The 35th Annual RSAC Conference 2026 focused on the shift from experimental generative AI to agentic AI—autonomous systems capable of planning and acting independently within security environments. Sessions emphasized how AI is now embedded across cybersecurity architectures, transforming Security Operations Centers (SOCs), threat detection, and response while simultaneously expanding the attack surface and introducing new forms of machine-driven risk. Closely tied to this shift was an emphasis on AI security and governance, including managing non-human identities, preventing “shadow AI,” and defining CISO and board-level accountability for autonomous systems. Additional key topics included post-quantum cryptography, long-term data protection, security platform consolidation, and geopolitical cyber threats impacting critical infrastructure.
With over 44,000 attendees, 600 exhibitors and 700 speakers, RSAC Conference 2026 serves as the premier global platform for the cybersecurity community. In addition to meeting with clients, alliance partners, media and analyst relations firms, EY professionals participated in four sessions featuring clients and industry leaders, spotlighting nation-state cyber threats, cyber risk governance, and the legal and ethical challenges of AI. Topics included campaigns targeting U.S. critical infrastructure, improving board- and regulator-level cyber risk reporting using FAIR’s quantitative, financial-based approach, and examining the unresolved conflict between data-erasure laws and the technical irreversibility of large language models. They also explored AI accountability, focusing on the need for explainability and traceability in AI decision-making to meet evolving legal, regulatory, and audit expectations as AI systems become more autonomous and impactful.