Everyone is building AI for security. Almost nobody is talking about the data underneath it.

Field notes from Black Hat USA 2026, read from the network side: the agents are moving faster than the data feeding them.

Port0 owl on a snowy watchtower island above a glowing network grid

After two days on the floor at Black Hat in Vegas, one thing became obvious. Every booth promised faster investigations, better copilots, autonomous SOCs. Around 60 launches in the business hall, most of them built on AI agents.

The data those systems run on got far less attention, but it decides whether any of it works. Network context still arrives through appliances, sensors, traffic mirroring, and long deployments. By the time it reaches an AI system, it is fragmented, expensive, and often incomplete.

Everything below is a version of that one problem.

The agents are already moving faster than the data feeding them

The most-shared session was the OpenAI and Hugging Face incident. During a controlled evaluation, AI agents broke out of their sandbox, found their own vulnerabilities, reached external infrastructure, and passed findings to each other. The question people kept asking afterward:

If one of our agents, or one stolen credential, starts moving tomorrow, how far does it get before we would see it?

To answer that, you need network context as it happens.

The data itself has holes in it

Palo Alto's Unit 42 reported that 45% of malware command-and-control now talks straight to IP addresses, skipping DNS. Plenty of network tooling watches only DNS and proxy traffic. East-west traffic between workloads is the part few teams cover, and it is where movement happens.

Feed that to an AI analyst, and it reasons confidently over an incomplete picture.

45%of C2 malware now skips DNS, going direct-to-IP (Unit 42)
<30 minattacker breakout time inside the network (Dataminr)
54%of AI-generated patches don't fix the bug (1Password)

What the week added up to

It also has to arrive fast enough to matter

Attackers now break out in under 30 minutes (Dataminr), while the average patch window grew by 11 days. Offense is cheap. Context that takes weeks to deploy arrives after the decision has been made.

AI on top of weak data produces confident wrong answers

1Password found that 54% of AI-generated vulnerability patches fail to fix the vulnerability, and some introduce a new one. Vicarius found 79% of orgs had an incident from a vulnerability already sitting in their inventory. Across the show, buyers asked for proof that an exposure is reachable and cared less about long vulnerability counts.

That gap closes with better ground truth.

The posture that won was using what you already own

The launches that landed ran on infrastructure teams already have. No new agents, no sensors, no rip-and-replace. Budget is the reason, and it is the same reason the data problem persists: east-west and lateral traffic, where a breach unfolds, is the most expensive to keep, so it gets dropped.

The business hall was almost all AI for security. Very few people were talking about the data those systems depend on. AI is not the bottleneck anymore. Data is.

The blast-radius question is a data question

The Port0 team on the Black Hat USA 2026 show floor
On the floor at Black Hat USA 2026.

Agentic-AI risk, direct-to-IP C2, and sub-30-minute breakout all point at the same gap. Once something is inside, the stack cannot see it move, and an AI layer on top of that inherits the blind spot.

Port0 is building the network data layer for AI security. Rather than deploying more hardware, we turn infrastructure organizations already own into machine-speed network context, fused with identity, endpoint, and cloud in one graph, with deep visibility in minutes. A beacon resolves to the user, the process, and the blast radius in one view.

We started by rethinking NDR. The ambition is bigger. Every AI analyst, copilot, and autonomous SOC will need a real-time network intelligence layer beneath it.

That is what we left Vegas thinking about. If internal visibility is on your 2026 list, or annoyingly not, we would enjoy comparing notes.

See Port0 on your own data.

Bring your noisiest alert queue. Watch Soc0 investigate it live.

Book a Demo

Never Miss an Insight

Subscribe to get the latest posts delivered to your inbox.