Black Hat Preview: AI Security and Agent Risk
Black Hat Sets the Stage for AI Security
Alan Shimel and Mitch Ashley preview Black Hat in a special episode of Still Cyber. The conversation looks at how the security industry is changing. AI is moving deeper into software development, cloud operations and daily work. They expect Black Hat to highlight a key question for security teams. Organizations are putting AI into production quickly. Many are still building the governance, identity and risk controls needed to manage it.
AI Is Changing Vulnerability Management
The discussion explores how AI security could reshape vulnerability discovery and remediation. Shimel points to the rise of tools that can find far more vulnerabilities than traditional approaches. That creates a new challenge. Many teams already struggle to fix the vulnerabilities they know about. If AI increases the volume of findings, security teams may need new ways to prioritize risk. They also need better ways to reduce noise and focus on issues most likely to cause real-world breaches.
Agentic Workflows Need Stronger Controls
Ashley and Shimel also discuss the emerging agentic work surface. AI agents can interact with cloud platforms, data stores, code repositories and business workflows. That makes identity, access control and least privilege more important. The hosts argue that organizations need to manage AI agents more like human identities. They also need fine-grained controls that limit what agents can access and what actions they can take.
Black Hat Is Still About People
The episode also reflects on the community side of Black Hat. Shimel and Ashley talk about hallway conversations, reconnecting with longtime industry peers and meeting practitioners who are working through these challenges directly. They also note that cybersecurity is broader than the CISO role. Engineers, analysts and practitioners still play a major role in shaping what products should do and how security programs actually work.
As Black Hat approaches, the episode frames AI security as both a technical and organizational challenge. Security teams need better visibility, stronger governance and more practical controls for agents, vulnerabilities and cloud environments. They also need input from the people doing the work every day.

