Black Hat 2026 Confirmed It: Security Has to Move Closer to Where Work Happens

Black Hat 2026 Confirmed It: Security Has to Move Closer to Where Work Happens

Black Hat USA 2026 was one of Ent’s biggest weeks, and one message came through clearly: security architecture needs to be rethought for the AI era, with prevention back at the center.

Across meetings with customers, prospects, and industry experts, live demos, and our hands-on Discovery workshops, we heard that the current security stack can no longer keep pace with how work happens.

img_8554_720
Ent signage at Black Hat 2026

Work now spans browsers, SaaS applications, AI tools, local files, and automated workflows. Attackers operate through many of the same tools. Their activity can appear legitimate because the user is authenticated, the application is approved, and each action looks normal on its own.

The strongest conversations at Black Hat focused on how security teams can recognize and stop that activity before it causes damage.

AI is making familiar security problems move faster

AI and agentic messaging dominated the conference, but most security leaders were not looking for another product category called “AI security.” They were trying to solve problems they already own: ineffective DLP, insider risk, unsanctioned AI use, application control, social engineering and click-fix attacks, and investigations that take too long or lack the right evidence.

Employees are putting company data into AI tools. Agents are taking actions across applications and files. On the flip side, attackers are using AI to find vulnerabilities, generate exploits, and coordinate campaigns faster. The activity still involves data, applications, identities, and endpoints. The speed and volume have changed.

A Microsoft keynote described how AI is lowering the cost of vulnerability discovery and exploit development. Work that once required specialized skills and significant time can increasingly be automated. That puts more pressure on defenders to prevent attacks earlier instead of relying on alerts and investigations after execution.

Several conversations at Black Hat raised the same architectural concern. Cloud-dependent security introduces delay when a decision needs to be made immediately. It can also require organizations to send sensitive workplace context outside their environment for analysis.

Security controls need to make more of these decisions locally, while the action is still underway.

Existing tools see pieces of the activity

Traditional security tools are very good at answering specific questions.

EDR can tell you what process was executed. DLP can tell you when governed data moved through a monitored channel. Identity tools can tell you who authenticated and are authorized to perform certain actions. SIEM can bring those signals together and SOC platforms can assemble them for investigation.

Those tools remain necessary. The gap appears when an approved user, application, or AI agent performs an action that looks legitimate on its own. The question that matters now is why an action is happening right now and whether it should be allowed to continue.

An engineer may use SSH every day as part of the job. The same action could become risky when it follows an unusual file download or connects to a system the engineer has never accessed. An employee may upload a document to an approved AI tool, but the action requires a different response if the document contains customer data and the tool is not sanctioned for that use.

The action alone doesn’t always tell you enough.

And more telemetry isn’t necessarily the answer. What matters is being able to interpret the action in context and understand what it means. The same action can be routine for one user and risky for another. Security teams need the sequence around it: who performed it, what data was involved, which applications and systems were touched, whether it fits the person’s role, and what happened immediately before it.

As Andrew Cal, CISO at WestCap, explains,

“Modern work creates signals that can look identical on the surface, even when the intent is completely different. Ent reads the chain of events and helps security teams understand the difference between normal work and risky actions.”

That’s where intent matters.

This is the foundation of Intent-Aware Workspace Security, an approach that brings together endpoint telemetry, behavioral context, organizational policy, and AI reasoning to understand why activity is happening as work happens and enable intervention before risky actions become incidents.

From watching an attack to stopping It

At Black Hat, we wanted attendees to experience that difference for themselves.

4d21e832-68dd-4d5e-841a-4546872faed4
Ent Discovery Workshop at Black Hat 2026

In our Discovery workshops: Threat Investigation Files, participants didn’t sit through another presentation. They sat down at an operator console and worked through the investigation themselves.

They watched an attack unfold across a user, an endpoint, applications, and other systems and saw what happened after access was gained. They investigated the activity using behavioral timelines and contextual evidence. Then they saw how user intervention could change the outcome and why it needed to happen at the endpoint, before the damage occurs.

The workshops brought the concept of intent-aware security to life. When activity looks legitimate on the surface, understanding the sequence of behavior and the context surrounding it can make the difference between another alert post-incident and meaningful intervention in real-time.

