Section Insights
Introduction to Black Hat USA 2026
Why is the Black Hat conference significant in the current cybersecurity landscape?
The Black Hat conference serves as a vital platform for cybersecurity professionals, researchers, and policymakers to address vulnerabilities, share knowledge, and innovate in response to evolving threats. It emphasizes the interconnectedness of various sectors in tackling cybersecurity challenges.
- Cybersecurity challenges are universal and affect all sectors.
- The conference fosters collaboration among researchers, defenders, and policymakers.
- AI is rapidly changing the dynamics of cyber operations.
- The importance of community engagement in advancing cybersecurity practices.
The Role of AI in Cybersecurity
What fundamental questions arise regarding cyber power in the age of AI?
As AI transforms various sectors, it raises critical questions about the nature of cyber power and the alignment of state, private, and public sectors in addressing these challenges. The conversation aims to explore how to leverage AI responsibly while ensuring cybersecurity.
- AI is reshaping national security and the cyber landscape.
- Collaboration between sectors is essential for effective cybersecurity.
- Understanding cyber power in the context of AI is crucial for future strategies.
- The need for open dialogue about the implications of AI in cybersecurity.
Balancing Innovation and Security
How can we balance the need for innovation with cybersecurity?
To balance innovation and cybersecurity, it is essential to foster open collaboration between industry and government, ensuring that regulatory frameworks do not stifle growth. A flexible approach that allows for rapid adaptation to technological advancements is necessary.
- Regulatory frameworks must be adaptable to keep pace with innovation.
- Collaboration between government and industry is key to responsible AI deployment.
- A proactive approach to cybersecurity can prevent stagnation in innovation.
- Information sharing is crucial for addressing emerging threats.
Proactive Cybersecurity Strategies
Why is a proactive approach to cybersecurity important?
A proactive cybersecurity strategy is essential to anticipate threats and shape adversary behavior. By establishing deterrence and working closely with industry, the government can better prepare for and respond to evolving cyber threats.
- Proactivity in cybersecurity provides a strategic advantage.
- Understanding emerging technologies and threat actors is critical.
- Establishing deterrence can discourage potential cyber adversaries.
- Collaboration with industry enhances government insight into cybersecurity challenges.
Future of AI and Cybersecurity
What steps can be taken today to prepare for the future of AI in cybersecurity?
To prepare for the future, it is important to address existing vulnerabilities, move away from legacy systems, and incentivize the development of technologies that can remediate issues at machine speed. Continuous innovation and adaptation are key to staying ahead.
- Addressing legacy issues is crucial for future cybersecurity resilience.
- Incentives for rapid technological advancement can enhance security.
- Innovation must be prioritized to tackle emerging cybersecurity challenges.
- The intersection of AI and cybersecurity presents both opportunities and risks.
Transcript
0:29 >> warning tonight about the scope of a massive cyber attack >> already believed to be the largest >> America under virtual invasion >> Please welcome to the Black Hat main stage, the president of Black Hat, Susie Pallet.
1:28 >> Good afternoon. Before we begin, I want you to consider something. Right now, in this room, we have researchers who've discovered vulnerabilities that could affect millions. We have defenders protecting critical infrastructure. We have entrepreneurs building the next generation of security tools. We have policy makers shaping the rules that will govern cyberspace for years to come. And somewhere out there right now are attackers, maybe our ones, trying to break what you've built. A researcher is finding a flaw no one else has seen. A team is responding to an incident that could change everything.
2:10 That's the world we live in. That's why we're here. And that's why Black Hat matters. Welcome to Black Hat USA 2026. For nearly three decades, this community has been where the most important conversations in cybersecurity happen. Not because of the venue, not because of the technology, but because of you, the community of leaders, researchers, practitioners, and innovators who show up, share what you've learned, challenge what we think we know, and push this industry forward.
