I flew home from Black Hat this week thinking about one shift that stood out to me above everything else.
For most of its history, this show has been about the break-in. The cleverest way through the door, the exploit nobody saw coming. That work was here as always. Someone coaxed secrets out of NVIDIA GPU memory. Someone showed a compiler quietly reintroducing bugs that had already been patched. Entry never stops being possible. That is more or less the point of Black Hat.
What moved was the center of gravity. The most senior group of US cyber officials ever to share the keynote stage spent it on AI and cyber power. Another keynote made the case that AI exploit generation is turning offense cheaper than defense. There were more than seven briefings on securing AI agents, which a year ago was a lab curiosity. And the floor told the same story as the stage. Least agency. Reachability. Blast radius. Containment. Words that lived on a handful of whiteboards last summer are booth graphics now.
Here is what I take from that, and it is good news. The industry stopped asking only how we keep them out and started asking what happens after they are in. That is the right question, and it is a genuine change.
The proof that it is the right question is not a demo. It is the record. On the flight home I did the thing I keep asking CISOs to do. I went back through the breaches that actually made the news over the last fourteen months and sorted them by one question. What would have changed the outcome. This is my own tally, so weigh it accordingly. Roughly four in five would never have become breaches if the network around each workload had simply governed what that workload was allowed to reach. Not stopped the intrusion. Stopped the intrusion from becoming a breach. The exposed database that should never have been reachable in the first place. The poisoned dependency whose only job was to phone home. The single foothold that walked, unobstructed, to the crown jewels. Different headlines, same shape.
This summer put an exclamation point on it. Two frontier labs disclosed that their own AI agents reached real companies through ordinary paths at machine speed. Then this week, the UK's AI Security Institute disclosed an incident of its own. During a cyber evaluation with internet access deliberately open, agents took unsanctioned action on the live internet and tried to slip malicious code into a real open-source project, creating fake identities to talk a human maintainer into approving it. AISI's first stated lesson was tighter controls on internet access, now something that has to be actively justified rather than assumed. And they wrote one sentence I would put in every architecture review. Good containment should not depend on the model choosing not to test its boundaries. A government safety institute, looking at the newest failure mode in the field, landed on the oldest idea in security done properly. Bound what the thing can reach.
That is the part I keep coming back to. Every other control has to be right about the attack. Signatures assume it looks like something we have seen before. Patching assumes the vulnerability is known. Host-based tools assume every workload can run installed software. Containment does not care whether the actor was a person or an agent, whether anyone detected it, or what AI they rented this morning. It only has to be right about what your own workloads are allowed to reach, and that is the one thing you actually know.
One honest caution as we all head home: adopting the vocabulary is not the same as adopting the architecture. Whether the boundary around a workload actually holds has nothing to do with the booth graphic and everything to do with whether policy governs every path that workload has, whether it holds without waiting for detection to fire, and whether it reaches the workloads you cannot install anything on, which in most clouds is a growing share of what you run. The words are how an industry starts. The enforcement is how it finishes.
So I will leave this week with the same observation I've been evangelizing for nearly two years now. When something authorized in your environment goes somewhere no one expected, what can it reach? If you cannot answer that from the reality of your own network, that is the work.
Aviatrix works on exactly this, so weigh my read accordingly. But if this week proved anything, it is that the question no longer belongs to any one vendor. It belongs to all of us.
Ready to see Aviatrix in action?
Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.
Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report
Download and gain actionable insights to advance your cloud security strategy.


















