Cybersecurity hands AI the controls at Black Hat USA 2026
For years, artificial intelligence in cybersecurity was largely presented as an assistant. It could summarise an incident, correlate suspicious activity or help an analyst search through thousands of alerts. The human operator remained firmly in control.
At Black Hat USA 2026, the Cybersecurity Conference held in Las Vegas from 1 to 4 August, that distinction began to blur.
Across the conference, cybersecurity companies unveiled AI systems designed to investigate alerts, test applications, reconstruct attacks, restrict access and implement fixes. While the language varied (there was talk about agentic security, autonomous response, closed-loop remediation, among others) the direction was consistent. AI is moving from advising security teams towards performing parts of their work.
Black Hat itself reflected that change. Its 2026 programme included a dedicated AI Summit and a new AI Zone where visitors could examine emerging cyber threats and defensive tools. AI now occupies both sides of cybersecurity: it gives attackers faster ways to find and exploit weaknesses while offering defenders the prospect of responding at comparable speed.
The underlying argument is persuasive. A cyberattack can spread across cloud services, identities and endpoints in minutes. Human analysts cannot manually examine every alert before deciding what to do. But giving software authority to isolate computers, revoke credentials or alter production systems introduces another risk: what happens when the autonomous defender is wrong?
SentinelOne moves towards an autonomous security operations centre
SentinelOne provided one of the clearest examples of the industry’s changing ambitions. At Black Hat USA 2026, it announced what it calls governed, closed-loop response across its Singularity security platform.
Its Purple AI system is designed to investigate alerts, assemble evidence and reach a verdict. Singularity Hyperautomation can then execute a response, such as isolating an affected device or containing a threat. Security teams determine in advance which actions the system may take independently and which require human approval.
The distinction between this approach and earlier security automation is important. Security orchestration, automation and response platforms have long allowed companies to create rule-based playbooks. If a predetermined event occurs, the software follows a predetermined sequence.
SentinelOne says Purple AI can instead choose its next step according to what it discovers during an investigation. In other words, it is intended to exercise a limited form of judgement rather than simply follow a static decision tree.
The company emphasises that actions remain governed by pre-approved policies, with activity recorded for later review. Its wider automation platform also supports rollback for certain response actions. Those safeguards are as revealing as the autonomous capabilities themselves. SentinelOne is effectively acknowledging that speed alone will not persuade businesses to trust AI with operational control.
Horizon3 lets AI attack first
While SentinelOne is applying autonomous AI to cyber defence, Horizon3 is using it to imitate the attacker.
Shortly before Black Hat, the company expanded its NodeZero autonomous penetration-testing platform to web applications. According to Horizon3, the system can test applications running in production, demonstrate which vulnerabilities can actually be exploited and follow attack paths across applications, cloud infrastructure, data and identity systems.
Traditional vulnerability scanners can produce extensive lists of theoretical weaknesses. Security teams must then determine which ones expose something valuable and which are unlikely to be exploited. Horizon3 wants NodeZero to perform more of that work itself.
For example, the platform could begin with a web application flaw and establish whether it leads to control of a host, access to corporate data or movement into another part of the network. The output is intended to show not only that a weakness exists, but what an attacker could achieve with it.
The commercial momentum behind autonomous penetration testing is notable. During Black Hat, Horizon3 announced a $250 million Series E funding round at a valuation of more than $2 billion. The technology is moving beyond experimental cyber ranges and into a serious enterprise cybersecurity market.
However, allowing an automated system to behave like an attacker inside a live environment requires carefully designed limits. Horizon3 describes NodeZero WebApp Pentesting as “production-safe”, but that claim will ultimately depend on how the system performs across complex customer environments.
AI agent security becomes a new cybersecurity category
Black Hat’s product announcements also revealed a second emerging market. Businesses are not only deploying AI in their security teams; they are introducing autonomous agents throughout their operations.
Those agents may read documents, call software tools, access customer records and make changes across connected systems. If an AI agent is manipulated through prompt injection, supplied with malicious data or granted excessive permissions, it can become a route into the organisation while operating with legitimate credentials.