2:47 The challenges we face today don't respect boundaries. They don't care if you work in government, in a Fortune 500 company, or in a startup. AI is reshaping attack and defense at a pace we've never seen before. Cyber operations are influencing global events in real time, and critical systems are more interconnected and more vulnerable than ever. And the foundations of identity and trust are being rewritten. Here's what we know. No single sector can solve these problems alone.
3:21 The most effective defense happens when everyone, state, private, and public sectors work together. When researchers share findings, when industry builds solutions, and when governments create frameworks that enable innovation to protect citizens, and when all of us learn from each other. That interconnection, that collaboration, is what makes Black Hat unique. It's what makes this community so vital. This year's program reflects that reality. You'll hear from researchers presenting groundbreaking work. You'll see emerging startups showcasing breakthrough ideas at our global spotlight competition.
4:00 And you'll engage with experts across the AI zone, the arsenal, the lab, and spaces designed for hands-on learning and real conversations. But the truth, the most important things that happen at Black Hat don't always happen on the stage. They happen when a researcher shares a finding that changes how someone thinks about a problem. They happen when states sit down with industry and realize they're solving the same challenge from different angles. They happen in the hallway, in the late-night debates, and the moments when someone says, "Wait, what if we tried this instead?"
4:36 That's the power of this community. So, as we kick off this week, I want to encourage you to engage. Ask the hard questions, share what you've learned, challenge assumptions, including your own. Make the connections that will matter long after you leave Las Vegas, because the future of cybersecurity won't be built by one person, one company, or one government. It will be built by all of us working together, learning from each other, and refusing to accept that the problems we face are unsolvable.
5:07 To start us off, we're beginning with a conversation that sits right at the center. As AI transforms everything from national security to economic competitiveness to the cyber landscape itself, we're facing a fundamental question. What does cyber power look like in the age of AI? And how do we ensure that state, private, and public sectors are aligned in answering it? To explore that question, we're honored to welcome a leader working at the intersection of policy, strategy, and cybersecurity at the highest levels of government.
5:38 Someone whose work directly influences how we think about those challenges and how we respond to them. Please join me in welcoming Shawn Carberry Cross, National Cyber Director at the White House, and moderator Misha Glaser, Chief Executive Officer of Reflection to the stage. >> >> Thank you, Susie. All right. Well, it's great to be here.
6:10 It's a It's an incredible production. I think as a first of both first time at Black Hatters and I'm I'm Misha. I'm the CEO of Reflection. We build open models, American open models. and today I'm fortunate enough to moderate a conversation with our National Cyber Director, Cairncross. Director Cairncross, thank you for being here. >> Th- Thank you for doing this, Misha.
6:40 thank you for all the work and engagement that Reflection AI has had with our office and in shaping what we're doing on a national strategic level, and thanks to Black Hat for having me. This is tremendous. And thanks everyone in the audience for the time and attention. >> So, we we have a lot to cover here. There are a lot of cybersecurity experts, CISOs, and otherwise in the audience. would it be fair to say Director Cairncross that you are the CISO of America?
7:11 >> I I I think it is in a way. If If it works, Misha, just to cover the office for a second because it is relatively new on the scene. This was an office that was created at the end of the first Trump administration. And the design of the office had always been to bring a national a single point of policy coordination to cyber. This hasn't happened in the the This is a domain that had grown up adjacent to a lot of different others, but had never been thought of as how do we use this to lever other strategic ends for the United States, and how do we use the tools at our disposal to leverage strategic ends in this space? What are we trying to get done?
8:00 And so, we've been asking those questions, and in doing so, I I'd say we're happy to talk about the strategy or things that we are doing to implement on on that, but the big picture is twofold. The first is we want to make sure that we are working hand in glove and collaboratively with industry, and that comes right from the President of the United States. We're We're more than aware that the innovators in this crowd are going to do more to protect the country and move this ball forward than government could ever do on its own.
