
At Black Hat USA, cybersecurity executives highlighted that as AI accelerates attack speed—with threat handoff windows collapsing from eight hours to 22 seconds—organizations must shift from preventing every disruption to ensuring they can quickly restore essential operations to a trusted state.
The emerging challenge is governing autonomous agents and securing data across hybrid environments at scale, requiring new approaches to identity visibility, software safety, and shared context between security and engineering teams.
What happened
At Black Hat USA, cybersecurity leaders discussed how AI is reshaping enterprise defense. The Mandiant M-Trends 2026 report showed attackers can now move from initial access to handing off to a secondary threat group in just 22 seconds in 2025, down from more than eight hours in 2022. The conversation has shifted from preventing every breach to understanding which operations are essential and whether they can be recovered quickly to a trusted state.
Why it matters
As attack windows compress beyond human response capacity, organizations must rethink security from prevention-only to resilience. This includes managing autonomous agents with dynamic identities and behaviors, securing data across hybrid environments before scaling AI to production, and breaking down silos between security and engineering teams. For enterprises deploying AI systems, the governance and visibility challenges are now as critical as the technology itself.
What to watch
Three practical shifts are emerging: memory-safe software construction and formal verification to catch vulnerabilities before production; unified telemetry between security and engineering teams to identify shared root causes; and machine-scale agent oversight tools (such as Rubrik Agent Identity, which governs access one tool call at a time) that don't rely on manual approval at scale.
Ask the AI about this article →
The core theme of Black Hat USA 2025 reflects a fundamental reset in how enterprises should think about cybersecurity: as AI accelerates both attack speed and the scale of operations, the old model of prevention-as-defense is no longer sufficient. The compression of response windows—from hours to seconds—means human-led security operations cannot match attacker velocity. Instead, the discussion has moved to resilience: understanding minimal viable operations, detecting and responding to breaches quickly, and recovering to a trusted state.
This shift intersects with three emerging operational challenges. First, autonomous agents introduce a new identity and access control problem: these systems have dynamic behaviors and make real-time decisions based on permissions that were designed for static human users. A system authorized to access both Salesforce and email may lack the judgment to recognize that transferring data between them would be unsafe. Second, AI-driven vulnerabilities lower the cost of exploitation, making traditional patching cycles insufficient; the defense must move upstream to safer software construction (memory-safe languages, formal verification) and downstream to faster detection via shared telemetry between security and engineering. Third, moving AI from pilot to production requires data governance at scale—discovery, encryption, and policy enforcement across hybrid clouds, on-premises systems, and shadow IT—because organizations often lack visibility into where data lives and how models were trained.
The common thread is visibility and context. As Krista Case put it, the key is understanding "what our minimal viable operations look like" and having "confidence that we're able to recover them quickly and confidently to that trusted state." None of this is purely technical; it requires breaking down silos between teams, extending asset discovery to include non-human identities and the models that run on them, and building governance frameworks that can scale oversight beyond manual approval.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
A UK study by UK AI Security Institute and Limbic AI surveyed 6,474 British adults

Broadcom's Clayton Donley says companies are doing mission-critical work with AI agents quickly, but without t…
Bank of England governor Andrew Bailey warned that advanced AI poses risks to financial infrastructure in a le…
As AI agents perform real business tasks, 'Agentic Identity' (giving each AI a unique employee-like ID) and 'D…

Andrew Bailey, head of the world's financial stability watchdog, warned in a letter to G20 finance ministers a…

Fortinet announced the acquisition of Virtue AI, a move aimed at expanding its AI security capabilities
