Black Hat USA is one of the biggest weeks of the year for cybersecurity. Thousands of security leaders, researchers, founders, investors and vendors descend on Las Vegas.

The official conference is only part of it.

Across the city, there are hundreds of dinners, receptions, private gatherings and side events competing for people's attention. For our CISO Executive Forum community at Open Future Forum, some of the most useful signals come not just from what is presented on stage, but from what senior security leaders are actually discussing and where they choose to spend their time.

1. At Big Conferences, the Real CISO Network Becomes Visible

There are hundreds of side events around a conference like Black Hat. Very few become the gatherings where you repeatedly see senior CISOs and security leaders.

The challenge isn't finding another event to attend. It is working out which conversations are worth being part of.

The best peer networks are the places where CISOs can talk candidly with other CISOs about what they are seeing, what they are buying, what is working and what is creating problems.

For senior security leaders, knowing where those trusted conversations happen can be as valuable as anything on the official agenda.

2. AI Security Has Moved From "Should We Worry?" to "How Do We Operate This Safely?"

AI was everywhere around Black Hat, but the conversation has become much more practical.

Companies are already deploying AI. Security teams now have to decide how those systems should be governed, monitored and controlled.

That means dealing with access to corporate data, model behavior, human oversight, auditability and what happens when an AI system is manipulated or simply gets something wrong.

We are seeing the same issues inside our own CISO community. In the Open Future Forum CISO AI Leverage Report, 62% of security-room respondents identified securing AI agents and their access as their biggest AI security problem, while 69% said they had no dedicated AI security budget line.

The question is no longer whether companies will use AI. It is how CISOs can enable that adoption without creating unacceptable risk.

3. AI Agent Identity Is Moving Onto the CISO Agenda

The harder security problem starts when AI can take action.

An agent may access applications, retrieve sensitive information, use credentials, call tools and make changes inside enterprise systems.

That creates a basic security question: Who, or what, is actually taking the action?

Security teams need to think about authentication, authorization, least privilege, credential management and accountability for non-human actors.

Giving an employee access to a tool is one thing. Giving an autonomous system permission to act across multiple applications is another.

That puts non-human identity, permissions and audit trails directly on the CISO agenda.

4. "AI-Powered Security" Is No Longer Enough

Almost every cybersecurity company can now say it uses AI.

That makes the phrase increasingly meaningless on its own.

CISOs need to ask a much simpler question: What does the product actually do better because of AI?

Does it reduce analyst workload? Detect threats existing systems miss? Shorten response times? Eliminate repetitive work? Lower costs?

At a conference where hundreds of vendors are competing for attention, that distinction matters.

The next phase of cybersecurity buying will require vendors to demonstrate measurable outcomes, not simply add AI to the product description.

5. Peer Intelligence Is Becoming More Valuable

The volume of information at Black Hat makes trusted peer intelligence more valuable, not less.

The security landscape is changing too quickly for any one executive to evaluate every vendor, technology and threat independently.

CISOs want to know what their peers are actually seeing.

What are they deploying? What survived procurement? What failed? Which AI projects created unexpected security problems? Which vendors delivered what they promised?

This is also why first-party research from executive communities can be useful. Our CISO research is built around the questions, conversations and data we see across the Open Future Forum security community.

Black Hat provides an enormous amount of information.

The advantage comes from having the right network to help separate the signal from the noise.

That is one of the reasons we continue to invest in the Open Future Forum CISO Executive Forum and publish research such as the CISO AI Leverage Report.

Frequently asked questions

What were the main themes for CISOs at Black Hat 2026?

The conversation moved from whether to worry about AI to how to operate it safely. The recurring themes were governing AI already in production, AI agent identity and non-human access controls, harder scrutiny of vendor AI claims, and the rising value of trusted peer intelligence.

What is the biggest AI security problem CISOs report?

In the Open Future Forum CISO AI Leverage Report, 62 percent of security-room respondents named securing AI agents and their access as their biggest AI security problem, and 69 percent said they had no dedicated AI security budget line.

Why does peer intelligence matter more at a large conference like Black Hat?

The volume of vendors and information makes trusted peer conversations more valuable, not less. CISOs want to know what peers are actually deploying, what survived procurement, what failed, and which vendors delivered — the fastest way to separate signal from noise.