8:36 So, that's thing number one, and we've we've made a tremendous effort to try to engage industry in in that design. And the second piece is working collaboratively with our colleagues across the interagency. I know you're going to hear in a in a few minutes from FBI and DoD and and CISA, but we work with Brett and Katie and Nick. We work with them all all the time, and they are vital to achieving In fact, without them, we we can't achieve our strategic goals in this space. And I think everyone has begun talking to one another in new ways both on the intergovernmental side and and between government and industry, and I think it's exciting exciting thing to be a part of.
9:22 well, thank you thank you so much for for your service, and it's been great working working with you in you know, this moment in time where we are all living through what I've been in AI research for some time for what we call the kind of exponential, right? The rate at which the capabilities are increasing is both spectacular and alarming. Every month, there's a new cyber capability that comes online. And so with that in mind, right? We are at once we're trying to protect and secure our country, but also stay ahead of our adversaries. So, how do you think about that tension between needing to do what we what we need to do to stay ahead of our adversaries while at the same time protecting the American innovation economy, but also not compromising on cybersecurity?
10:12 >> Of course. Well, I think it's worth taking a step back and sort of talking about how we got here, at least recently, and the step function change in artificial intelligence model capability. It's a tremendous story of American innovation. It's a huge success story. It's going to have enormous benefits for for our society, for our country, for the world, medical, cybersecurity, taking leaps that we hadn't thought possible before. So, this hasn't this conversation hasn't kicked off in earnest because of some catastrophic breach. This has been a very positive story. So, to lead with that and say the real answer your question, how do we make sure we use this responsibly, we deploy it securely, we get it into the hands of the people who need it at speed, it really is having an open collaboration with industry. To your point, this is moving at such speed and at such pace, a regulatory regime one would not only strangle growth, development, and innovation, and be enormously harmful to the industry, but it would be obsolete but hours after it was going through whatever process it had gone through.
11:35 And so what needs to be built is a flexible, adaptable structure that enables information sharing between industry and government. so this so we can guarantee that this technology benefits everyone it's going to benefit but is used responsibly and securely. >> But when we think about this technology having kind of wide benefit both in America and and globally, you know, a lot of the technology, right, has been was invented by companies in in this country and got us to where where we are today.
12:15 But today there's I'd say the one of the things in the eye of the storm is the increasingly capable open models coming from our adversaries. And I'm curious what your thought is about the role of open source AI as it plays in the cyber ecosystem in America. >> I think the role that open source plays is vital to this to this ecosystem is the answer. I think there is a role for proprietary models to serve and there is a tremendous role for open source to serve. And we are extremely interested in looking at ways to build US open source, make it competitive, make it the adopt the preferential adoption by planet Earth for US open source is really our our goal. And we understand and appreciate the value to the ecosystem that it has, the innovation, the startups who rely on it, the the leap forward it makes possible in ways that otherwise would never happen. And so, I think it's a it's a incredibly thriving ecosystem in AI right now.
13:37 And we are looking to do what we can to, like I say, grow, foster, and push that US open-source model. >> I mean, I I think that I I definitely agree, right? You want to win by by merit. You want to just have be building the best open models, the best technology, and ensure that that cuz ultimately both domestically and and abroad, like customers will just want, like, the best technology at the sort of every model size.
14:06 >> Yeah, look, at its core, this is an American technology. It's an American innovation. We lead the world in this. We lead the world throughout the tech stack. This is no different, and we want to do everything we can to support that and make sure that that drives forward in the future to expand to expand US companies and innovators their access to to markets abroad, but also the uptake by our allies and partners to increase their defensive capabilities.
14:40 >> I I think this moment in time that we're living through where we are in the exponential, AI is progressing so quickly is I'd say also matched by this administration's kind of dynamic posture in terms of right, being kind of on the offense of thing about cyber and regulation around the stuff. why is that why is that important to you? Why is that a priority? >> I think it's you're either on your heels or or you're on your toes. And if you are trying to get ahead something, if you're anticipating where things are going, I think that gives you an advantage. And I think that sets and in order to do so, you've got to work with industry.