Varonis introduced Agent Intent-Based Access Control to address that problem. The capability, part of its Atlas platform, compares an AI agent’s behaviour with the task it was originally assigned. It can evaluate data access, tool calls and activity across an entire session, rather than assessing each action in isolation.
If an agent begins acting outside its instructions, Atlas can flag or block the behaviour. Varonis says organisations can also route selected actions to a human for approval or temporarily quarantine the identity associated with a suspect session.
Several other Black Hat cybersecurity launches approached the same problem from different directions. Zero Networks presented controls intended to restrict which systems AI agents can reach and when additional authentication is required. Sweet Security said its new blocking capabilities can stop unauthorised tool calls and terminate agent sessions at runtime. Acalvio unveiled decoys and honeytokens designed to expose agents that have been compromised or manipulated.
Collectively, these releases suggest AI agent security is becoming a distinct cybersecurity category. The old principle of least privilege—giving a person or application only the access required for a task—is being adapted for software that can interpret instructions and decide how to carry them out.
Cyble brings hardware-backed trust to endpoint security
Cyble’s latest version of Titan adds a different layer to the story. Rather than relying entirely on evidence reported by an operating system, the endpoint security platform uses what Cyble calls silicon-rooted attestation to establish whether a computing environment can be trusted.
The problem it addresses is real. Endpoint detection and response software collects activity from the operating system and kernel. But if an attacker has already compromised that foundation, the telemetry supplied to the security tool may be incomplete or deliberately misleading.
Cyble says Titan combines hardware-backed attestation with endpoint activity, threat intelligence, behavioural analytics and BlazeAI-powered attack reconstruction. The intention is to build a more complete picture of a cyberattack and support an autonomous but auditable response.
Hardware-backed attestation itself is not new. Trusted Platform Modules, Microsoft Pluton and Measured Boot already allow organisations to verify aspects of a device’s integrity. Cyble’s potential distinction lies in incorporating attestation evidence directly into a broader endpoint detection, attack reconstruction and response workflow.
Some of the technical claims still require clarification. Titan’s website references AMD SEV-SNP, Intel TDX and Arm CCA; these are technologies primarily associated with trusted execution environments and confidential computing. Meanwhile Cyble also describes Titan as an endpoint security platform for Windows, Linux and macOS.
That does not necessarily mean the same attestation mechanism is available on every device or operating system. Cyble will need to explain which hardware configurations support the feature, precisely what is measured and how its architecture differs between physical endpoints and virtualised environments.
Artiphishell focuses on verifiable remediation
Artiphishell, which describes its technology as backed by the US Defense Advanced Research Projects Agency, focused on another obstacle to autonomous cybersecurity: proving that an automated fix has worked.
Its Verifiable Remediation technology is designed to filter false positives, establish whether a reported software vulnerability can be exploited, identify possible variations of the attack and deliver a proposed remediation. It then produces evidence intended to demonstrate that the underlying weakness has been addressed.
This is important as generating a patch is not the same as resolving a vulnerability. A change can close one attack route while leaving variants open, or disrupt the software it was intended to protect. If AI is to participate in vulnerability remediation, verification must become part of the same process.
Artiphishell’s announcement does not yet provide independent evidence of how reliably the platform performs across production software. Nevertheless, its emphasis on verifiable outcomes addresses one of the most important weaknesses in automated cybersecurity: the gap between taking action and proving that the action worked.
Autonomous cybersecurity still needs boundaries
The repeated emphasis on human approval, policy controls, audit trails, rollback and verification shows where autonomous cybersecurity still lacks trust. Vendors may be handing AI more of the controls, but they are also constructing increasingly elaborate guardrails around it.
The question after Black Hat USA 2026 is no longer simply whether AI can participate in cybersecurity operations. It is how much authority organisations are prepared to give it, and how they will know when it has made the wrong decision.
Liked this article? You can support our independent journalism via our page on Buy Me a Coffee. It helps keep MoveTheNeedle.news focused on depth, not clicks.
👉 https://buymeacoffee.com/movetheneedle.news