ZscalerZero TrustAIAgentic AI

Zscaler Is Bringing Agentic AI Security to Black Hat 2026, and I Have Thoughts About Booth Culture

August 3, 2026 · Brian Deitch

Black Hat 2026 is this week, August 4 through 6, and Zscaler just dropped a preview of what it's bringing to booth #2557. Before I get into the actual substance, and there is substance, I have to acknowledge what Black Hat has become.

For the uninitiated: Black Hat is where the entire security industry piles into a Las Vegas convention center to talk about how everything is on fire, then walks a show floor of 400 vendors who all claim to be the fire department. There are t-shirts. There are stress balls shaped like padlocks. There is at least one booth with a magician, and you will genuinely wonder whether the magician understands the product he's standing in front of. He does not. Nobody does. That's the point of a magician.

So yeah, I'm going in with full disclosure: I work at Zscaler. The enthusiasm below is informed, not neutral. But the reason I'm actually writing this instead of just posting the booth number is that the thing Zscaler is demoing is the thing I've been banging on about for months.

The Actual Pitch

The theme is securing agentic AI at machine speed. Here's the line from the preview that framed it well:

When copilots and autonomous agents can move data, call tools, and trigger actions in seconds, the blast radius of a single compromise grows exponentially.

— Diana Shtil, Sr. Product Marketing Manager, Zscaler

That's the whole problem in one sentence. The old security model assumed a human in the loop. Humans are slow. Humans take coffee breaks. Humans forward the phishing email to IT with the subject line "is this real??" before clicking it anyway.

Agents don't do any of that. An agent compromised at 2:00pm can move data, call three tools, spawn a sub-agent, and touch a database before the SOC analyst has finished reading the first alert. You cannot "detect later" what already happened at machine speed. By the time the dashboard refreshes, the raccoon is already in the attic and it has a service account.

What They're Actually Showing

Zscaler laid out four things the platform is built to do, and I'll translate each one out of marketing-speak because that's a service I provide for free:

Secure every AI interaction. Visibility and control across AI apps and copilots. Translation: know which AI tools your people are actually using, including the eleven browser extensions nobody told procurement about.

Broker every agent action. Governing agent behavior and tool use in agentic workflows. Translation: an agent shouldn't get to do a thing just because it wants to. Somebody, or in this case something, checks the policy first.

Hunt at machine speed. Surface risk earlier, accelerate response. Translation: if the attack moves at machine speed, your hunting has to too, because a human squinting at logs is bringing a fork to a drone fight.

Stop every threat. Reduce attack surface, apply consistent policy across users, apps, branches, and AI agents. Translation: the whole zero trust thing, now extended to entities that don't have a badge or a laptop.

The Part I Actually Respect

Buried in the session list is one titled "90 Days with Frontier AI. What We Learned." That's a talk about actually living with this stuff in production for three months, not a slide that says "AI-Powered" in a gradient font. There's also a ThreatLabz session on the latest attack trends and one specifically on going from zero trust to agentic security.

That's the difference between a booth and a contribution. Anybody can print "Secure Your AI" on a banner and hand you a fidget spinner. Standing up on the theater stage and saying "here is what actually broke when we ran frontier AI for 90 days" is the useful version. I will be at that one, probably eating a free pretzel, taking it seriously.

Bottom Line

The security industry loves to treat Black Hat as a costume party where everyone dresses up as the solution to a problem they described five minutes earlier. Fair. But the underlying shift here is real: enterprises are deploying AI agents right now, faster than most of them can secure, and the attack surface is quietly mutating from "people clicking apps" to "software entities acting on behalf of people, apps, and other agents."

Zero trust was the answer when the risk was users. It's still the answer now that the risk is agents. It just has to move faster than the thing it's guarding.

If you're at Black Hat this week, booth #2557. Come argue with me about the magician.

Full post: Secure Agentic AI at Machine Speed: Meet Zscaler at Black Hat 2026

zscalerblack-hatagentic-aizero-trustai-securityevents
All postsDiscuss on LinkedIn