15:25 Sitting in Sitting in an office in government doesn't give you the exposure you need to be able to think through Here are the problem sets that are coming. Here is the latest technology that's coming. Here is the threat actors that are evolving that we may or may not have insight on. But many folks in this audience and you do. And so, having that relationship is, is important. In terms of leaning forward strategically the strategy that we put in place in, in March the lead piece of that is shaping adversary behavior. And what that really means, when you boil it right down is introducing the concept of deterrence in this space. I understand it's a tricky concept in this space. But at the end of the day, the speed and the technology that is moving on the attack side makes it, a critical moment in time to ensure that those who may seek to do us harm know that it is not going to be cost free.
16:35 And the same day that the president signed the strategy into place, he signed into place a an executive order on cyber crime designating ransomware actors and scam centers transnational criminal organizations. And that has allowed us to bring new authority and and, working groups together in government to get at the at this problem in a real way. And I happy to let the next panel talk a little bit more on it. But the FBI, and law enforcement have had Operation Riptide moving, which has taken a dent into this space, making sure that we are denying safe haven, taking down infrastructure, and making life very difficult online and then denying them the benefits of of their actions. Taking the money back.
17:26 and so that is a that's a significant focus of ours and we are going to keep pressing forward on that and there's there's a lot more to come. And you note in that executive order the private sector is talked about explicitly and looking for ways that we can work together with you to gain insight on things that you are seeing and capabilities that you have that that can be useful in achieving that end. >> So speaking speaking of the the executive order but it seems like it's kind of a collaboration between multiple parties within the government to understand kind of how to regulate this this technology that has both immense positive but also you know dangerous applica- implications if not used properly.
18:14 Can you talk about the importance of the cyber perspective in shaping the administration's >> Sure. Well well the first thing I'd say is is the executive order is designed to be non-regulatory but to put in place a system to work with industry to ensure that this is that these that this technology is handled responsibly. And so what we've seen it and we've had tremendous industry engagement which is been a very gratifying thing to see.
18:49 Everyone is working towards the same goal in terms of protecting the country and securing our systems. and we are trying to ensure that defenders have this technology as quickly and at scale as possible. But there are obviously specific security concerns and and industry has been very sensitive to this as well and it's been an ongoing collaboration that has evolved at speed and will continue to. We've been implementing that executive order and and like I say, look forward to making sure those partnerships are in a great place moving forward. And finally, this is a relationship between government and industry that I don't think has existed before. It's largely thanks to the direction it is and thanks to the direction of the President of the United States.
19:42 And the design of this is when there is something that that happens, when there is a breach, when there is an event, that that system of then that network of connections can can exist, adapt to that, and seek to remedy that as quickly as possible. So, that form follows function rather than turning that upside down and and you know, as usual with the government government pen just proceeding proceeding in a vacuum.
20:15 So, I think that, you know, we've right now as we think about the EO and and kind of regulation of these models, we're thinking about the world locally as it is today and right recently we celebrated the 250th anniversary of of this nation. As you're and I mean, I don't know. And maybe I'm not saying we'll be eating paper clips in 250 years, but right maybe if if if if we don't do our jobs right, maybe that's that's what we all do to us. But thinking of the next 250 years kind of ahead, what do you think we can, you know, as we're thinking about the future, we can just be doing today as it pertains to this intersection of AI cyber to set ourselves up in a strong position in the decades to come? Yeah, well, look, I think we we've seen these models don't necessarily create new problems, but they bring a lot of latent problems to the surface, things that hadn't been tended to in a long time. And so, I think I think taking care of those issues, moving forward from legacy systems, is is great. But, what hasn't happened before is there wasn't an incentive for technology that that remediated at machine pace.
21:34 And so, now there is such an incentive, and that technology We're excited about that. There's technology, I think, that will be coming online sooner rather than later that will start to address that. Which is to say, in answer to your question, the best thing moving forward is to continue to innovate, to continue to run at speed. That is the way these problems are solved. It's solved I will said it before, I'll say it again, it's solved by the people sitting in the chairs in the audience, far more than it is by someone making policy in Washington D.C. And so, we have to be able to ensure that the security equities are in place, but that innovation is running full speed ahead.
22:22 Because, at the end of the day, the American innovator is going to be is is going to provide technology that's going to be beneficial to the entire planet. It will secure our country, and it will it will improve the lives of our citizens. I I believe that firmly, and I see nothing changing in the next 250 years. >> Yeah, I I share your kind of net, I think, positive thinking about this tremendous technology that's to come.
22:54 In In our last minute, I wonder, what do you think that members of the audience, the various security experts, CISOs, and so forth can be doing to help us you know, help guide us into this future. >> Yeah, well the first thing is it's boring and not sexy, but fix the basic stuff. Get it to the top of the boardroom and make it a priority. E- Every enterprise, every every infrastructure sector needs to take care of the low-hanging fruit and they need to do it at speed.
23:28 And that is that is the number one thing and I'm sure everyone's sitting in the audience saying, "Yeah, we do this day in and day out. That's been That's been >> >> It's been my my life." But we're here to do whatever we can to raise that priority and bring attention to it. We've made a hard push across sectors to put this on CEOs' desks so that it is a priority priority number one for their system. So, it what I would say to all of you and anyone else listening is our office loves engagement. It we will be responsive. We love hearing hearing what you think is working and certainly need to hear what you think isn't or where you need support.
24:17 So, pick up the phone and call if if anything i- if you've got a question on something, an idea on something, or I'm saying something that you think doesn't make sense. We want to hear from all you. >> Well, I think that puts us at time. Thank you so much, Director Karen Cross, for for your service during this critical time and for being here with us in Vegas today. >> That'll do it. It's a pleasure to be here. Thank you, everybody.
24:49 >> Thank you.
Summary
- Cybersecurity challenges are increasingly complex and require collaboration across government, industry, and academia.
- AI is reshaping both cyber attacks and defenses, necessitating rapid adaptation and innovation.
- The U.S. government aims to work closely with the private sector to leverage innovation for national security.
- The National Cyber Director's office focuses on policy coordination and strategic goals in cybersecurity.
- Open-source AI plays a vital role in the cybersecurity ecosystem, fostering innovation and competition.
- The government is implementing a non-regulatory executive order to ensure responsible AI deployment while encouraging industry collaboration.
- Basic cybersecurity practices must be prioritized by organizations to mitigate vulnerabilities effectively.
- Engagement between cybersecurity experts and government is crucial for addressing emerging threats and enhancing national security.
Questions Answered
Why is the Black Hat conference significant in the current cybersecurity landscape?
The Black Hat conference serves as a vital platform for cybersecurity professionals, researchers, and policymakers to address vulnerabilities, share knowledge, and innovate in response to evolving threats. It emphasizes the interconnectedness of various sectors in tackling cybersecurity challenges.
What fundamental questions arise regarding cyber power in the age of AI?
As AI transforms various sectors, it raises critical questions about the nature of cyber power and the alignment of state, private, and public sectors in addressing these challenges. The conversation aims to explore how to leverage AI responsibly while ensuring cybersecurity.
How can we balance the need for innovation with cybersecurity?
To balance innovation and cybersecurity, it is essential to foster open collaboration between industry and government, ensuring that regulatory frameworks do not stifle growth. A flexible approach that allows for rapid adaptation to technological advancements is necessary.
Why is a proactive approach to cybersecurity important?
A proactive cybersecurity strategy is essential to anticipate threats and shape adversary behavior. By establishing deterrence and working closely with industry, the government can better prepare for and respond to evolving cyber threats.
What steps can be taken today to prepare for the future of AI in cybersecurity?
To prepare for the future, it is important to address existing vulnerabilities, move away from legacy systems, and incentivize the development of technologies that can remediate issues at machine speed. Continuous innovation and adaptation are key to staying ahead.