a user account, service account, workload identity, or dedicated agent identity.
    3. What can it access? Document the applications, APIs, systems, and data in reach.
    4. What credentials can it use? Identify tokens, secrets, service accounts, and privileged credentials.
    5. Who approved the access? Tie permissions to a named owner, team, or approval workflow.
    6. How long does the access last? Know whether it is persistent, time-bound, or just-in-time.
    7. Can we stop it quickly? Make sure access can be revoked and the agent can be disabled or quarantined.
    8. Who owns the outcome? Assign a person or team responsible for the agent’s behavior.

    If your team can’t answer one of these quickly, that’s a good place to start investigating.

    Serpentine flow chart outlining 8 key questions for reviewing AI agent access before production.

    AI Agent Discovery Needs Ownership and Accountability


    Discovering AI agents is only part of the problem. Teams also need to understand what identity it uses, what access was delegated, how long it exists, and who owns the actions it takes.

    Joseph said accountability became one of the biggest topics in his hallway and dinner conversations:

    “Accountability was probably one of the biggest topics when it comes to agentic AI agents… What identity did it use to do that type of access? What types of credentials or privileges does it have? … Who does this tie back to from an accountability and governance perspective?”

    The lifecycle matters too. Some agents may run for months. Others may exist for a few seconds, complete one task, and disappear.

    Security teams still need an audit trail that answers:

    • Who created it?
    • Who authorized it?
    • Which identity did it use?
    • What did it access?
    • What did it change?
    • When did its access end?

    Short-lived agents still leave business impact behind.

    Just-in-Time Access Limits What AI Agents Can Do


    AI agents make standing privilege harder to justify.

    Joseph repeatedly returned to just-in-time access, authentication, authorization, and guardrails during the webinar.

    The model is straightforward:

    Give the agent the access required for the task. Give it when the task starts. Remove it when the task ends.

    That reduces the amount of privilege available if the agent misunderstands context, reaches outside its intended workflow, or uses an exposed credential.

    Edu put the credential issue plainly:

    “It starts with the credentials, always.”

    For security teams, this connects AI agent security directly to work they already understand:

    • Vault privileged credentials
    • Reduce standing access
    • Rotate secrets and tokens
    • Require authorization
    • Monitor privileged activity
    • Remove access after the task

    Zero Trust for AI Agents Comes Down to Everyday Controls


    Zero trust was much less visible in Black Hat booth messaging this year, but the principles were still there.

    Joseph described zero trust as an operating practice:

    “Zero trust is not something you implement. It’s something you practice. It’s a mindset on how you operate your business in a secure way.”

    For AI agents, that means applying familiar access controls.

    Zero Trust Controls for AI Agents

    Infographic outlining 5 Zero Trust controls for AI agents, from authentication to auditability.

    Joseph also connected zero trust to continuous authentication, continuous authorization, just-in-time elevation, and least privilege.

    For AI agents, those controls answer the questions security teams care about most: Who is acting? Is this action allowed? How much access does the agent have? And when should that access end?

    What Security Teams Should Do After Black Hat 2026


    You do not need to turn every conference trend into a new project.

    Focus first on the access, ownership, and control issues that came up repeatedly in the webinar:

    1. Find the AI agents already in useIdentify where they run, who owns them, and which identities they use.
    2. Map their accessCheck applications, APIs, credentials, tokens, service accounts, and production permissions.
    3. Reduce standing privilegeGive agents only the permissions required for the task.
    4. Use just-in-time access for high-risk actionsShorten how long privileged access remains available.
    5. Assign accountabilityEvery agent needs an owner and a clear record of who authorized its access.
    6. Set production boundariesDefine which actions require human approval and how teams can stop an agent.
    7. Keep the audit trailRecord what the agent accessed, changed, and delegated.

    Start with the agents already in use, then tighten the access and controls around them.

    Watch the Webinar: Hear What Didn’t Fit in the Recap


    In the webinar, Joseph and Edu go deeper into what they heard at Black Hat, what practitioners were worried about, and where they think security teams should focus next.

    Watch “The Black Hat 2026 Briefing: Translating Las Vegas’s Biggest Reveals into Action” for their full discussion of:

    • The questions practitioners asked them most often
    • Agents going outside their intended scope
    • AI as both a defensive tool and an attacker accelerator
    • Accountability for persistent and short-lived agents
    • What zero trust looks like around AI
    • Audience questions on evaluating and governing AI agents

    Find and Control the Identities Behind AI


    The AI agent questions coming out of Black Hat are identity questions:

    What exists? What can it access? Who authorized it? How long does that access last?

    Segura helps teams discover identities, control privileged access, reduce standing privilege, protect credentials, and maintain an audit trail across human and machine access.

    See how those controls can help you reduce the access available to AI-driven workflows.

    Segura | Team

    Segura: Futureproof Identity Security

    Segura, #1 in Privileged Access Management, trusted worldwide for fast, simple & powerful PAM solutions, ranked top by Gartner Peer Insights.

    Full Bio and articles ›

    Request a Demo or Meeting

    Discover the power of Identity Security and see how it can enhance your organization's security and cyber resilience.

    Schedule a demo or a meeting with our experts today.

    • 70% lower Total Cost of Ownership (TCO) compared to competitors.

    • 90% faster Time to Value (TTV) with a quick 7-minute deployment.

    • The Only PAM solution available on the market that covers the entire privileged access lifecycle.