Interviews | July 14, 2026
Security Teams Should Treat AI Agents as High-Privilege Identities
Elastic | Mind.Io | Reco.ai | XBOW
Q1. You recently suggested that organizations relying on standalone SOAR are falling behind. Why is that the case? What operational benefits are customers seeing from consolidation that they cannot achieve with standalone SOAR?
Standalone SOAR should never have existed as a permanent category. Security automation belongs inside the SIEM, where the detections and the data live, and it always did. SOAR emerged because large vendors failed to innovate as quickly as security needs changed, and smaller startups did what startups do: they filled the gap. That instinct was right. The industry's mistake was what came next. Instead of absorbing automation into the platform where it belonged, we hardened a stopgap into a separate product with a separate line item. A feature became a category, and the category outlived its reason for existing. Per-endpoint pricing that forces customers to ration their own visibility follows the same pattern: structures that serve vendor revenue instead of the defender's mission.
Customers paid for that architecture twice. Once in dollars, and again in the integration barrier of keeping two products stitched together, with dedicated engineers whose full-time job became building and feeding playbooks and connectors.
The architecture also has a speed problem no integration can fix. The evidence sits in one system, and the action sits in another, and every handoff between them is latency. Average eCrime breakout time is down to 29 minutes, and the fastest recorded is 27 seconds. A static playbook waiting for an alert to be forwarded, parsed, and matched was built for yesterday's pace of attack.
When automation is native to the platform, the response is informed by the full investigation rather than a thin alert payload passed over a wall. Detections carry dynamically generated runbooks, and when alerts correlate into a single attack, those runbooks merge into one coordinated response with the evidence attached. The customer holds the autonomy dial. The benefits are what you would expect when you remove an unnecessary product from the middle: less plumbing, faster detection to action, and automation the team can explain to leadership.
Q2. Where do you see organizations actually succeeding with agentic security ops today? Where is the gap between the marketing and the operational reality?
Start with the person this is supposed to help. Analysts today sit eight to ten hours in a queue of alerts that are all marked critical, that they can never get through. It is a search for a needle in a stack of needles. The clearest success in agentic security operations is replacing that queue of alerts with a queue of work: AI handles the triage, the correlation, and the evidence assembly at machine speed, and the analyst reviews proposals and reasoning instead of raw alert noise. That works today, in production. Investigations that took days compress into minutes, and agentic triage is now table stakes. Every serious vendor ships some version of it.
The gap opens the moment someone says "autonomous SOC." I do not believe in a people-less SOC, and I think it is the wrong goal entirely. You would not let a junior analyst handle a major incident completely unsupervised, and the same applies to AI agents. They earn elevated actions the way a new analyst does: by being right repeatedly while a human checks the work. Trust is a dial, not a switch. Vendors promising customers can remove the humans are asking them to bet their environment on a demo.
Transparency is the other tell. If a team cannot inspect how the system reached its conclusion, healthy skepticism is the correct reaction. The hype also misses what matters most: done right, AI brings more people into security, not fewer. One of the best SOC analysts I ever worked with started as a meteorologist. Sharp analytical minds have been kept out by tooling that demanded years of vendor-specific knowledge. AI removes those barriers. That is the difference between a feature and a mission.
Q3. Elastic has used Black Hat as a venue to showcase its vision for the future SOC. What do you hope to demonstrate at Black Hat USA 2026?
We are showing the SOC evolving two of its operational tiers at once. The first is a major leap in tier-one AI triage. We're bringing two things together at Black Hat. Attack Discovery already correlates alerts into attack narratives so analysts stop drowning in a queue where everything reads "critical", and we're now extending it with an agentic flow of skills and workflows that reasons across the evidence and carries each narrative further into the investigation. Alongside it, we're introducing a new agentic alert-triage workflow that sorts real alerts from noise at machine speed. Together they turn triage from a queue of raw alerts into a queue of work, each item arriving with its evidence and reasoning already attached. Investigations that took days compress into minutes, and the analyst reviews conclusions instead of assembling them.
The second is a debut: a tier-three agentic hunting workflow. Threat hunting is a specialist craft, and most teams either cannot hire for it or have hunters buried under other work. This workflow continuously reads hundreds of intelligence sources, including the unstructured ones where new tradecraft surfaces first, extracts the discovery, builds the hunt, runs it against live data, and delivers findings as a complete package with detection rules drafted to cover the gap going forward. All of it lands in front of a human with the evidence attached. It puts a craft that was once reserved for the best-funded SOCs within reach of every team, and when a CISO asks whether the organization has seen a new threat and whether it is impacted, the answer becomes instant instead of a two-week project.
