Opening Session: Cyber Power in the Age of AI

Sean Cairncross (National Cyber Director · The White House), Misha Laskin (Co-founder and CEO · Reflection)

Black Hat USA 2026 · Day 1 · Main Stage

Overview

This Black Hat USA opening session featured a compelling dialogue between Sean Cairncross, the National Cyber Director for The White House, and Misha Laskin, Co-founder and CEO of Reflection, an AI company specializing in open models. The discussion, moderated by Laskin, delved into the profound implications of artificial intelligence on national cybersecurity, exploring what "cyber power" fundamentally means in an era defined by rapid AI advancement. Cairncross’s presence underscored the US government's commitment to engaging the private sector at the highest levels to address these evolving challenges.

Watch on YouTube

Key moments

  1. 2:00 Welcome to Black Hat USA 2026: Community and collaboration
  2. 4:26 Core question: Cyber power in the age of AI
  3. 5:00 National Cyber Director Shawn Cairncross and Misha Laskin introduced
  4. 6:00 Moderator Misha Laskin's opening remarks
  5. 7:00 Is the National Cyber Director the 'CISO of America'?
  6. 7:30 ONCD's twofold strategy: Industry and interagency collaboration
  7. 8:50 AI's exponential growth: spectacular and alarming

Opening Session: Cyber Power in the Age of AI

Speakers: Sean Cairncross (National Cyber Director, The White House); Misha Laskin (Co-founder and CEO, Reflection)

Conference: Black Hat USA

YouTube: https://www.youtube.com/watch?v=Ht9NfbmrKVw

Overview

This Black Hat USA opening session featured a compelling dialogue between Sean Cairncross, the National Cyber Director for The White House, and Misha Laskin, Co-founder and CEO of Reflection, an AI company specializing in open models. The discussion, moderated by Laskin, delved into the profound implications of artificial intelligence on national cybersecurity, exploring what "cyber power" fundamentally means in an era defined by rapid AI advancement. Cairncross’s presence underscored the US government's commitment to engaging the private sector at the highest levels to address these evolving challenges.

The talk emphasized the critical juncture at which the cybersecurity community finds itself: AI is not merely an incremental technological shift but a transformative force reshaping both offensive and defensive capabilities at an unprecedented pace. It influences global events, renders critical infrastructure more interconnected and vulnerable, and redefines the very foundations of identity and trust in digital ecosystems. This session aimed to dissect how state, private, and public sectors can align their efforts to navigate this complex landscape, ensuring that American innovation is both protected and leveraged for collective security.

At its core, the conversation highlighted the US administration's proactive stance, advocating for a collaborative, adaptable, and forward-leaning approach to cyber defense. Cairncross articulated a vision where innovation is fostered, strategic deterrence is established, and information sharing between government and industry becomes the bedrock of national cyber resilience. This is not a reactive response to a crisis, but a strategic effort to harness the positive potential of AI while mitigating its inherent risks responsibly and at speed.

Background

▶ Watch: Welcome to Black Hat USA 2026: Community and collaboration (2:00)

The rapid, "exponential" growth of artificial intelligence capabilities forms the backdrop for this critical discussion. Misha Laskin characterized this period as one where the rate of capability increase is both "spectacular and alarming," with new cyber capabilities emerging monthly. Sean Cairncross affirmed that this AI revolution is primarily an "American innovation" success story, promising enormous benefits across various sectors, from medicine to cybersecurity. Crucially, the current heightened focus on AI in cybersecurity is not a reaction to a catastrophic breach but rather a proactive effort to manage a positive technological leap.

The establishment of the National Cyber Director's office at the end of the first Trump administration marked a significant shift, aiming to provide a single point of policy coordination for cyber issues within the US government. Historically, cyber had grown adjacent to many domains without a unified strategic vision. This office was designed to integrate cyber considerations into broader national strategic ends and to leverage available tools more effectively. A key directive from the President of the United States, as highlighted by Cairncross, is the imperative for "hand in glove" collaboration with industry, recognizing that private sector innovators are indispensable to national security.

