TL;DR: Black Hat USA 2026 is expected to centre cloud exploitation, SaaS vulnerabilities, identity-based attacks, and AI-driven risks, according to Safetica, reinforcing that visibility gaps across distributed data, non-human identities, and embedded AI workflows now shape the attack surface. The practical problem is governance drift, where controls lag behind how modern systems actually exchange data and privilege.
NHIMG editorial — based on content published by Safetica: Black Hat USA 2026 and the cloud data protection trends shaping it
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
Questions worth separating out
Q: What breaks when SaaS sprawl is left out of AI governance?
A: AI governance breaks when SaaS sprawl is ignored because the organisation loses visibility into where AI is embedded, which identities connect those tools, and what data those tools can touch.
Q: Why do non-human identities complicate data protection controls?
A: Non-human identities often have broader reach, longer lifetime, and more machine-speed reuse than human accounts.
Q: How do security teams know whether cloud access policy is actually working?
A: They should test whether policy decisions are traceable from discovery to approval to revocation.
Practitioner guidance
- Map every SaaS and API trust chain Create a live inventory of SaaS applications, third-party integrations, automation paths, and delegated access that can touch sensitive data.
- Audit machine identities for ownership and expiry Review service accounts, tokens, and workload identities for explicit owners, justification, and expiry or revocation logic.
- Govern AI access to sensitive data Define which AI tools can retrieve regulated or confidential data, what prompts or connectors are allowed, and how outputs are logged and reviewed.
What's in the full article
Safetica's full article covers the operational detail this post intentionally leaves for the source:
- Conference schedule context for August training, summit, and briefing sessions that shape the research agenda.
- Examples of the cloud, SaaS, and AI threat themes the event organisers expect researchers to prioritise.
- The article's discussion of how data protection tooling fits into visibility and governance across hybrid environments.
- The business-facing rationale for why Black Hat themes matter for mid-market security programmes.
👉 Read Safetica's analysis of Black Hat USA 2026 cloud, SaaS, and identity risks →
Black Hat USA 2026: what cloud, SaaS, and identity teams should expect?
Explore further
Cloud data protection has become an identity governance problem, not just a data visibility problem. SaaS sprawl and AI-assisted workflows make access paths dynamic, which means policy cannot stop at storage or endpoint controls. The critical question is which human and non-human identities can reach data, under what conditions, and for how long. That shifts cloud security toward lifecycle governance, ownership, and revocation discipline.
A question worth separating out:
Q: Who is accountable when AI search exposes sensitive enterprise data?
A: Accountability sits with the teams that approved the data connections, retrieval scope, and response handling, not just the users who queried the system. Governance should cover access design, provenance controls, and operational monitoring across identity, search, and AI platform owners.
👉 Read our full editorial: Black Hat USA 2026 puts cloud identity and SaaS risk in focus