The larger story is the operating mode. The SOC is evolving from a queue of alerts into a queue of work, with the autonomy dial in the customer's hand and the analysts as the decision makers. Help, not hype.
Q1. You've warned that AI agents can broadly move sensitive data across systems without malicious intent. Why is this a problem? What should enterprise security teams be doing to address the issue?
Most agent-driven data exposure has no attacker behind it. An agent inherits a user's permissions, picks up sensitive data while completing a task and drops it somewhere with weaker controls, all in seconds. Our research found 68% of security leaders can't determine what their agents are accessing. Nearly a third have unknown agents already operating in their environment. Security teams should start with the data itself. Discover where sensitive information lives and classify it, then fix the exposure before an agent finds it. Enforcement has to run at the speed agents move, because manual review can't keep up.
Q2. From your vantage point, what separates organizations that are finally making data protection work from those still treating DLP as a compliance checkbox? Where do you think the market is headed over the next two to three years?
The teams making it work treat data protection as an engineering problem. They know what data they hold and who or what can reach it. Fixing exposure is part of their normal operations. The checkbox crowd writes policies nobody enforces, and that gap shows in AI adoption. Our research found nine in ten organizations have given broad data access to enterprise GenAI, yet only 1 in 5 AI projects meet their intended KPIs. The missing ingredient is data trust. That's where the market goes next. Over the next two to three years DLP becomes autonomous. Classification and enforcement will run continuously at machine speed. That's what earns the data trust rapid AI advancement depends on.
Q3. What does Mind plan on highlighting at Black Hat USA 2026? What can attendees expect by way of announcements, presentations, product demonstrations, or broader messaging around the company's priorities?
The headline at Black Hat is the expansion of our Autonomous DLP Analyst, which takes on the most time-consuming tasks in data security and runs them autonomously. Today it builds classifiers and investigates issues. At the show we're adding skills that write policies and remediate exposure risk. Another evaluates whether a policy override is justified. Every skill will also be interactive via MCP from whatever AI chat system you already use, so day-to-day data protection gets simpler while coverage gets more complete. That holds no matter who or what is accessing the data. You'll see it live at Booth 4527. The message behind the demos is the one our research keeps confirming. AI advancement depends on continuously earned data trust.
Q1. AI is increasingly getting embedded into everyday workflows with access to enterprise systems like CRM, email, etc. What should security leaders be doing differently to ensure real-time governance and control?
Most security teams are tracking AI tools at this point, but they're not tracking AI agents. Those aren't the same thing.
Salesforce has agents. ServiceNow has agents. GitHub Copilot is running agents in your codebase right now. The exposure isn't just at the tool level. It's at the agent level too, and most teams don't have visibility there.
Real-time governance comes down to three things, done continuously. Discover every agent before you try to secure it. Prioritize the ones with real blast radius instead of chasing every alert. Remediate with precision instead of broad lockdowns. It's the same discipline we built for SaaS apps.
Q2. You've noted how agent risk lives in the apps, identities, and workflows an agent touches, and not in the agent itself. So, how should an organization approach agent security? Who owns the risk?
Let’s use Claude running with MCP connectors in an enterprise as an example. It has access to Notion, Slack, GitHub, email, calendar, CRM. And is executing tasks across all of them on behalf of various users, often without IT knowing the connections exist. Nobody provisioned it the way you'd provision a service account, mapped what it can reach or asked who owns it. That's the actual attack surface. Not the agent, but the ecosystem it quietly assembled.
Security teams need to treat agents like any high privilege identity and ask four questions. Who is it, and who owns it? What can it do, and what permissions and scopes did it inherit? What is it actually doing right now, measured against its normal baseline? Where can it reach, and what apps and systems is it connected to?
Most security teams can answer one of those. You need to be able to answer all four, continuously. One customer found 74 agents in an environment where they thought they had 12. The gap is almost always bigger than expected.
Ownership of agent risk belongs to the CISO. Since agent access spans identity, data, app configuration, and cross-SaaS connections, this is security's domain. In most organizations agents are being deployed by business units who didn't realize their new SaaS app ships with agents pre-configured. Shadow AI has become shadow agents. The same fix applies to both problems, make the approved path to deploying agents easier than the workaround.
Q3. What should attendees expect to see from Reco at Black Hat USA 2026?
This year we will demonstrate how to control agent risk without breaking business processes.