The inherent challenge in this rapidly evolving environment is balancing the need to stay ahead of adversaries with the equally vital goal of protecting the American innovation economy. Traditional regulatory regimes, Cairncross argued, would not only stifle growth but would become obsolete almost as soon as they were enacted due to the sheer speed of AI development. Therefore, the strategic imperative is to build flexible, adaptable structures that facilitate robust information sharing between industry and government, ensuring that AI benefits society responsibly and securely without impeding its progress.

Key Findings

▶ Watch: National Cyber Director Shawn Cairncross and Misha Laskin introduced (5:00)

The discussion revealed several critical findings and strategic orientations from the perspective of the US government regarding cyber power in the age of AI:

  1. AI as an Exposer of Latent Problems: AI models, while revolutionary, do not necessarily introduce entirely new problems. Instead, they bring existing, long-neglected issues (such as legacy systems, basic cyber hygiene deficiencies) to the surface with increased urgency. This highlights the foundational importance of addressing these persistent vulnerabilities.
  1. Incentive for Machine-Pace Remediation: A significant contribution of AI to cybersecurity is the creation of a powerful incentive for machine-pace remediation. Traditional human-speed responses are insufficient against AI-powered threats; therefore, AI itself offers a path to automated, rapid defense and mitigation. This technology is expected to come online "sooner rather than later."
  1. Vital Role of Open-Source AI: The US government views open-source AI as vital to the entire cyber ecosystem. It fosters innovation, supports startups, and drives technological leaps that might otherwise not occur. A strategic goal is to build and promote US open-source models to make them the "preferential adoption by planet Earth," ensuring American leadership and influence in this critical domain. This complements the role of proprietary models.
  1. Proactive and Dynamic Posture: The administration advocates for a "on your toes" rather than "on your heels" approach to cybersecurity. This dynamic posture emphasizes anticipating threats and leveraging insights from industry to get ahead of evolving problem sets, new technologies, and emerging threat actors. This proactive stance is seen as crucial for maintaining a strategic advantage.
  1. Introduction of Deterrence in Cyberspace: A central tenet of the National Cyber Strategy, released in March, is shaping adversary behavior through the concept of deterrence. This acknowledges the complexity of applying deterrence in cyberspace but emphasizes making it clear to those who would do harm that their actions will incur significant costs.
  1. Non-Regulatory, Collaborative Framework: The government's approach, particularly concerning an Executive Order on AI, is explicitly non-regulatory. Instead, it focuses on establishing a system of collaboration with industry to ensure responsible handling of AI technology. This involves continuous, evolving partnerships to secure systems and accelerate the deployment of defensive AI capabilities.
  1. New Paradigm of Government-Industry Partnership: A relationship between government and industry is being forged that, according to Cairncross, "hasn't existed before." This partnership is designed to create a resilient network of connections that can adapt rapidly to breaches or events, ensuring that form follows function in responding to cyber incidents quickly and effectively, rather than government operating in a vacuum.

Technical Deep Dive

▶ Watch: Moderator Misha Laskin's opening remarks (6:00)

While the talk primarily focused on high-level policy and strategic direction rather than specific code or architectural details, it articulated several key mechanisms and concepts that underpin the government's technical approach to cybersecurity in the age of AI. The "technical deep dive" here pertains to the strategic architecture and policy protocols being implemented.

Central to the discussion was the recognition that AI presents both an offensive and defensive paradigm shift. On the defensive side, AI offers the potential for machine-pace remediation. This is a critical concept, suggesting a future where AI systems can detect, analyze, and neutralize threats far faster than human operators, potentially at the speed of the attack itself. This capability is not yet fully realized but is a significant incentive driving innovation in the cybersecurity sector. The implication is a move away from reactive, human-intensive incident response towards automated, AI-driven defense mechanisms that can keep pace with rapidly evolving threats.

