As RSAC 2026 opens its doors at the Moscone Center, the industry is no longer just talking about AI—it is re-platforming on it while fighting to secure it.

Two fronts, one agenda

RSAC 2026 at the Moscone Center arrives with a clear split in how security teams talk about artificial intelligence. One front is offensive and operational: attackers use models to write better phishing, probe systems faster, and adapt after each failed attempt. The other is defensive and architectural: organizations are rebuilding detection, response, and access control so AI sits inside the control plane rather than beside it. Both fronts run at once. Treating them as separate roadmaps is how budgets fragment and gaps open between what the SOC can see and what the business has already automated.

The practical shift is from pilot demos to platform decisions. If identity, logging, and policy engines still assume only human operators and static rules, AI-assisted attackers will outpace them. If models are wired into production without the same review, monitoring, and rollback you already apply to critical software, you inherit a new attack surface while claiming you are modernizing defense.

War one: re-platforming defense on AI

Re-platforming means models participate in triage, enrichment, and prioritization—not only after an alert fires, but while signals are still raw. Useful designs keep humans as owners of high-impact actions and use AI to compress work that is repetitive and high-volume: grouping related events, drafting investigation notes, mapping activity to known techniques, and suggesting next checks against your own playbooks. The stack that supports this needs clean telemetry, stable schemas, and clear authority boundaries so a model cannot open tickets, disable accounts, or change firewall rules without an approved path.

Build for inspectability. Every automated recommendation should show which inputs mattered, which policy constrained the answer, and how to reverse the outcome. Prefer tools that integrate with your existing SIEM, EDR, and identity systems rather than another isolated console. Measure success by time-to-triage, false-positive reduction you can audit, and analyst hours recovered—not by how many “AI features” appear on a product sheet.

War two: securing AI itself

While defense platforms absorb models, the same organizations ship copilots, agents, and retrieval systems that touch customer data and internal systems. That second war is classic application and data security applied to a new runtime: prompt injection, tool abuse, data leakage through retrieval, poisoned training or fine-tuning sources, and over-privileged service identities that act on a model’s behalf. If an agent can call APIs, read mailboxes, or write to tickets, treat those capabilities as production privileges with least privilege, short-lived credentials, and continuous monitoring.

  • Inventory models, agents, and data sources the same way you inventory apps and SaaS.
  • Separate untrusted user input from system instructions; never merge them into one free-form blob without controls.
  • Log prompts, tool calls, and outputs at a fidelity that supports incident response without storing secrets in the clear.
  • Gate high-risk actions behind human approval or policy engines that do not depend on the model’s self-assessment.

A defense stack that holds both lines

The new cyber defense stack is not “AI product plus old perimeter.” It is identity that covers humans, services, and agents; continuous validation of device and session risk; detection that can reason over narrative as well as indicators; and response paths that work when volume spikes because automation is on both sides. Governance belongs in the same design: who may deploy a model, which data it may touch, how often it is re-evaluated, and what happens when behavior drifts.

For teams walking the RSAC 2026 floor, the useful filter is simple. Ask whether a capability shortens the attacker’s loop or your own. Ask whether securing AI is in the same architecture diagram as using AI for security. The industry is re-platforming on AI while fighting to secure it; the organizations that win both wars will treat them as one program with shared telemetry, shared identity, and shared accountability—not as two conference themes that never meet in the backlog.

Automate Your Content with AI Video Generator

Try it Free →