Reco will show how to build runtime enforcement on top of security posture management with prompt analysis, AI DLP, and action-level controls informed by what we already know about each agent. Runtime controls without posture context are blunt instruments.
We'll also be showcasing the Reco Kill Switch. The most common question we get after a demo is "What do I do if an agent goes rogue?" The response has to be surgical. Stop that agent, in that app, without touching anything else.
Finally, we will demonstrate Reco's native integration with Claude via MCP, showing how security teams can query their entire agent inventory, identity graph, and posture findings directly from inside Claude. No dashboards or exports. Simply ask the question and get the answer.
Q1. How is AI reshaping penetration testing in practice? Where do you think the real limits still are?
Historically, penetration testing served a crucial purpose: to emulate what an attacker could do. This point in time model worked because both the attacker and the defender were human. Overnight, AI forever changed that equation.
The biggest impact of AI isn't simply that penetration testing is faster. It's that attackers are now effectively leveraging AI, and defenders need to be able to fight that fire with fire. We’ve directly observed attackers discovering vulnerabilities, building exploits, and automating offensive workflows in minutes and hours vs. weeks or months. It's no longer enough to emulate yesterday's human hacker, you have to test against AI.
At the same time, for years, the industry has also struggled with a shortage of elite human defenders. Our customers tell us the XBOW platform has allowed them to infinitely scale their human teams by enabling the continuous testing that seemed impossible just months ago. Most importantly, it lets these cutting edge organizations measure how they actually stand up against AI-powered attacks today.
The real limits aren't the AI models themselves as they’re increasingly becoming more capable and affordable. The challenge is building the enterprise-grade systems around them. A raw model isn't a penetration tester. It needs the right customized harness – unique guardrails, reliability, and methodology – before it can effectively operate autonomously in a complex environment.
This is the challenge XBOW solves. We believe the future isn't AI assisting a human tester, it's autonomous AI operating at the level of an elite hacker, safely and repeatedly.
Q2. What guardrails, validation steps, or governance measures are most important when organizations use automated systems to identify weaknesses in their own environments? What would an audit trail look like in practice?
Too many in our industry are still assuming that autonomous AI = uncontrolled AI. That's backwards.
An autonomous penetration testing system needs to be trained to think like an elite attacker, but it should never behave like an uncontrolled one. This means setting clear boundaries around scope, permissions, safety, and execution. Without those critical guardrails, AI can eventually attempt actions that create unnecessary risk instead of delivering security value. It’s not just about making the models smarter, but more trustworthy as well.
Just as important is transparency. In the past, penetration testing often relied on somewhat blind trust. You hired the consulting firm, received a report a few weeks later, and, often based on reputation, anticipated that everything important had been vigorously tested. The static report told you what vulnerabilities were found, but there was no efficient way of understanding everything that had been explored along the way.
From my point of view as a Chief Information Security Officer, the complete audit trails that autonomous testing provides are a total game changer. Every endpoint explored, every request made, every attack attempted, every decision taken, and every vulnerability discovered are captured and serves to make my team and I smarter.
Now defenders can really learn from the attacker's behavior, not just the final finding. Security teams can understand how AI reasoned its way through an application, identify where controls failed, and improve detections before a real attacker follows that same path.
Autonomous AI has replaced blind faith with radical transparency.
Q3. What does XBOW plan to highlight at Black Hat USA 2026? What should attendees expect by way of demos, research, or product capabilities?
Two years ago, when we said we were going to build a fully autonomous hacker, many laughed. At Black Hat 2025, we proved the power of our technology by achieving the #1 spot on HackerOne’s leaderboard.
Fast forward to Black Hat 2026, and our business results speak for themselves. In just a few quarters of commercially selling, we’re working with over 100 customers worldwide, including industry leaders like Moderna, Samsung, and Fortune 500 financial institutions. We’ve found 14,000 zero days in real customer applications.
In this time of disruptive change in the security industry, our team, made up of the world’s top hackers, Copilot builders and GTM talent, has put our heads down and learned what it really takes to deploy autonomous offensive AI inside large, complex organizations.
Sharing those insights is the conversation we want to have at this year’s event. In my experience, Black Hat attendees are some of the sharpest and most skeptical in the industry. I know they’ll ask the tough questions and push our team so that we only continue to get better and innovate faster.
Come to our booth #3448, and you’ll find live demonstrations of autonomous AI finding real vulnerabilities in real applications – no canned demos or carefully scripted marketing examples. We'll be sharing research from our work over the past year, and the lessons learned from thousands of real-world findings.
