Black Hat 2026 has one real theme, and it’s speed.
Read the hundred-plus accepted Briefings as one document and a single bet runs under most of them: the slow parts of an attack are about to get fast. Roughly one in three talks involves AI, and every direction points to speed.
TL;DR
- Black Hat 2026's real theme isn't AI. It's speed.
- Roughly one in three accepted talks bets on it: about ten show AI compressing exploit-building from months to minutes, and about fifteen show researchers already breaking the AI agents companies just shipped.
- The takeaway: security spent thirty years optimizing the "find" step. Offense has moved on. The gap that decides breaches now isn't discovery, it's the time between knowing about a risk and resolving it.
- Exploits can be built in minutes. The average fix still takes 63 to 270 days. That gap is the whole game.
The Black Hat USA 2026 program is public, the event is two weeks out, and the schedule is already the most useful thing about it.
Read all hundred-plus accepted Briefings as one document, not a list, and a single bet runs underneath most of them. It is not "AI is coming." AI has headlined this conference for three years. The bet this year is narrower and more concrete: the parts of an attack that used to be slow are about to get fast, and we are building the software that will make them faster. If you want to know what the security industry will spend next year worrying about, that is it.
The agenda is the industry's best forecast
Skip the keynotes. The signal is the full Briefings list.
A Black Hat talk is roughly a year of an offensive researcher's life, and it has to clear a review board that turns away most of what it sees. So the final program behaves like a prediction market: whatever clears that bar is a fair preview of what we will be defending against a year later. That is why the makeup of the program is the story. By our count, roughly one in three accepted talks this year involves AI. The volume is not the interesting part anymore. The interesting part is that the AI talks point in two clear directions, and both are about doing something faster or at a scale that was not possible before.
Direction one: AI is doing security's hard technical work now
The first group of talks, around ten of them, has AI doing work that used to require a rare human specialist. And it cuts both ways.
On offense: one session, "The 0-Day Engine," says its authors used LLMs to find more than 100 vulnerabilities in Chrome and Android. "Prompt2Own" walks through kernel exploit development with a model in the loop. "One Percent of the Tokens" takes the same approach into IoT and embedded firmware. On defense: "Catch Me If You Can" puts AI investigators to work hunting autonomous attackers, "Beyond Detection" tests AI approaches to sorting real vulnerabilities from noise, and "Closed Loop" runs the full cycle, from working exploit to deployed defense, in a promised five minutes.
The expensive part of hacking has always been the front end. Finding a flaw. Proving it is real. Building something that actually fires. That work took skilled people weeks or months, and that lag is a big reason most organizations survive: attackers are rate-limited by talent. What this group of talks shows, from both sides of the fence, is that the rate limit is coming off. If even a few of the claims deliver, the time between a vulnerability existing and a working exploit for it existing starts collapsing toward nothing.
For scale, once an attacker is already inside a network, the fastest breakout to lateral movement CrowdStrike has recorded is 51 seconds. The industry answered that speed by investing heavily in detection, in seeing the attack sooner. This group is a reminder that detection was the easier half. You can see the attack faster than ever and still lose, because the clock that decides the outcome is the one running before the alert ever fires.
Direction two: we are shipping a lot of new things that can be broken
The second group is larger, around fifteen talks, and it is about a target that barely existed two years ago: AI agents, assistants, and browsers running inside real companies.
The titles are blunt. "Breaking AI Agents in Official Workflows." "Pwning Agentic Browsers." "Turning AI Agents into Credentials Exfiltration Vectors." "Remote Prompt Execution on AI Assistants." "Owning ChatGPT's Secure Sandbox." "Promptware EOD," which treats a crafted prompt as a delivered payload, malware written in plain English. Even the defensive slot on the schedule points the same way: Roblox is presenting on how it sandboxes Claude Code inside its own walls, which is a company explaining how it tries to contain something it has already let in.
Here the count does the arguing on its own. Fifteen separate research teams spent a year each learning to break AI agents. The reason it is direction two rather than a footnote is what these tools are. An AI agent is not a document sitting on a server. It acts. It reads data, calls other systems, and takes steps on someone's behalf, at machine speed. So this group is the mirror image of the first. In direction one, AI makes the attacker faster. In direction two, the fast-moving software is inside the building, and the agenda is fifteen demonstrations of how to turn it around.
The through-line is speed, in both directions
Put the two groups together and the shared thread is not "AI." It is time.
One direction compresses the time it takes to build an attack. The other adds a large, fast-moving surface that can be attacked, deployed quicker than any security process was designed to check. The same underlying capability is cutting both ways at once. It shortens the attacker's slowest step, and it hands defenders a pile of new software that moves faster than they can review.
For thirty years the attack surface mostly sat still. Servers, endpoints, code. You could scan it, rank it, argue about it over weeks, and it did not do anything while you argued. That assumption is the thing quietly breaking on this schedule. More and more of the environment now acts on its own, and the people trying to break it are automating their side too.
What the agenda says the industry got wrong
Step back and the program reads like a correction.
For three decades the hard problem in security was assumed to be discovery: finding what is wrong. So that is where the money went, into more scanners and better ways to rank an ever-growing list. It worked, narrowly. We are extraordinarily good at finding things now. The volume proves it. Published CVEs set a record in 2025, more than 48,000 in a single year, and the cumulative total has passed 300,000. Finding is close to solved, and getting cheaper by the month.
But look at what the researchers chose to spend their year on. Not a smarter way to sort the list. They chose to make attacks faster and to break the new software we just installed. Their attention and the market's attention have drifted apart. The market is still optimizing the "find" step. Offense has moved on to speed.
Which means the constraint has moved with it. When an exploit can be built in minutes and the average remediation still runs somewhere between 63 and 270 days, the distance between those two numbers is not a metric on a dashboard. It is the outcome. It is whether you get breached. Every hour a fix waits is now competing against an attacker who is automating their half of the race.
The speed problem is unavoidable, and it is on the schedule in a hundred rooms.
The forecast
Read as a forecast, Black Hat 2026 is saying the next few years will be won by whoever can close the gap between knowing about a risk and actually resolving it, before an attacker who is automating everything gets there first.
The flashy talks in August will be the ones that break an AI agent live on stage. The durable lesson underneath them is simpler and less fun. The clock is the product now. Everything that lengthens the time between a problem and its fix is a liability, and everything that shortens it is an advantage.
That is the shift. The Black Hat agenda put it in writing two weeks before anyone walks in.