Agentic AI security tests enterprise defenses as scale outpaces strategy
Cybersecurity leaders are confronting an inflection point as agentic AI security becomes the defining challenge of this year’s threat landscape, with attackers and defenders racing to harness autonomous tools at unprecedented speed and scale.
That urgency was on full display during the first day of Black Hat USA 2026, where autonomous AI agents dominated briefings and hallway conversations alike. As agents move into production and gain access to sensitive systems, the need for new governance models is colliding with a market still figuring out how to operationalize control, according to Jon Oltsik (pictured, left), principal analyst in residence at theCUBE Research.
“Certainly it’s unprecedented in terms of scale and speed,” Oltsik said. “I’m starting to hear from people it’s a manageable problem — but you have to go into it with strategy and intelligence and the right balance of people, process and technology. I don’t think a lot of companies are doing that, but those that are are managing.”
Oltsik and theCUBE Research’s Krista Case (right) wrapped up day one coverage of Black Hat USA, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how enterprises are navigating agentic AI security, identity governance and cyber resilience amid a fast-moving threat landscape. (* Disclosure below.)
Identity emerges as the control point for agentic AI security
Beyond the hype cycle, practitioners are zeroing in on identity as the critical layer for managing autonomous agents. Static entitlements no longer suffice when an agent can improvise its way toward a goal.
“If you ask an agent to do a task, it’s going to do whatever it needs to do or whatever it can do to accomplish that task,” Oltsik said. “Some of that may be rogue behavior. That’s where I think identity — non-human identities, agentic identities — that’s the challenge, and it’s not static; it’s very dynamic.”
Visibility must come before any control layer can work, Oltsik noted, describing the process as sequential rather than simultaneous — organizations first need to know what agents exist and what they touch before they can govern them. That discipline extends to resilience, where CISOs face pressure to prove systems can keep operating even after a breach.
“We have to be much more sensitive to where the human in the loop takes place,” Oltsik said. “We have to guide this technology. We have to understand this technology. But humans are still necessary to make decisions, and will be.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Black Hat USA:
(* Disclosure: TheCUBE is a paid media partner for Black Hat USA. Sponsors of theCUBE’s event coverage do not have editorial control over content on theCUBE or SiliconANGLE.)