Published Security3 min read
Washington's top cyber official argues against AI rules, so governance lands in your contracts
At Black Hat USA 2026 the National Cyber Director made the case that AI regulation would stifle innovation and lag the technology. The accountability gap for agentic AI does not close on its own.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- AI dominated the conversation at Black Hat USA 2026, including a large number of presentations claiming AI was in some way responsible for current cyberthreats.
- The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials.
- Sean Cairncross, the White House National Cyber Director, spoke first and set out the case that regulation of AI would both stifle innovation and development and struggle to keep pace with the speed at which AI is currently moving.
- Cairncross said "AI is a tremendous story of American innovation" and made various other comments on how America leads the world in the field.
- Cairncross noted that the US government is looking at ways to build a US open-source infrastructure that the rest of the world can benefit from.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Sean Cairncross, the White House National Cyber Director, opened Black Hat USA 2026 by arguing that regulating AI would both stifle innovation and development and struggle to keep pace with how fast the technology is moving, according to ESET's WeLiveSecurity account of the keynote [3]. For anyone buying or deploying agentic systems, the reasonable planning assumption is now that near-term guardrails come from procurement terms, contracts and internal policy, not from a federal rule.
The framing was national rather than technical. Cairncross said "AI is a tremendous story of American innovation" and made several other comments about US leadership in the field [4]. He also said the US government is looking at ways to build a US open-source infrastructure that the rest of the world can benefit from [5]. The WeLiveSecurity writer, who was in the room, noted that one of the companies named as instrumental to "AI made in America" is based in London [6], and characterised the keynote session overall as feeling like a party-political speech ahead of the forthcoming mid-terms [14].
The rest of the opening block was staffed at the same level: Nick Andersen, Acting Director of CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman, Assistant Director of the FBI's Cyber Division [7]. The FBI pointed to Operation Riptide, which it said resulted in arrests of more than 200 people allegedly engaged in cybercrime [8]. The panel discussed vulnerabilities now being found by AI-powered systems in large volumes and at speed [9], which prompted CISA's representative to call for "ruthless prioritization" and to stress industry collaboration [10]. Pressed on staffing, Sutton offered an analogy: you do not want a pediatrician performing heart surgery [11].
Read as a set of asks, that is thin. On the record in this account, the government's requests to industry were prioritisation, collaboration and an eventual open-source infrastructure play; no new federal AI rulemaking was put on the table [18]. The WeLiveSecurity author's objection is that without some form of regulation the boundaries on the use of AI remain blurred [16].
The most useful sentence of the week came from a vendor, not a podium. David Weston of Microsoft said, in summary, that AI agents authenticate, invoke tools and inherit permissions the same way a human employee does, but without the oversight, policy and governance needed to make them accountable [13]. That is a controls problem you already know how to price: identity lifecycle, entitlement review, least privilege, logging of tool invocation. The WeLiveSecurity view is that the technology remains within human control, and that if it is not under control the answer is to switch it off and re-task it with the correct controls in place [17]. Blunt, and cheaper than the alternative.
Three things to watch. Whether the promised US open-source infrastructure effort produces anything a defender can use [5]. Whether CISA turns "ruthless prioritization" into published guidance rather than a slogan, given the volume of AI-discovered vulnerabilities [10][9]. And whether the specialisation gap Sutton described gets funded or gets a training budget [11].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
AI dominated the conversation at Black Hat USA 2026, including a large number of presentations claiming AI was in some way responsible for current cyberthreats.
- [2]
The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials.
- [3]
Sean Cairncross, the White House National Cyber Director, spoke first and set out the case that regulation of AI would both stifle innovation and development and struggle to keep pace with the speed at which AI is currently moving.
- [4]
Cairncross said "AI is a tremendous story of American innovation" and made various other comments on how America leads the world in the field.
- [5]
Cairncross noted that the US government is looking at ways to build a US open-source infrastructure that the rest of the world can benefit from.
- [6]
During the opening talks, companies described as instrumental to the innovation of 'AI made in America' were mentioned; the report's author notes one of those companies is based in London.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- welivesecurity.comAug 12Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Additional citations
- WeLiveSecurity (ESET) conference report
- WeLiveSecurity (ESET)
- WeLiveSecurity (ESET) account of the Black Hat USA 2026 keynote
- WeLiveSecurity (ESET) author's observation
- FBI, as reported by WeLiveSecurity (ESET)
- CISA, as reported by WeLiveSecurity (ESET)
- Katherine Sutton, as reported by WeLiveSecurity (ESET)
- David Weston, Microsoft, as reported by WeLiveSecurity (ESET)
- WeLiveSecurity (ESET) author's opinion



