Black Hat 2026: The AI Conversation Is Growing Up

Randy Watkins, CTO & Co-Founder

Last year at Black Hat, security leaders wanted to know what AI could do. This year, they wanted to know what it should be trusted to do.

Black Hat is one of my favorite conferences because it gives me a chance to see where the security industry is investing and how different companies are approaching the problems security teams are facing. I love walking the expo floor, seeing new technologies, and understanding where organizations are placing their bets. Just as valuable are the conversations with CISOs and other security leaders about what they are seeing inside their own environments and where they are focusing their roadmaps in the coming years.

Same theme, different conversation

The expo floor also tends to develop a pretty obvious theme every year. This year, just like last year, that theme was AI. The difference was that the conversation around AI felt considerably more mature. Last year, most organizations were still trying to understand what AI could do for security operations. Vendors were racing to introduce new capabilities, buyers wanted to see the latest technology, and there was a general sense that AI might fundamentally change how security teams operated.

Over the last year, organizations have had time to actually experience these platforms, test them against real environments, and understand where the technology works well and where it still falls short. That experience changed the questions and sentiment heard at Black Hat. Instead of asking what AI could do, more security leaders were asking where the humans were involved, how AI output was being validated, and how much autonomy the technology should really have.

Security leaders are asking about the humans

That was especially evident in conversations at the Critical Start booth. A number of customers and prospects came by specifically wanting to understand how we were using AI in security operations. They wanted to know who validates an investigation, who determines whether an escalation is legitimate, whether AI can take containment actions, and what controls exist when the AI gets something wrong. Several people had already experimented with AI-driven security operations platforms and were uncomfortable with the level of autonomy being proposed. Others had seen their MDR providers become more aggressive about using AI to reduce analyst involvement and felt they had experienced a degradation in detections, investigations, or escalations as a result.

Key distinction Augmenting an analyst is not the same as replacing an analyst. That distinction is becoming increasingly important as AI takes on more of the repetitive investigation work in security operations.

Security operations contain an enormous amount of repetitive investigation work, and AI is very good at collecting context, querying multiple systems, correlating information, following investigation procedures, and summarizing what it finds. Those capabilities can materially reduce investigation time and make analysts far more effective. The risks increase considerably when AI moves beyond investigation and starts making consequential decisions or taking actions on its own. AI models are still probabilistic, and they can misunderstand context, make incorrect assumptions, or confidently arrive at the wrong conclusion.

Gartner is seeing the same shift

This also lines up closely with what Gartner has been saying about the future of security operations. At Gartner SRM earlier this year, Pete Shoard described the analyst role increasingly shifting from manually performing every investigation to validating investigations performed by AI. Gartner research also showed that a majority of surveyed organizations viewed AI SOC agents as augmenting human decision making rather than replacing it, with many expecting human validation, governance, and approval to remain part of the process. Gartner's 2026 Hype Cycle for Security Operations placing AI SOC agents at the peak of inflated expectations felt particularly relevant walking the Black Hat floor.

The industry clearly believes AI will have a significant role in security operations. The end state, however, is not likely a completely autonomous SOC operating without meaningful human oversight. The consequences are too significant when you move from generating an investigation summary to isolating a production server, disabling an executive's account, deleting email, or resetting credentials. Those actions require much more confidence, governance, and accountability than simply asking an LLM to determine whether an alert looks malicious.

Augmenting analysts, not replacing them

At Critical Start, we've intentionally taken the approach that AI should augment our SOC analysts rather than quietly replace them. SOC AI performs and accelerates investigation work, while an analyst validates the investigation and verdict before escalation. Response capabilities are also explicitly controlled instead of giving an LLM unrestricted access to response APIs. That approach may sound less exciting than claiming a fully autonomous SOC, but the conversations at Black Hat suggest it is much closer to what security leaders actually want.

From "what can AI do?" to "what should AI do?"

AI was still everywhere at Black Hat this year, but the market seemed noticeably less interested in the novelty of AI and much more interested in how it should actually be used. The conversation is moving away from asking what AI can do and toward the much more important question of what we should actually trust AI to do. That feels like progress.