












Humans get identity. That is what MFA and single sign-on are for, and we all understand the bargain: prove you are who you say, then go do your work. Machines get predictability. That is what monitoring is for. A script does the same thing every day. If it deviates, somebody notices.
Related: Part 1: AI is forcing security and operations to merge in the SOC
Agentic AI upsets that arrangement. An agent logs in like a human, with an identity that says who it is. Then it goes to work without a script. It figures out its own steps as it goes. There never is a script. No baseline. Nothing ever amiss.
In part two of my three-part Black Hat USA 2026 wrap-up, the eight vendors I looked at closely are all trying to insert permission where predictability used to be. Predictability was something you watched for after the fact. Permission is something you set in advance. Somebody decides what the agent may reach and what it may not, and the agent runs inside that. Permission can be set in several places.
Radware — Mahwah, N.J. Founded 1997. Application, API and bot defense, extended to the AI agents companies are now deploying.
“Authentication establishes identity,� says Shira Sagiv, vice president of product portfolio. “It does not control what happens next.�
A script that changed behavior was easy to spot. An agent is built to interpret and adapt, using valid credentials and approved tools the whole way. It can reach data it does not need, call the wrong tool, or take a series of individually valid actions that add up to something nobody intended.
Radware’s answer is three stages: discover every agent running, establish what each may access, then watch behavior at runtime with controls that can stop an action in progress.
Suzu Labs — Las Vegas. Founded 2025. Secure AI adoption built on the data layer underneath it.
I spent an hour with founder and CEO Mike Bell at the show, my second sit-down with him this year, reporting for Machines Against Machines.
Bell grants agents no permissions at all. An agent inherits whatever the employee running it could already reach, so there is nothing separate to over-grant and nothing to drift as agents multiply.
Making that work meant rebuilding the plumbing. One client, a $2.5 billion equipment dealer ordered to put AI into more of the business, went looking and could not say where the company’s own data lived. Hundreds of integrations had piled up through acquisitions, some still on an AS/400.
One tier holds material no AI touches, whatever the employee’s rights.
Airlock Digital — Adelaide, Australia. Founded 2013. Application allowlisting, deny by default, now extended to what an agent may do once it is running.
Blocking an agent does not stop it. “AI agents don’t simply stop when an action is blocked,� says CEO and co-founder David Cottingham. They evaluate alternatives and keep working toward the objective.
That is why he separates two decisions. Whether software may execute, which allowlisting has answered since 2013, and what an agent is allowed to do once it already has. Airlock now enforces the second at the command and session level, through the CrowdStrike Falcon sensor.
His conclusion: draw the boundary and let the agent adapt inside it.
Straiker — Mountain View, Calif. Founded 2025. Discovery, adversarial testing and runtime defense for the agents already running inside a company.
You cannot permit what you have not found. In adversarial testing, Straiker’s research arm found 91 percent of successful attacks on productivity agents ended in silent data theft, with no malware and no stolen credentials. Nearly 29 percent of the MCP tools it cataloged carried direct security risk.
“An autonomous attacker takes whichever door is open,� says CTO Sreenath Kurupati. Every agent nobody mapped is a door.
Straiker maps them, red-teams them before deployment, then holds a kill switch that can stop one mid-action.
HERE Enterprise — New York. Founded 2010 as OpenFin. A work-apps browser that keeps a company’s own AI inside its own permissions.
CEO Mazy Dar sat down with me at the show for close to an hour, recording a Fireside Chat podcast. The permission Dar cares about is which AI an employee is allowed to use. Google makes Chrome and Gemini. Microsoft makes Edge and Copilot. Hand an employee one of those browsers and the browser maker decides which AI shows up in it.
HERE is a browser for work apps. An employee opens Salesforce, work email and an internal database in a single secure window supplied by HERE. Those apps share data, so clicking a customer in one updates the others. The company runs its own AI inside that window, with permissions accounted for.
Semperis — Hoboken, N.J. Founded 2014. Identity resilience for Active Directory and Entra ID.
Permissions get granted to a name. Active Directory holds the names, and when an AI agent shows up asking for something, Active Directory matches it to a name and grants whatever that name is permitted.
Semperis researcher Shai Laron showed at Black Hat that the match can go wrong. He found 385 characters that show up as blank spaces on a screen. An attacker can slip an invisible character into his own name and become somebody else.
Laron showed how an attacker can use that to impersonate a domain administrator and take the administrator’s privileges. Microsoft patched it in April.
Semperis also premiered a documentary at the show. Midnight in the War Room runs on more than 50 interviews. Among those on camera are Chris Inglis, David Petraeus, Jen Easterly and Tim Brown, who was CISO of SolarWinds when it happened. The film follows security executives through the worst nights of their careers. Its argument is that complacency is the real adversary.
Token — Rochester, N.Y. Founded 2014. Biometric assured identity, hardware-bound and non-transferable.
Most of the work going into agent permissions aims at acceleration, at letting machines carry more on their own. Token argues that for some tasks the final step still needs a human, however well the agents perform up to that point.
Token sells hardware. An employee wears a ring or carries a stick that reads his fingerprint, and access opens only when the right finger touches the device.
In June, Token introduced a way for companies to attach that same check to what their AI agents do. A company might have agents moving money, deleting records or granting access, with the agents taking over more and more of the steps. But the final step cannot happen until an authorized employee, verified by his device, gives the green light.
“More AI watching AI is useful, but it is still probabilistic,� CEO Kevin Surace said in announcing the capability. “Biometric assured identity is deterministic.�
Pindrop — Atlanta. Founded 2011. Deepfake detection and identity verification across voice, video and digital channels.
Permissions govern what an agent reaches inside a company. Pindrop works the channel where an attacker calls in and talks a person into granting access.
I spent an hour with co-founder and CTO Vijay Balasubramaniyan a few weeks before the show. “We started off solving, okay, is this the right human,� he said. “And then we’re like, is it even a real human? And that’s the big change.� Pindrop now analyzes the audio for the acoustic anomalies that give a synthetic voice away, sounds no human mouth could have made. AI-generated calls went from one a month across its customer base in late 2023 to 84 a day per customer now.
In March, Pindrop turned agents on its own side of the problem. Protect Fraud Assist puts AI into the fraud analyst’s workflow, summarizing calls and writing case documentation. First National Bank of Omaha cut investigation time 35 to 40 percent.
Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.
(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)
August 11th, 2026 | Black Hat | Black Hat Podcasts | My Take | Top Stories
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。