Black Hat USA 2026 ran August 1 through 6 in Las Vegas this year, days of training, briefings, presentations, and of course, the vendor showroom, that drew cybersecurity professionals and enthusiasts from across the industry. This year’s event spotlighted how quickly AI has moved from a nice to have pitch to the operational center of the security conversation, alongside enduring priorities like cloud security and identity as organizations build more of their business on AI and cloud technologies.
Orca Security was at the center of these conversations, engaging with customers, partners, and industry leaders to share insights and strategies for securing what teams are building today. Through countless interactions on the expo floor, in briefing sessions, and at networking events, our team of experts uncovered valuable lessons and trends shaping the future of cloud, code, and AI security.
As the dust settles on this year’s event, here are the key takeaways that stood out to us.1. AI agents are everywhere, but the conversation has moved from “does it have AI” to “does it act safely”
Every vendor conversation on the show floor touched AI in some form, but the tone was different this year. Nobody needed convincing that AI brings both incredible opportunities for improvements and efficiencies, but also introduces risks that require new approaches to securing it. The real question on everyone’s mind was whether it can be trusted to act on its own.
That shift showed up clearly in the briefings and conversations on the trade room floor. Researchers demonstrated how AI agents themselves are becoming attack targets, from credential exfiltration to hijacked shopping assistants, and containment was a headline topic in its own right. Multiple sessions dug into sandbox escapes for agentic systems.
The message was consistent. Giving an agent access to your environment is easy, but making sure it safely stays inside the lines you drew for it is a growing challenge.
2. Governing AI agents is turning into a growing conversation, fast
It’s not that agent governance is a new category so much as it’s becoming an urgent, budgeted priority. Customers are asking how to identify, secure, govern, and put guardrails around the agents that are already running in their environments, with or without their approval, and the industry response this week showed it. New agent-specific controls launched across the show, from access limits that cap what an agent can touch and when it needs human approval, to identity-based microsegmentation built specifically for non-human actors.
Security teams aren’t asking whether they need to govern their AI agents. They’re asking how they can do it, and how quickly it can be implemented.
3. AI is playing offense and defense at the same time, and legacy AppSec tooling is struggling to keep pace
Attackers are using AI to find and chain vulnerabilities faster than most teams can patch them, and defenders are doing the same thing in reverse, using AI assisted tooling for threat hunting and investigation. But the more interesting thread was what’s happening upstream, in the code AI is writing. Coverage from the show pointed out that many existing scanning tools still carry high false positive rates and often miss the context of a scan, which means AppSec teams are inheriting more review work, not less, especially as AI accelerates how much code ships.
The problem isn’t the AI writing the code. In fact, it’s incredible how much faster code can be written and shipped now, and how people without any coding background can build and ship things of their own. The problem is that the tools reviewing that code need to keep pace, with the same speed, context, depth, and accuracy the moment demands.
4. Attack path and business risk are eclipsing raw CVE counts
A recurring theme throughout the conference was that nobody wants another list of vulnerabilities ranked by severity score alone, especially as the sheer number of findings organizations are sitting on keeps climbing every year. The industry is converging on attack path analysis, tying findings to what’s actually reachable and what actually matters to the business, over simply counting CVEs. This has been Orca’s argument for years, and it was good to see the industry rally around the same idea.
5. Cloud fundamentals and government policy shared the stage with AI
For all the AI headlines, some of the most consequential research this year had nothing to do with agents. One standout, a chain of flaws in a major cloud provider’s automation service that could have let an attacker seize another tenant’s identity and reach into their data and workloads, entirely by exploiting a misconfiguration, not a model. It’s a reminder that cloud misconfiguration and identity risk are still very much live problems, AI or not.
Government took the keynote stage in a way we haven’t seen before, too, with senior cyber officials speaking together on coordinating offensive and defensive operations and defending critical infrastructure. Between that and the ongoing conversation about ransomware disruption, the show made clear that the fundamentals, cloud posture, identity, infrastructure, still set the floor everyone else builds on.
Where Orca fits into all of this
For Orca, one of the most exciting parts of Black Hat 2026 was seeing how closely our own roadmap lines up with what customers and the broader industry are asking for. As our team talked through AI AppGen Security, Code Security Auditor, and Attack Surface Red Agent, and how each ties back into a shared risk prioritization engine, customers responded with real excitement and recognition. They saw their own challenges reflected back at them, and that kind of alignment felt like more than good timing.
These conversations were never just about the technology. They were about building real partnerships rooted in trust, collaboration, and a shared goal of making the cloud a safer place to build. As we look to what’s next, we’re energized by the momentum from this show and committed to keep pushing the Orca Platform forward for the customers who’ve put their trust in us.
Deep. Accurate. Actionable. Security for the companies that build.
Book a meeting with our team