One workshop participant summed it up this way.

“I didn’t know what to expect, but it wasn’t this. I have nothing that does this today, you’re solving the hardest part of our investigation and no one is doing this. I can’t wait to show my team.”

That reaction reflected something we heard throughout the week. Security teams don’t need another pile of telemetry. They need help inferring the context and intent behind an action, pinpoint deviations from regular work, and what to do next.

Prevention needs more than a block button

Real-time prevention does not mean blocking every unusual action.

One of the clearest themes at Black Hat was a shift from reactive detection and response toward proactive prevention. It showed up in conversations across the conference, not just at our booth.

Visibility is only valuable if it can change the outcome.

A good control should apply the right response for the situation. It may warn the user, ask for a reason, redirect the user to an approved application, require another approval, or block the action when the risk is clear.

Context determines which response makes sense.

Security teams don’t just want to know that something risky happened. They want enough context to make a decision while the action is still unfolding.

That means moving from detecting and reconstructing incidents after the fact toward intervening at the moment risk occurs. Controls that understand the user, role, data, application, and sequence of activity can be more operationally effective than blunt controls.

Ent Founder Elias (Lou) Manousos with Richard Sherman at Decibel GameDay.

The same approach can govern people and AI agents. If an agent tries to move sensitive data, install an unsanctioned application, or execute an action outside its approved role, the policy should apply regardless of whether it was a human or an agent-driven workflow.

AI Agents are redefining endpoint security

AI is changing how employees work and how attackers operate.

Employees can move sensitive information into AI tools in seconds. Attackers can automate social engineering and parts of the attack lifecycle. AI agents can act across applications and systems faster than security teams can review each step.

But the underlying problems are often familiar.

Sensitive data still leaves the organization. Attackers still abuse trusted applications. Insiders still work outside expected workflows. Social engineering still convinces users to take actions they shouldn’t. AI increases the speed, scale, and volume of that activity.

As Jon Sakoda, Founding Partner at Decibel, puts it,

“AI has been a killer app for hackers and offensive researchers, but the industry is waiting for a novel defensive solution that can keep up with the modern era of LLMs. Ent has reimagined what is possible to protect the endpoint by using specialized AI models and adaptive policy enforcement to detect and prevent malicious activity in real time. It’s a game changer for cybersecurity teams who need a paradigm shift to defend their workforce against LLM-based attacks.”

That shift was evident throughout Black Hat. Security leaders aren’t simply looking for more AI security products. Many are trying to solve problems they already own, including data protection, insider risk, application and AI usage control, investigations, and rapid response.

Protecting work requires trust

As security moves closer to where work happens, trust becomes essential.

Understanding behavior at the endpoint naturally raises questions about privacy, what telemetry is collected, and how that information is used.

Organizations need control over what is collected, where security data resides, and how behavioral information is used. The goal is to capture the context needed to understand risk without turning security into employee surveillance. This requires clear policies, controlled access to behavioral data, and an architecture that lets customers keep sensitive context inside their environment.

Protecting work as it happens requires an approach that balances security with privacy and gives organizations control over how they protect their human and AI workforce.

What comes next

The response we experienced at Black Hat reinforced that the market is ready for a different approach. We saw a growing interest in endpoint security that can understand human and AI activity and intervene while risk is still unfolding.

The energy around Gen3 endpoint security, prevention, securing human and AI agent workflows, and real-time intervention was impossible to miss. Investors, customers, partners, and practitioners were all wrestling with versions of the same question. How does security keep up when risky activity increasingly looks like legitimate work?

For Ent, the answer starts with intent.

DSCF2610
Ent booth at Black Hat 2026

It means working towards a vision where organizations understand why an action is happening, apply the right response, and give investigators evidence they can follow. It also means working with the EDR, DLP, SIEM, and SOC systems customers already use.

We left Black Hat 2026 energized by the conversations, the engagement in our workshops, and the momentum around what we’re building.

See Ent in Action

Learn how Ent helps security teams understand intent, intervene before risky actions become incidents, and protect human and AI-driven work as it happens.

See the platform in action and schedule a demo at ent.ai/contact.

Follow us on X and LinkedIn.