The role of open models versus proprietary models in the AI ecosystem was also addressed. The US government, through the National Cyber Director, explicitly stated its interest in fostering and pushing US open-source models. This isn't just about technological leadership; it's a strategic move to build a robust, transparent, and widely accessible foundation for AI development that can be adopted globally by allies and partners. The underlying "tech stack" – from foundational research to deployment – is seen as a domain where American innovation leads, and open-source contributions are crucial for maintaining that leadership and promoting collective defense.

The National Cyber Strategy, launched in March, serves as a foundational "protocol" for the government's cyber operations. Its lead piece, shaping adversary behavior, introduces the concept of deterrence into the cyber domain. While acknowledging its complexity, the strategy aims to make it unequivocally clear to malicious actors that cyberattacks against US interests will incur significant costs. This involves a multi-faceted approach, including offensive cyber capabilities, diplomatic pressure, and economic sanctions.

A concrete "technical" implementation of this deterrence strategy is the Executive Order on cybercrime signed concurrently with the National Cyber Strategy. This executive order designates ransomware actors and scam centers as transnational criminal organizations. This designation is not merely symbolic; it activates new authorities and enables the formation of inter-agency working groups. These groups, involving entities like the FBI and other law enforcement agencies, are empowered to conduct operations such as Operation Riptide, which focuses on:

  • Denying safe haven: Preventing criminal groups from operating freely from specific jurisdictions.
  • Taking down infrastructure: Disrupting the technical networks and command-and-control systems used by these organizations.
  • Denying benefits: Seizing illicit funds and assets derived from cybercrimes, thereby removing the financial incentive for such activities.

This approach represents a shift towards a more aggressive, coordinated, and resource-intensive effort to dismantle the economic and technical underpinnings of cybercrime, directly impacting the operational capabilities and incentives of threat actors. The executive order is specifically framed as "non-regulatory" for industry but establishes a framework for government and industry to collaborate on gaining insights into threat actor methodologies and leveraging private sector capabilities to achieve these disruptive ends. This collaboration forms a critical "inter-governmental and government-industry network" designed to be adaptable for rapid response to future incidents.

Demo / Proof of Concept

▶ Watch: ONCD's twofold strategy: Industry and interagency collaboration (7:30)

This particular Black Hat session was an opening keynote discussion and policy-focused conversation. As such, it did not include a technical demonstration or a proof of concept of any specific tool, vulnerability, or defensive mechanism. The content remained at a strategic and policy level, discussing governmental approaches and the broader implications of AI.

Defensive Implications

▶ Watch: AI's exponential growth: spectacular and alarming (8:50)

The insights shared by National Cyber Director Sean Cairncross offer clear, actionable implications for cybersecurity defenders across all sectors:

  1. Prioritize Basic Cyber Hygiene (Fix the Basics): Despite the advanced nature of AI threats, the most fundamental defensive implication is to address "low-hanging fruit" – the basic, often unsexy, cybersecurity practices. AI, as Cairncross noted, brings latent problems to the surface. This means organizations must elevate patching, strong authentication, network segmentation, and secure configurations to the top of their boardroom agendas. These foundational elements remain the first line of defense against both traditional and AI-enhanced attacks.
  1. Embrace AI for Machine-Pace Remediation: Defenders should actively explore and invest in AI-driven security solutions that offer machine-pace remediation. As AI accelerates attack capabilities, human-speed responses will become increasingly insufficient. This includes AI for threat detection, automated incident response, vulnerability management, and predictive analytics. Evaluating and integrating these technologies will be crucial for maintaining parity with evolving threats.
  1. Engage with Government Cybersecurity Initiatives: The National Cyber Director's office explicitly encourages engagement and feedback from the private sector. CISOs and security experts should proactively reach out, share insights on emerging threats, discuss effective defensive capabilities, and provide constructive criticism on government initiatives. This two-way communication is vital for shaping effective national strategies and ensuring that policy decisions are informed by real-world operational realities.
  1. Support and Leverage US Open-Source AI: Recognizing the strategic importance of open-source AI, defenders should consider contributing to and adopting US-developed open models where appropriate. This not only fosters innovation but also strengthens a collective defense ecosystem that benefits from transparency, community review, and shared development, aligning with the national goal of making US open-source the global preference.
  1. Understand and Contribute to Deterrence Efforts: Defenders should be aware of the government's efforts to introduce deterrence into cyberspace, particularly through initiatives like the Executive Order designating ransomware actors as transnational criminal organizations. By sharing intelligence on ransomware attacks, scam centers, and threat actor infrastructure, the private sector can directly contribute to operations like Operation Riptide, helping law enforcement deny safe havens, take down infrastructure, and seize illicit gains, thereby increasing the cost for adversaries.
  1. Build Adaptive, Collaborative Response Frameworks: The emphasis on a new paradigm of government-industry partnership highlights the need for organizations to develop internal systems and external relationships that facilitate rapid adaptation and response during a breach or significant cyber event. This means establishing clear communication channels, pre-defining roles, and practicing coordinated responses with both peer organizations and government agencies to ensure seamless remediation.
  1. Drive Cybersecurity as a Business Priority: Cairncross stressed the need to raise cybersecurity as a "priority number one" on CEOs' desks. Defenders must articulate the strategic and financial risks of cyber vulnerabilities in business terms, ensuring that adequate resources and executive attention are dedicated to proactive defense and resilience-building, rather than viewing security as merely a cost center.

Key Takeaways

  • AI is a Transformative Force: AI is fundamentally reshaping cybersecurity, demanding a proactive, adaptive, and collaborative approach from all sectors.
  • Government-Industry Partnership is Paramount: The speed of AI innovation necessitates an unprecedented level of collaboration and information sharing between government and the private sector to secure national interests.
  • Open-Source AI is Strategic: The US aims to lead in and foster the adoption of American open-source AI models as a vital component of the global cyber defense ecosystem.
  • Deterrence is Key to National Cyber Strategy: The US is actively implementing strategies to shape adversary behavior by increasing the costs associated with cyberattacks, as exemplified by the Executive Order on cybercrime and operations like Riptide.
  • Basic Cyber Hygiene Remains Foundational: Even with advanced AI threats, addressing fundamental cybersecurity weaknesses (the "low-hanging fruit") is critical, as AI often exposes these latent vulnerabilities.
  • Engagement is Encouraged: The National Cyber Director's office actively seeks engagement, feedback, and insights from cybersecurity professionals to inform and strengthen national cyber policy and strategy.

About the Speaker(s)

Sean Cairncross serves as the National Cyber Director for The White House. He is a key leader working at the intersection of policy, strategy, and cybersecurity at the highest levels of government, directly influencing how the US addresses national security, economic competitiveness, and the evolving cyber landscape. His office was established to provide a single point of policy coordination for cyber issues.

Misha Laskin is the Co-founder and CEO of Reflection, a company focused on building "open models," specifically American open models. As moderator for this session, Laskin brought an industry perspective on AI innovation and its rapid advancements to the discussion.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Standard executive keynote that says almost nothing you couldn't get from a press release. Cairncross confirms the government likes open-source AI, wants industry collaboration, and plans to be tough on ransomware. No new programs, no budget numbers, no timelines, no insider signal.

Heather Calloway (CISO) — WEAK

A policy-level conversation with the National Cyber Director that stayed firmly in talking-points territory. If you've read any three government cyber strategy documents in the past two years, you heard nothing new here. The 'deterrence' framing sounds good but was never operationalized in a way that tells a CISO what to expect or do differently.

→ Top-rated talks at Black Hat USA 2026

All talks from Black Hat USA 2026