TL;DR: History doesn’t repeat, but in security, it echoes with brutal fidelity. Black Hat 2026 feels like 2011’s cloud frenzy all over again—drowning in vendor wrappers, non-deterministic guesswork rebranded as control, and an alarming push to destroy our entry-level pipeline. We are misusing technology as a replacement for defenders when it was meant to be a cognitive prosthetic. With technological acceleration reaching speculative fiction levels, we are rapidly running out of time to fix our trajectory.
Walking the floor at Black Hat USA this week brought a heavy, familiar weight. For those of us who have spent decades dissecting this industry’s cycles — and calling out the structural rot on Liquidmatrix Security Digest — the atmosphere wasn't forward-looking. It was an echo chamber.
I’m less angry than I am exhausted and sorrowful. We’ve seen these patterns play out before, yet we keep marching into the same predictable traps.
1. The Fragmented Commons
The human element remains the only real redeeming factor of this week: running into old friends and co-conspirators. But it highlights how thoroughly our digital community has balkanized.
Fifteen years ago, during the #sectwits era on Twitter, we shared a single, chaotic, but unified room. Today, our town square has shattered into BlueSky, Mastodon, Threads, LinkedIn, X, Facebook, a dozen semi-private Slack teams and Discord servers, and an endless array of Signal group chats. Routing IP packets over avian carriers via RFC 1149 feels like a more coherent communication architecture than trying to maintain a cohesive community across today's fragmented web.
These brief, in-person reconnections are becoming the only thread keeping what's left of our collective memory intact.
2. "AI All the Things" & The 2011 Echoes
The vendor floor was drowning in AI promises to a degree that was genuinely painful.
Cast your mind back to ~2011 during the early rush to the cloud. The floor was covered in bolt-on proxies, Format-Preserving Encryption, and early CASB wrappers—all desperate attempts to take architectures that were explicitly not enterprise-ready and force them into enterprise-ish shapes.
Today, legacy brands are frantically slapping LLM wrappers on aging platforms to stay relevant, while point-solution AI startups pitch features disguised as companies. Most will be flash-in-the-pan failures or acqui-hires because they solve only a fraction of the architectural puzzle.
3. The Determinism Trap
Despite the ubiquitous marketing, deployment is following the classic teenager rule: everyone is talking about it, everyone thinks everyone else is doing it, so everyone claims they are doing it—but almost no one actually is.
The fundamental engineering roadblock hasn't changed: Determinism.
In security, governance, and safety systems, a non-deterministic mechanism is not a control mechanism. You cannot build real risk boundaries or operational reliance on top of a core engine whose outputs are inherently probabilistic. Until we solve boundary enforcement for these models, they remain experimental, not controlling.
4. Human Augmentation vs. The Looming Pipeline Collapse
The most tragic mistake on the floor was the push to use AI to eliminate junior and entry-level security staff.
Over a decade ago, Violet Blue interviewed me for ZDNet about our industry’s massive talent gap. Back then, we warned about the urgent need to build sustainable pathways into the field. Today, short-sighted leaders are attempting to "optimize" headcounts by destroying the entry-level roles that forge senior practitioners.
If you destroy the entry point, you eliminate the future pipeline. In five years, we will face an unprecedented talent crunch with zero senior architects to hire.
We are deploying the technology entirely backwards.
AI shouldn't be used to replace your team; it should be built as a cognitive prosthetic to make your people better, faster, and stronger. I brought this up in my 2009 Black Hat presentation on memory and mind security. The exocortex isn't a distant sci-fi concept—it arrived years ago in the poorly named "cell phone," the most personal piece of personal computing ever made. That memory prosthetic is now evolving into a full cognitive prosthetic. The organizations that use AI to augment and elevate human intelligence will thrive; those trying to fire their way into efficiency will collapse under their own operational debt.
5. Open vs. Closed: The Enterprise Poverty Line
The current debate around open versus closed models directly intersects with Wendy Nather’s core thesis on "Security Below the Poverty Line".
If frontier inference remains locked behind expensive, walled-garden APIs, we will drastically widen that poverty gap, leaving small and mid-sized organizations entirely undefended against automated threats.
The political push against open weights is particularly shortsighted—it's the equivalent of forcing the enterprise to build its future on Internet Explorer 5.5 and closed .NET runtimes instead of Linux and open web standards. We already know how that story ends: Microsoft eventually ended up shipping its own Linux distribution.
Just as the launch of the iPad famously signaled the end of Adobe Flash by refusing to run closed, inefficient runtime bloat on mobile hardware, open-weights and local-first models will inevitably outlast closed API monopolies. Open infrastructure always wins the long game because reality demands accessibility, interoperability, and efficiency.
Out of Time
The speed of acceleration has officially crossed out of standard tech cycles and into speculative fiction territory. We are simply out of time to keep making the same predictable, cyclical mistakes and course-correcting after the damage is done.
We cannot automate away the human defender, nor can we hoard capabilities behind closed gates and expect the global threat ecosystem to wait for us. We need to do better for the people working the frontlines—building true cognitive prosthetics, preserving our junior talent pipelines, and sharing open tools, models, and capacity as broadly and cooperatively as possible. The alternative isn't just another tech bubble bursting; it's a systemic failure of defense at a moment when we can least afford it.
A much abbreviated version of this was posted to my LinkedIn