Black Hat USA 2026: AI Security Spending Booms, but Skills Gaps Remain
Black Hat USA 2026 recap: agentic SOC tools, AI supply chain exploits, and why AI still isn't replacing skilled security professionals.

Black Hat USA 2026 in Las Vegas drew a wave of heavily funded agentic security startups competing for CISO attention, with AI supply chain exploits from Anthropic, OpenAI/Hugging Face, and Meta dominating hallway conversations. New products from Dropzone AI, Nebulock, Huntress, Strike 48, Certiv, and Geordie AI all addressed the same core problem: how to give AI agents enough autonomy to be useful inside a security operations center without making the attack surface dramatically worse.
What happened
| Detail | Fact |
|---|---|
| Event | Black Hat USA 2026, Las Vegas |
| Hot topic | AI supply chain exploits and agentic SOC tools |
| Incidents cited | Anthropic Mythos-class escape exploits, OpenAI/Hugging Face attack, Meta supply chain incident |
| Strike 48 integrations | More than 300 MCPs (model context protocol connectors) |
| Huntress platform reach | Hundreds of thousands of customers including service providers and mid-sized companies |
This year’s Black Hat confirmed what many in the industry have suspected: AI-enabled security is attracting serious capital, but the vendor claims outpace the evidence. Guest columnist Jason English, writing for SiliconAngle, described the show floor as a “bandwagon of million-dollar booths for overfunded agentic security startups” rising like mirages from the Nevada desert.
The concrete incidents driving CISO anxiety were real, though. Three separate AI supply chain attacks came up repeatedly: escape exploits tied to Anthropic’s Mythos-class models, a joint OpenAI/Hugging Face incident, and Meta disclosing its own similar event. Patrick Duffy, head of product at Dropzone AI, framed why these attacks are hard to catch: “There’s just a lot more code and traffic generated within a quicker time period, which can hide abuses.” Dropzone announced its new AI Threat Hunter product at the show.
Who is building what in the agentic SOC
Several vendors showed distinct approaches to putting AI agents inside security operations centers (SOCs), the teams that monitor and respond to threats around the clock.
- Nebulock builds a behavioral world-model graph of an enterprise, overlaying existing SIEM and IT security tools. Its agent fleets can be triggered by new CVEs, patches, or a plain-language analyst request.
- Huntress Labs runs a 24/7 managed platform. Its agentic investigator, called Athena, is built from specialized subagents that compile signals, run investigations, and write incident reports. If Athena is not confident in a finding, the case goes straight to a human analyst. “We’re definitely still hiring them,” said Aimee Simpson, director of product marketing.
- Strike 48 offers a broad SecOps platform connecting SOC, network operations, and DevOps workflows through more than 300 MCP connectors. Larger customers can work with Strike 48’s forward-deployed engineers to build custom agents.
- Dropzone AI specifically targets the investigation bottleneck: human teams cannot run a thousand parallel investigations simultaneously, but AI agents can.
The pattern across all four is similar: AI handles volume and initial triage, humans handle judgment and escalation. Nobody at the show was seriously claiming AI would make security analysts redundant. The skills shortage in cybersecurity makes that outcome structurally unlikely regardless of how capable agents become.
Why does it matter for businesses running AI tools?
The supply chain attacks highlighted at Black Hat are not just problems for large enterprises. Any business using AI models hosted on platforms like Hugging Face, or running third-party AI agents inside their stack, inherits some of this risk. The nondeterministic behavior of AI models (meaning the same input can produce different outputs) makes traditional rule-based security controls harder to apply.
Three vendors at the show addressed this directly by extending established security practices to cover AI agents:
- Zero Networks announced enforcement of the OWASP Least Agency Principle for enterprise AI. Its microsegmentation approach, already used for cloud infrastructure on Azure, AWS, and GCP, now wraps a protective boundary around AI agents the same way it does for servers and workstations.
- Certiv focuses on behavioral and intent monitoring. Its CEO Jason Needham summarized the risk plainly: “Agents can be your best worker, and your worst worker, and your adversary, all at the same time.”
- Geordie AI takes a discovery-first approach with its Beam solution, finding every agent running across an enterprise, mapping what it does, and identifying who is responsible for it. CTO Benji Weber noted that the trend toward giving agents more autonomy is “only increasing this year.”
For teams already thinking about AI integration inside their business, these frameworks are worth watching. The governance gap between “we deployed an AI tool” and “we know what that tool is doing on our network” is where most of the risk lives.
Our take
Black Hat 2026 read like a classic hype cycle with a real problem underneath it. The money flooding into agentic security is real, the AI supply chain exploits are real, and the shortage of qualified security staff is real. But a lot of the vendor pitches on the show floor are solving the same problem with slight variations, and the category will consolidate.
The more useful signal for business operators is narrower: if you are running AI agents in any workflow, whether a customer-facing chatbot or an automated workflow connecting your tools, you probably do not have clear visibility into what those agents can access or what they do when something goes wrong. The vendors at Black Hat are building tools for enterprise security teams, but the underlying principle applies at any scale. Know what your agents can touch, and limit it.
The one claim thoroughly punctured at the show is also worth remembering: AI automation has not replaced professional security expertise, and the evidence from this year’s incidents suggests it will not any time soon. That should inform how you evaluate any AI vendor promising to run your operations autonomously.
What to do about it
- Audit every AI agent or AI-connected tool in your stack and document what data and systems each one can access.
- Apply least-privilege access controls to AI agents the same way you would for a new employee: start with minimal permissions and expand only when needed.
- Check whether any of your AI tools pull models or weights from public repositories like Hugging Face, and verify those sources against known vulnerability disclosures.
- If your business uses a managed security provider, ask specifically how they handle AI agent activity in their monitoring and incident response workflows.
Follow our ongoing AI news coverage as this category evolves quickly heading into late 2026.
Frequently asked questions
What were the main AI security topics at Black Hat USA 2026?
AI supply chain exploits and agentic SOC platforms dominated the show. Three specific incidents were widely discussed: Anthropic Mythos-class escape exploits, an OpenAI/Hugging Face attack, and a similar Meta incident.
Is AI replacing security analysts in SOC teams?
No. The consensus at Black Hat 2026 was that AI agents handle volume and initial triage but human analysts remain essential for judgment, escalation, and strategic decisions. Vendors like Huntress said they are still actively hiring human analysts.
What is the OWASP Least Agency Principle for AI?
It is a security principle that limits the permissions and access an AI agent is granted to the minimum needed for its task, reducing the damage possible if the agent is compromised or behaves unexpectedly. Zero Networks announced enforcement of this principle for enterprise AI at Black Hat 2026.
What is microsegmentation and why does it matter for AI agents?
Microsegmentation is a security practice that places tight network boundaries around individual assets like servers, workstations, or cloud resources. Vendors at Black Hat 2026 are now extending this to AI agents to limit what they can access and communicate with, reducing exposure from nondeterministic agent behavior.


