Interviews | July 17, 2026
With AI, Speed Without Control Leads to Chaos
Amazon | Exaforce | Microsoft | TrendAI | Oak
Q1. AWS recently announced AWS Continuum to help organizations address vulnerabilities at machine speed. What’s driving the need for this shift? What guardrails should organizations consider when delegating security decisions to automated agents rather than human analysts?
Customers are telling us their vulnerability backlogs are growing faster than their teams can triage. Adversaries are now moving from initial access to full compromise in hours across their enterprise. The old model (collect telemetry > store it > query it > build dashboards for humans) cannot keep pace. Security has to shift from human-driven analysis to context-aware reasoning and automated action.
The guardrails question is the right one to ask, because speed without control is chaos. Customers want a graduated trust approach: Continuum starts in learn mode, every recommendation surfaces its full reasoning, and a human remains accountable for every outcome. Customers define which categories and risk levels the system can act on, and nothing executes without blast-radius visibility and rollback paths. As the system proves accuracy within those boundaries, it earns the right to move toward automatic enforcement, but immutable audit logs and human accountability never go away. That’s the design principle behind the over 26,000 agents operating internally at Amazon, and it’s exactly what we built into AWS Continuum.
Q2. What are the customer concerns you are hearing?
Beyond speed, two things keep coming up. Fragmentation. We hear that security teams are spending more time correlating alerts than responding to them. A dozen tools, none talking to each other, while the attacker moves as one. We’re showing how we close that gap at our booth, live, with automatic correlation across domains and clouds.
Agentic risk. Most AI agents are deploying across enterprises with no registry, no audit trail, and no security review. This is a solvable concern. We’re showing new capabilities at Black Hat that give teams full visibility and governance over every agent in their environment.
Q3. What are AWS’ key goals and plans for Black Hat USA 2026? How do you plan to engage with customers and other stakeholders at the event?
Black Hat is all about practitioners and that’s why this event is important to us. Attendees can see AWS Continuum in action against real vulnerabilities, explore our agentic security and multi-cloud capabilities at live demo stations, and test their own detection skills in a hands-on challenge environment. We’re running short, focused talks from AWS and partner speakers in our booth’s theater throughout expo. And we’re hosting roundtables, workshops, and networking events where security leaders can have direct conversations about the problems dominating their roadmaps.
Q1. Exaforce talks about “real-time security reasoning” as a way to detect and respond to attacks as they unfold. How do you ensure that level of automation remains trustworthy and explainable enough for security teams to act on in high-stakes incident scenarios?
Most AI-powered SIEMs and SOC triage tools make their agents rebuild the story during the investigation, pulling logs, calling APIs, stitching signals together, and reasoning only after the fact. During active threat investigation, that can mean hundreds of queries and additional delays just to land on an answer, burning both time and SOC efficiency step by step. The more data is added to the investigation, the harder it becomes to reason across it, increasing the likelihood of incorrect conclusions and poor decisions that allow threats to spread unchecked.
Exaforce builds and continuously maintains a real-time security knowledge graph at ingest, linking events to identities, permissions, configurations, code, files, and cloud activity as the data arrives. So we can proactively detect threats that SIEMs miss. And when an analyst asks an investigative question, our agents retrieve the relevant context instead of reconstructing it, delivering answers in under a minute, roughly 10x faster. From there, Exaforce can automatically launch a deep investigation, automate response actions, and defend your environment against threats at scale.
That ingest-time correlation is what enables true real-time triage and detection. If correlation happens at query time, it is inherently too late to be real time.
Q2. Many organizations have already made significant investments in SIEM, SOAR, and EDR platforms. Do you see Exaforce replacing any of these technologies or operating on top of them? What would the integration model look like in practice?
We support both models. Exaforce is designed to work with the security stack organizations already have, and then progressively reduce the need for legacy SIEM-style workflows over time. Many customers also choose Exaforce as their SIEM because it delivers capabilities legacy tooling cannot, especially when context is connected at ingest rather than reconstructed during an investigation.
We cover the full SOC cycle from detection and triage to investigation and response, with built-in case management and clear analyst workflows. We also enable proactive threat hunting by ingesting external threat intelligence and public reporting, automatically matching IOCs to your environment, enriching hits with identity and access context, and driving actions through assignments, ticketing, and automated response integrations.
Q3. Exaforce has used previous Black Hat conferences to showcase the company's vision of an AI-driven SOC? What are your plans to evolve that message at Black Hat USA 2026?
At this year's conference, we're going big. We see the value that the Black Hat community brings, and there's never been a better time to move beyond the hype. The industry doesn't need another AI SOC marketing pitch. It needs to see what an AI SOC looks like in practice. We want to show the community real practical use cases and demonstrate how Exaforce is transforming security operations. Most AI SOC pitches today talk about triaging and reduction in false positives as the main use case. As AI-driven attack methods accelerate and zero-day threats scale, security teams need systems that can detect and respond faster than humans can keep up. Exaforce is designed for that reality, where speed, context, and consistent reasoning are non-negotiable. Its real-time knowledge graph goes beyond alert triage, helping security teams detect attacks as they unfold.
