Black Hat

Black Hat 2026: 6 qualities security pros should look for in agentic AI systems

stunning futuristic background featuring "agentic ai" on a glowing circuit board. ideal for tech, ai, and innovation projects. high-resolution image perfect for websites, presentations, and more.

COMMENTARY: The doors of the Business Hall at Black Hat USA 2026 have just opened and it’s clear that there’s one topic on everyone’s mind: Agentic AI.

This was obvious as soon as I boarded my flight to Las Vegas. A couple of passengers seated across from me started talking about Black Hat, DefCon, what they do, and which vendors they represent.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

Let’s face reality, AI is no longer just another security tool. It has become the newest attack surface, the newest identity, and gradually, the newest administrator with massive unknown risks.

Frankly, I expect to see AI everywhere at Black Hat this year. Conversations I’ve already had with fellow conference attendees and industry colleagues has led to the understanding that agentic AI has not not just become another evolution in middleware: it’s a revolution in automation that can accelerate businesses and introduce cybersecurity risk all in one motion. It’s a fundamental shift in how decisions are made, actions are executed, data analysis gets performed, and identity and trust is delegated inside an organization.

Don’t think of agentic AI as passive solution. On the contrary, it can plan, reason, orchestrate, and perform automated actions at machine speed. In doing so, it introduces a new reality for governance and cybersecurity leaders. Every agent becomes an identity, every identity becomes a potential path to privileged access, and every action from a data query to simple automation becomes a privilege escalation opportunity if left unchecked.

The technology industry has spent decades designing open models of interoperability. APIs connect everything, identities federate across boundaries, and access gets granted to enhance productivity. The concept of an open security model breaks down completely with agentic AI because of unmanageable risk. When autonomy increases, so does risk. We don’t want to slow down adoption, but rather enclose attributes, authentication, privileges, and identities that create risk. Here’s where a closed security model becomes essential.

The risk does not exist in the first place because in lieu of offering access by default, we must explicitly add access. A closed security model does not mean isolation from innovation, it means intentional constraint. It means every identity, agent, process, connection, and decision operates within a tightly governed and continuously verified boundary.

In the context of agentic AI, this model represents the difference between controlled autonomy and unavoidable exploitation. This entire paradigm starts with identity. Security pros should look for agentic AI systems to:

Rely heavily on non-human identities (NHIs) to interact with infrastructure, data, resources, and other AI based agents: These identities are often over-provisioned, poorly tracked, and rarely audited with the same rigor as human users. That’s the first failure point. In a closed model, every agent must have a unique, verifiable identity with strict authentication controls, that includes, no shared credentials, no embedded secrets, and no static keys. All identities must be ephemeral, dynamically issued, and continuously validated.

Require access to perform tasks, but access should never imply initial or implicit trust: The principle of least privilege doesn’t cut it alone in this context. We need just-in-time privilege access management with zero standing access. An AI agent should only receive the exact entitlements it needs for the exact duration of a given task, and nothing more, and once we complete the task, access gets revoked automatically. Every action should have immutable logs and reauthenticate each time for accountability. Without it, every agent becomes a long-lived attack vector.

Thrive on interconnected workflows that can cross electronic boundaries within an organization: One agent calls another, data flows between resources, and decisions cascade across systems that create implicit trust chains that threat actors can exploit. A closed security model enforces strict segmentation between agents, workloads, data domains, and the identities that can authenticate across them. We have to make communications explicitly allowed, inspected, and logged and denied by default. There’s no implicit trust between agents, even if they are part of the same system and in even in the same segment.

Consist of guardrails that are enforceable, not just defined in written policies: It’s about human control and having humans in the loop for sensitive operations. Security controls and application guardrails need to operate in line with decision making processes, not after the fact. If an agent attempts to execute an action outside of its defined parameters, we have to block, alert, and have human escalation immediately. Here’s where many organizations make a critical mistake. They treat AI governance as a compliance exercise. It’s an operational control plane that determines whether our environment remains secure or becomes compromised based on actions performed in a rapidly- evolving digital world.

Built on models, data sources, plugins, open-source code, and external integrations: Each of these introduces risk and a closed security model requires strict validation of every dependency. We must vet models, use trusted data sources, and authenticate and authorize integrations at every interaction point. If we do not control the inputs, we cannot trust the outputs. Here’s where we have to secure and vet supply chain management for models, open-source libraries, and third-party updates to mitigate the risks from any third-party malicious interference.

Offers a kill switch. It's non-negotiable in this architecture. If an agent begins to behave unpredictably or maliciously, we must have an immediate and automated way to revoke its identity, terminate its sessions, isolate its access, and roll back any actions that are a liability to the business. It’s not a theoretical scenario. Adversarial manipulation, prompt injection, and model drift are real risks and without a kill switch, you are relying on detection without response, which is effectively no control at all.

Finally, organizations must treat agentic AI as a workforce. Like any workforce, it requires governance, oversight, ownership, management, funding, and accountability. We would not give an employee unrestricted access to our most critical systems without controls. The same logic applies here, but with significantly higher stakes because of the scale and speed in which access and data exfiltration can occur.

Today’s harsh reality requires all organizations to embrace a Secure-by-Design philosophy for agentic AI and a closed security model from the start of every new AI-related project. The organizations that understand this next phase of digital transformation will succeed.

Morey J. Haber, chief security advisor, BeyondTrust

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds