CultureAI
All blog posts
NewsEvents

RSA 2026: The Shift Toward Security FOR AI

Ria ManzaneroHead of Marketing
PublishedRead time6 min readShare

In brief

  • Security buyers are fatigued by AI washing. What cut through at RSA 2026 was a more grounded question: how to govern and control AI usage inside the organisation.
  • The token quota paradox is real: business leaders push for more AI use while security teams lack visibility into the data flowing through prompts and uploads.
  • Agentic AI breaks the intern analogy. Agents scale errors in milliseconds, and identity and access management for non-human actors remains unsolved.
  • Deepfake-driven attacks bypass technical controls entirely, and incident response playbooks fail without visibility into how AI is actually being used.

RSA Conference 2026 made one thing clear very quickly.

Security leaders are done with generic AI pitches.

After two years of relentless “AI everything,” the market is now pushing back. There is a growing fatigue with vague promises, surface-level features, and what many are calling outright AI washing.

The result is a trust gap.

If everything is AI security, then none of it is.

What cut through this year was not another AI-powered detection claim. It was a much more grounded question:

How do we actually govern and control AI usage inside the organisation?

That is the shift. Not more AI. Better control of it.


Day 1: The Buyer Reality Check and the Demand for Security FOR AI

The first major theme was a reset in buyer expectations.

CISOs are no longer interested in GenAI wrappers or tools that sit on top of models without addressing the underlying risk. The priority has moved decisively toward infrastructure that can govern AI usage in real environments.

At the centre of this is a growing contradiction inside most organisations.

The token quota paradox.

On one side, business leaders are pushing teams to use more AI. In some cases, productivity is measured by token usage, prompt volume, or output.

On the other side, security teams are deeply uncomfortable with what that means in practice.

Sensitive data is being entered into public models. AI is embedded into SaaS tools without visibility. Employees are using personal tools outside of policy.

This is not edge-case behaviour. It is the default.

At the same time, the way security is trying to manage this risk has not evolved.

Defenders are still working in tables. Attackers are working in graphs.

Security teams rely on static rules, predefined lists, and binary decisions. Meanwhile, AI systems and adversaries operate in context, relationships, and behaviour.

That mismatch is becoming harder to ignore.

Legacy tools like DLP and CASB can block or log, but they do not understand prompts, intent, or how AI is actually used across modern workflows.

What this means for security leaders:

  • AI adoption is already happening, with or without approval
  • Blocking is not a viable strategy at scale
  • Logging is not enough if you cannot interpret behaviour

The requirement is shifting toward something more precise. Not just security around AI, but security for AI usage.

Day 2: The Agentic AI Era and the Identity Nightmare

By Day 2, the conversation moved beyond chat interfaces and copilots into something more complex.

Agentic AI.

Autonomous systems that can take actions, trigger workflows, and interact across multiple systems without direct human input.

This is where the industry narrative starts to break down. There is a common analogy that AI agents are like interns: that they need supervision, guidance, and guardrails.

Most CISOs we spoke to rejected that completely.

The intern fallacy is dangerous.

An intern learns. An intern slows down when unsure. An intern makes small mistakes.

An AI agent does not.

A poorly prompted agent can execute thousands of actions in milliseconds. If it is wrong, it scales that error instantly. This introduces a problem that remains largely unsolved.

Identity and Access Management (IAM) for non-humans.

  • How do you assign identity to an AI agent
  • How do you track what it is doing across systems
  • How do you enforce policy or shut it down if something goes wrong

The industry has not solved IAM for humans cleanly. Now it is being asked to extend that model to potentially hundreds of thousands of non-human actors.

Gartner has already highlighted this as a major emerging gap, particularly as agentic AI adoption accelerates.

What this means for security leaders:

  • Identity is expanding beyond users to include AI-driven actors
  • Access control alone is insufficient without behavioural context
  • Visibility into AI activity becomes critical before scale is introduced

Chatbots were the introduction. Agents are the real shift.

Day 3: Nation-State Deepfakes and the Failure of IR Playbooks

By Day 3, the conversation turned toward what happens when these risks materialise.

And the answer, in many cases, is uncomfortable.

Because the nature of compromise is changing. We are seeing the convergence of nation-state capability and enterprise attack surfaces, accelerated by AI.

The example that came up repeatedly:

  • A multi-million dollar fraud
  • Executed through AI-generated voice and video
  • Involving fake executives in live meetings

This is not a technical exploit. It is a human one.

The human identity is now the attack surface.

Deepfakes bypass traditional controls entirely. They do not rely on malware, vulnerabilities, or lateral movement in the traditional sense.

They rely on trust.

During tabletop exercises at RSA, many CISOs reached the same conclusion.

Their incident response playbooks do not work for AI-driven compromise.

The core issue is visibility.

If you do not know:

  • Which AI tools are being used
  • What data is being shared
  • How employees are interacting with these systems

Then you cannot investigate, contain, or respond effectively. Traditional IR assumes known systems and observable signals. AI breaks both assumptions.

What this means for security leaders:

  • The attack surface now includes AI-mediated human interactions
  • Deepfake-driven attacks bypass technical controls
  • Incident response must include visibility into AI usage, not just infrastructure

The Overarching Narrative: AI Washing and the Trust Deficit

Across all three days, one theme connected everything. A growing lack of trust in the market.

AI is everywhere. Every vendor has a story. Every product claims coverage. But buyers are increasingly sceptical.

Because the underlying problem is not being solved:

  • AI is already embedded across SaaS and workflows
  • Shadow AI usage is widespread
  • Sensitive data is already leaving the organisation through prompts and uploads

More than half of employees are using AI without approval, and most organisations expect AI-related breaches in the near term.

This is why the narrative is shifting.

From tools that claim to “secure AI” to platforms that can make AI usage visible, measurable, and controllable.

Where Security Leaders Need to Focus

If there is a single takeaway from RSA 2026, it is this:

The problem is no longer whether AI will be used. It is whether it will be used safely.

That leads to a set of clear priorities.

  • Move from blocking to enabling<br>The business will adopt AI regardless. The role of security is to make that safe.
  • Focus on behaviour, not just access<br>Risk sits in prompts, inputs, and workflows, not just applications.
  • Establish visibility before enforcement<br>You cannot govern what you cannot see.
  • Prepare for agentic AI and non-human identity<br>This is not theoretical. It is already emerging.
  • Rethink incident response for AI-driven threats<br>Without AI usage context, response strategies will continue to fall short.

Final Thought: From AI Hype to AI Security and Governance

What RSA 2026 made clear is that the market is maturing.

The conversation is moving away from hype and toward control. Not control in the sense of restriction, but control in the sense of confidence.

Confidence that:

  • AI can be used across the organisation
  • Sensitive data is not being exposed
  • Policies are enforced in real time
  • Behaviour is understood, not just logged

The end state is straightforward.

High adoption. High security.

The organisations that get there will not be the ones that slow AI down. They will be the ones that understand it, guide it, and control how it is used in practice.

That is the shift underway.


Start Surfacing Risks

If RSA made anything clear, it’s that AI usage is already happening across your organisation, whether you control it or not.

👉 Start a free AI Risk Assessment with CultureAI to see how AI is actually being used across your environment, surface hidden exposure points, and understand where policy breaks down in practice.

Uncover hidden AI risk

Start a free 2-week AI Risk Assessment. Easy setup. Fast visibility.