That's why Patrick McKinney, Head of Security at Invisible Technologies, will take the stage to share his firsthand experience implementing Exaforce and transforming his SOC from 0 to 1. He'll walk through what worked, the challenges along the way, and the lessons learned from deploying AI in real security operations.
Q1. It's been six months since Microsoft launched its In Scope by Default approach to vulnerability disclosures. Has the expanded scope actually surfaced more third-party and open-source vulnerabilities? How has it changed the way Microsoft thinks about its own vendor and dependency risk internally?
Yes. We announced our expanded scope, which includes third-party and open-source software, at Black Hat Europe in December. Since then, we have received more than 300 additional reports and awarded more than $800,000 for vulnerabilities that would not have been paid under our bounty programs previously. The expanded scope helped contribute to our biggest year in bounty awards ever. I want to thank the security community for their work to help protect our customers across the globe.
Q2. You have noted that AI and automation are accelerating vulnerability discovery. What impact do you expect that to have on enterprise security teams and the traditional Patch Tuesday model?
Many of our customers use our cloud services, and these environments receive continuous updates. Cloud service customers are protected without needing to take any action.
AI is increasing the volume of vulnerabilities discovered across the industry, which makes patching and updating on-premises software more important than ever. Patch Tuesday remains the predictable and scalable way to deliver security updates, supplemented by out-of-band releases when risk warrants. While we can expect the number of CVEs addressed each month to continue to increase, it is important to remember that the number of cumulative update packages remains the same. We encourage customers to ensure they are installing available updates as soon as possible.
As vulnerability discovery accelerates, organizations may need to evolve their existing patch management processes to operate more efficiently at scale. Additionally, while patching remains a foundational security practice, it is most effective when combined with strong exposure management, detection, and response capabilities.
Q3. What are you planning to showcase at Black Hat USA 2026? What message do you want security leaders to take away from your company's participation at the event?
The Microsoft Security Response Center attends Black Hat every year to connect with the global research community. Our team partners with this community every day - identifying, assessing, and mitigating vulnerabilities before our customers are impacted. We use this event as a chance to celebrate these partnerships and learn from one another. There is always interesting research presented at Black Hat, and we encourage researchers to share their findings once a fix has been released. One highlight for me is our annual researcher appreciation event where we have deeper, more direct conversations with the community and celebrate in person. Of course, the team is also here to listen to feedback on where we can improve. We are always looking for ways to deepen partnerships with individual researchers as well as members of the broader security community.
This year, that work connects directly to a larger industry challenge: threat actors are increasingly looking for trusted paths into organizations, from software supply chains and cloud services to identity systems, developer workflows, and emerging AI surfaces. Security teams need strong vulnerability research, coordinated disclosure, threat intelligence, and operational response working together to reduce risk before it becomes impact.
That is the message I hope security leaders take away from Microsoft’s presence at Black Hat: security is strongest when research moves quickly into protection, and when vendors, researchers, partners, and defenders work as one community.
I encourage attendees to visit Microsoft Security at booth #2144, where experts from across the company will host live sessions, AMAs, hands-on demos, community conversations, and interactive experiences focused on the security challenges practitioners are facing now.
Q1. How will TrendAI's collaboration with Anthropic on Claude Opus 4.7 help organizations bridge the gap between AI-driven vulnerability discovery and actual risk reduction in enterprise environments?
This collaboration closes the gap between how fast AI can find a vulnerability and how fast an organization can act on it. Claude Opus 4.7 and now Opus 4.8 powers TrendAI’s Zero Day Initiative (ZDI), giving our research attacker-level reasoning — determining what's reachable, controllable, and exploitable across complex, fast-changing software environments — at a scale no human research team could match alone. We access these capabilities as a participating member of Anthropic's Glasswing coalition, advancing frontier AI for defensive research, and through credentialed access via Anthropic's Cyber Verification Program; Anthropic has named TrendAI a leading cybersecurity partner embedding Opus 4.8 into enterprise platforms. From there, the research translates directly into risk reduction. Every finding we surface feeds ZDI’s coordinated disclosure process, so the industry benefits, not just our customers. It also triggers virtual patching through TrendAI Vision One, protecting exposed systems up to 96 days ahead of an official vendor patch, and runs through Cyber Risk Exposure Management's prioritization, turning findings into ranked, business-relevant action instead of another alert. The result is measurable risk reduction and governance a team can act on, not just faster detection.
Q2. What are the biggest operational and architectural challenges you see customers struggling with today as they continue expanding into hybrid and multi-cloud environments? How is AI changing that dynamic?
The core challenge is a widening “complexity gap.” Roughly 88% of organizations now run hybrid or multi-cloud environments, but security visibility, detection, and response haven't kept pace with how fast those environments change. Identity sprawl, inconsistent controls across providers, and fragmented telemetry mean most teams can't see their full attack surface in one place — and when something goes wrong, over a quarter of organizations can't even determine root cause. AI is intensifying this on both sides. Attackers are using it to reverse-engineer patches and weaponize vulnerabilities faster. Defenders are adding GenAI workloads and autonomous agents into production even faster than they can govern them — the large majority of organizations have updated their security strategy for AI, but only about a quarter feel they actually have the architecture to enforce it. Closing that gap requires AI-native, unified platforms (not multiple point tools) — which is the thinking behind TrendAI Vision One, including Cyber Risk Exposure Management and our new Agentic Governance Gateway — that deliver visibility (what is being used & where), observability (what AI does & how, including data), and actionability (ability to take risk-based actions to respond & adapt) for enterprise-wide governance.
Q3. What themes and technologies does TrendAI plan on highlighting at Black Hat USA 2026? What can attendees expect by way of sessions, demos and product announcements?
Black Hat 2026 is shaping up to be TrendAI's biggest statement yet on AI security leadership: faster research, coordinated disclosure, and governance built for the agentic era. Our threat research team ran an AI-powered sweep of nearly 19,000 MCP servers and surfaced hundreds of exploitable vulnerabilities across a fast-expanding agentic attack surface... just a preview of what's coming in our Black Hat booth sessions.
On the Pulse Stage, industry expert Tom Kellermann will unpack how AI-driven automation has broken the traditional, linear cyber kill chain. Rounding things out, on the AI Summit stage, our Global CISO Johnny Hand is joined by senior executives from Anthropic, NVIDIA, and AWS for "Defending at Machine Speed", a conversation on why AI platforms, cloud infrastructure, and threat intelligence need to converge as AI compresses the gap between vulnerability discovery and exploitation. That panel is a great snapshot of three partnerships we're leaning into hard.
We'll announce new partnership news with both AWS and NVIDIA at Black Hat, and we'll demo it live: TrendAI Vision One's new Agentic Governance Gateway, in an AWS/Bedrock workshop. The panel also builds on our recent moves with Anthropic — joining Glasswing and using Claude Opus 4.8 to bring attacker-level reasoning at machine scale to our Zero Day Initiative (ZDI) — proof of how deep these relationships run. We will have product announcements focused on how TrendAI is managing critical vulnerabilities in the age of frontier AI models, as well as how deep integration with NVIDIA uniquely positions TrendAI for solving sovereign AI deployments, two challenges defining this next phase of enterprise AI security.
At booth #3439, we're bringing something new as well: hands-on threat hunting challenges, live product demos, and the TrendAI ZDI Vanguard Awards, honoring researchers and vendors advancing responsible vulnerability disclosure. Come see it firsthand. Stop by booth #3439, or catch us at Flanker Kitchen & Sports Bar.
Q1. You've spent years building identity and security companies. What fundamental shift convinced you now was the right time to launch Oak?
I've built several security companies, so I've watched this problem from every angle. Identity tools were built for a slower world: human users, static environments, one system per identity type. That architecture is twenty years old, and it can't keep up with today's AI reality, where human, machine, and now agent identities are multiplying at machine speed. Identity became the control plane for the entire enterprise, and PANW just paid $25 billion to say that out loud. The instinct from the incumbents has been to bolt AI onto those old cores and acquire their way into coverage, but that only adds another disconnected piece to a stack that was already fragmented. It doesn't fix the architecture; it just adds to it. What convinced me now was the right time is that AI has finally made the real fix possible: a single system that maps what every identity can access against what it actually uses, and governs all of it in real time. That's not a patch; that's a different foundation. Oak was born complete, not assembled.
Q2. What resonated most with investors about your vision, and how has that shaped Oak's direction?
The conversations with Greylock, Accel, and CRV weren't about a feature or a roadmap slide, they were about ambition. Instead of building another module for security teams to bolt onto what they already have, we set out to build the operating system enterprise identity has never had, one platform, covering every identity, from the ground up. That's a bigger scope than most companies take on at seed stage, and it's shaped everything about how we operate. We didn't sequence this as point-feature, then point-feature. We hired to build the complete system in parallel, connectors, the graph, the AI layer, the real-time governance, etc., because a platform that arrives in pieces is just the same fragmentation we're trying to replace, one company later. Oak will win with a foundation layer that makes any identity use case possible.
Q3. What are your key goals for Black Hat USA 2026, and what's the one takeaway you want security professionals to leave with?
Black Hat is where we go from a launch announcement to a live conversation with the people actually running identity day to day. Our goal at Booth 4203 isn't to hand out a feature list, it's to show security teams what it looks like to actually run future governance instead of just watching it. Oak connects to everything, builds one live graph of every identity and what it can reach, and puts a team of AI agents to work alongside your team, surfacing real risk, fixing root cause instead of symptoms, and doing the lifecycle and access work your team does by hand today. If someone walks away from our booth with one thing, I want it to be this: Oak is the one AI foundation strong enough to finally cover identity governance and security end-to-end: human, machine, and AI agent, in a single live system.
