Looking at Black Hat's schedule this year, a striking number of the AI sessions are about what deployed agents are permitted to do. A substantial share of accepted Briefings involve AI, and the AI Summit is a full curated track for CISOs, IT leaders, and security engineers. Many of the sessions start with agents already deployed inside companies and examine the systems, data, and actions placed within their reach.

In most of these cases, the model behaved as expected. The problem was the authority the agent had afterward: the queries it could issue, the tools it could call, the records it could reach, and the messages it could send.

The session list makes the point better than any summary of it. One team is presenting on compromising the AI shopping assistant of a major US retailer (“Bye Bye AI: How We Hacked the AI Shopping Assistant of a Top 3 US Retailer”), a system that Rein Security says was built on Vertex AI Search and sat behind an LLM gateway intended to enforce intent-classification guardrails. Another covers breaking AI agents inside official workflows (“Trusted Enough to Run: Breaking AI Agents in Official Workflows”), the unattended automations that companies have already promoted to trusted status. A third demonstrates a class of attack on AI assistants that ends in a sandbox escape to the host underneath (“A Billion-User Blast Radius: Owning ChatGPT’s Secure Sandbox”). In each case, the consequence came from the authority the surrounding system gave it once it acted.

The defensive sessions say the same thing

The defensive talks are the more revealing part of the schedule. One session covers how a large consumer technology company sandboxes a coding agent operating inside its own environment (“Caging the Agent: How Roblox Built Multi-Layer Sandboxes to Secure Claude Code at Enterprise Scale”), which is a serious engineering organization explaining in public how it contains a system it has already chosen to run. A separate session introduces a defensive layer for LLMs (“Rules for Neural Traffic: A New Defensive Layer for LLMs”), accepted onto both the Defense and Resilience track and the AI track. The keynote on agentic security covers shifting defenders toward formal verification and automated remediation.

None of those are about selecting a better model or writing a stronger system prompt. They are about constraining what a system can reach and do while it operates, and about what happens after something gets through. The defensive work on the program is about containment and verification, which says something about where practitioners are starting to put control.

The sandboxing session is worth one further note. It represents one company, hand-building containment, for one agent, in one environment, staffed by a team most enterprises could not assemble. That is the current state of the art in agent governance, and it does not transfer easily to a company running a support assistant, a claims workflow, and an internal copilot across three business units.

What to carry into the week

The vendor floor will likely sound different from the research track. Plenty of sponsors describe their products as AI-powered or agentic, which is a statement about how the tool was built. The research is asking what stops an agent that has already been manipulated, misconfigured, or handed an unclear instruction by someone with entirely legitimate access. The gap between those two conversations is the difference between adding AI to a product and controlling what that AI is allowed to do.

So the practical question for anyone running agents in production is what decided that action was permitted, and whether you could show afterward what the decision was based on. In many companies both answers are scattered across application code, agent frameworks, and vendor platforms, maintained by teams who do not carry the risk when it goes wrong. This is turning into one of the more interesting problems in enterprise security, and it's what we work on at ThirdLaw.

Sources: Black Hat USA 2026 program materials and Rein Security’s account of the retailer shopping-assistant architecture.

Your AI. Your Rules.

Take command of your LLM-connected applications and AI agents with tools designed to simplify oversight and enforce your policies.

More Resources

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.