Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI security at RSAC 2026: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: RSAC 2026 showed that AI security messaging is outpacing practitioner confidence, with Expel arguing that the harder question is not how to use AI but how to secure it as shadow AI, GenAI leakage, agentic identity compromise, and MCP security expand the attack surface. The implication is that security teams need governance and accountability models for AI systems now, not later.

NHIMG editorial — based on content published by Expel: RSAC 2026 commentary on AI security messaging and the expanding attack surface

Questions worth separating out

Q: How should security teams govern AI workflows that use multiple tools and data sources?

A: Security teams should govern AI workflows by placing explicit authorization at each decision point, not by relying on the permissions attached to the surrounding application or service account.

Q: Why do AI tools create new access governance risks for security teams?

A: AI tools often sit close to mail, data, and response systems, which makes their permissions unusually broad.

Q: How can organisations tell whether their AI security model is actually working?

A: They should test whether the control stack can explain who acted, what data was touched, and what purpose the action served.

Practitioner guidance

  • Inventory AI systems that can act on data or tools Build a register of AI assistants, agents, MCP connectors, and workflow automations that can read, write, or trigger enterprise systems.
  • Classify agent permissions as privileged access Map each AI system to the exact tools and datasets it can reach, then apply least privilege, separation of duties, and approval boundaries where actions can change state or expose sensitive data.
  • Measure where AI changes analyst decisions Track whether AI reduces triage noise, improves evidence quality, or only accelerates output volume.

What's in the full article

Expel's full article covers the operational detail this post intentionally leaves for the source:

  • The specific RSAC 2026 examples behind the AI messaging problem and how practitioners reacted on the floor.
  • The five SOC architecture questions Dave Merkel used to test whether AI is actually supporting defenders.
  • The article’s examples of AI attack surface categories, including shadow AI, prompt injection, and MCP security.
  • The vendor’s description of operational defense in depth across enrichment, triage, response, and reporting.

👉 Register for Expel's RSAC 2026 analysis of AI security messaging and attack surface growth →

AI security at RSAC 2026: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI security is now an identity governance problem, not just a model risk problem. Once AI systems can access tools, data, or downstream services, they need lifecycle controls that resemble non-human identity governance. That means explicit ownership, scoped privilege, revocation paths, and logging across the full access chain. Organisations that treat AI as only a software feature will miss the governance layer that determines whether it becomes an attack surface.

A question worth separating out:

Q: Who is accountable when an AI agent takes an unsafe action?

A: Accountability should sit with the business owner of the agent, the team that provisioned the access, and the control owners responsible for monitoring and revocation. If no one can answer who approved the identity, the scope, and the oversight model, the governance framework is not complete enough for production.

👉 Read our full editorial: RSAC 2026 exposed the real AI security question for practitioners



   
ReplyQuote
Share: