San Francisco skyline with Bay Bridge at sunset, California, USA

Key takeaways from the RSAC Conference 2026

March 23-26, 2026 | San Francisco, California


The 35th Annual RSAC Conference 2026 focused on the shift from experimental generative AI to agentic AI—autonomous systems capable of planning and acting independently within security environments. Sessions emphasized how AI is now embedded across cybersecurity architectures, transforming Security Operations Centers (SOCs), threat detection, and response while simultaneously expanding the attack surface and introducing new forms of machine-driven risk. Closely tied to this shift was an emphasis on AI security and governance, including managing non-human identities, preventing “shadow AI,” and defining CISO and board-level accountability for autonomous systems. Additional key topics included post-quantum cryptography, long-term data protection, security platform consolidation, and geopolitical cyber threats impacting critical infrastructure.

With over 44,000 attendees, 600 exhibitors and 700 speakers, RSAC Conference 2026 serves as the premier global platform for the cybersecurity community. In addition to meeting with clients, alliance partners, media and analyst relations firms, EY professionals participated in four sessions featuring clients and industry leaders, spotlighting nation-state cyber threats, cyber risk governance, and the legal and ethical challenges of AI. Topics included campaigns targeting U.S. critical infrastructure, improving board- and regulator-level cyber risk reporting using FAIR’s quantitative, financial-based approach, and examining the unresolved conflict between data-erasure laws and the technical irreversibility of large language models. They also explored AI accountability, focusing on the need for explainability and traceability in AI decision-making to meet evolving legal, regulatory, and audit expectations as AI systems become more autonomous and impactful.


Watch the conversation on cybersecurity, and the rise of AI

Kapish Vanvaria, EY Global and Americas Risk Consulting Lead and Dan Mellen, EY Global Cyber Chief Technology Officer join TheCube for an exclusive interview on the the current cybersecurity landscape and the rapid rise of AI.



AI in Cybersecurity 2026: Agentic AI, autonomous threats and the future of defense

A survey of 500 senior security leaders examined how organizations measure AI’s value in security operations and plan budgets over two years.


Trust is essential for organizations adopting AI

Watch Reuters on the Road featuring Sarah Liang, Ganesh Devarajan and Emmett Koen, CISO of Mondelēz, discuss trust as essential for organizations adopting AI and the importance of a strong governance framework.


Our latest thinking

Responsible AI monitoring

As AI evolves from prediction to autonomous action, businesses need a framework for effective AI monitoring across governance, risk and performance.

Why responsible AI has become a growth strategy

Responsible AI designed into systems lets organizations scale faster, navigate fragmented rules and turn risk into trust and growth. Read more.

How do you build a security roadmap for a shifting AI terrain?

Protecting the enterprise in an age of autonomous threats and the future of defense; EY research and insights on AI cybersecurity in 2026.

AI risk management: establishing safe and effective deployment

Discover strategies for mitigating AI risks while enhancing deployment confidence, enabling your organization to thrive in a competitive landscape.