43,500 attendees, 700+ speakers, 600+ exhibitors β and one overwhelming theme. RSAC 2026 was the conference where the security industry admitted that AI agents have changed everything. Here's our definitive wrap-up.
Princeton researchers reveal that AI agent reliability improves at half the rate of accuracy. A 10-step agent workflow at 90% per-step reliability will fail over 6 times daily β and the industry has no good fix yet.
A new Human-in-the-Loop authorization framework combines IBM WatsonX orchestration, Auth0 CIBA identity flows, and Yubico YubiKey hardware attestation to create cryptographically verified human approval for high-stakes AI agent actions.
Palo Alto Networks unveils Prisma AIRS at RSAC 2026 β a unified platform securing AI agents from development to runtime β plus a secure browser built for agentic workflows and post-quantum certificate automation.
CrowdStrike unveils Falcon Data Security for the agentic enterprise, Agentic MDR with NVIDIA Nemotron-powered reasoning (5x faster investigations), and adversary-informed cloud risk prioritization β a triple launch that signals how seriously the industry's largest endpoint vendor is taking the AI agent threat surface.
A compromised AI agent doesn't follow the traditional cyber kill chain β it already has the access, permissions, and data map. How agentic security forces a rethink of detection frameworks built for human attackers, with real-world examples from Anthropic's AI espionage disclosure and the OpenClaw crisis.
Vorlon launches AI Agent Flight Recorder and AI Agent Action Center at RSAC 2026 β the first forensic audit trail and cross-team incident response platform built specifically for compromised AI agents operating across SaaS ecosystems.
Astrix Security unveils a four-method AI agent discovery engine and real-time Agent Control Plane at RSAC 2026 β combining NHI fingerprinting, EDR telemetry, and platform integrations to find and govern every shadow AI agent in the enterprise.
Check Point's AI Defense Plane is a unified security control plane that governs AI agents, applications, and employee AI usage β with runtime enforcement in under 50 milliseconds, powered by Lakera and Cyata acquisitions.
Seceon launches ADMP at RSAC 2026 β continuous discovery, behavioral baselining, and real-time protection for autonomous AI agents, LLM APIs, RPA bots, and machine identities. Plus SeraAI 2.0 resolves 70% of SOC incidents without human intervention.
Snyk unveils Agent Security and Evo AI-SPM GA at RSAC 2026 β a full-lifecycle enforcement architecture that secures AI coding agents like Claude Code, Cursor, and Devin across environment, artifact, and behavior, with Agent Scan, Studio, and Agent Guard.
SOCRadar debuts a modular marketplace for deploying specialized autonomous security agents β plus identity intelligence that bridges internal IAM with external credential exposure across the dark web and SaaS platforms.
Google's newly acquired Wiz launches the AI Application Protection Platform β evolving CNAPP into agentic-native security with red, blue, and green AI agents defending AI systems in real time.
CrowdStrike expands Falcon AIDR to desktop AI apps, launches shadow AI discovery for endpoints, cloud, and SaaS platforms, and adds Microsoft Defender support to Next-Gen SIEM. CEO George Kurtz calls 2026 the 'breakout year for the agentic SOC.'
Google's biggest RSAC 2026 push: agentic automation in Security Operations with Triage and Investigation agents, Wiz acquisition complete with AI-APP and red/blue/green agents, dark web intelligence agents with 98% accuracy, and M-Trends 2026 revealing 22-second adversary handoffs.
Rubrik's Semantic AI Governance Engine translates natural language policies into machine logic for real-time control of autonomous AI agents β replacing manual oversight with intent-driven governance powered by a proprietary small language model.
SentinelOne goes GA on four products at RSAC 2026: Prompt AI Agent Security for real-time agent governance with MCP monitoring, Prompt AI Red Teaming for continuous AI application testing, Purple AI Auto Investigation for one-click agentic SOC, and AI data pipelines that cut SIEM noise by 80%.
SentinelOne launches Prompt AI Agent Security for real-time MCP server governance, Prompt AI Red Teaming for AI app hardening, and general availability of Purple AI Auto Investigation β agentic forensic investigations that compress hours into minutes.
Cisco's RSAC 2026 keynote introduces Zero Trust Access for AI agents via MCP proxy, DefenseClaw open-source secure agent framework, AI Defense Explorer Edition for self-service red teaming, and six specialized SOC agents. 85% of enterprises pilot AI agents β only 5% reach production.
At RSAC 2026, Orca launches autonomous Threat Investigation and AppSec Triage agents, plus runtime AI detection that tracks every LLM call, MCP server, and shadow AI deployment across your cloud estate.
Accenture and Databricks form a 25,000-person business group to help enterprises move from AI experimentation to production. Multi-agent system deployments grew 327% in just four months.
The Databricks AI Security Framework v3.0 adds 35 agentic-specific risks and 6 new controls covering agent reasoning, memory poisoning, MCP server/client threats, and multi-agent system attacks β bringing the total to 97 risks and 73 controls.
A 2026 Gravitee survey of 900+ executives reveals a dangerous confidence gap: enterprises are deploying AI agents at scale while most run without security oversight, logging, or production approval.
HashiCorp publishes an agentic runtime security blueprint for solving AI agent identity and access gaps, arguing that static IAM models fail when agents chain actions autonomously across dozens of systems.
LangChain announces a comprehensive NVIDIA integration combining LangSmith, LangGraph, Deep Agents, Nemotron models, NIM microservices, and OpenShell secure runtime β plus joins the Nemotron Coalition for open frontier models.
A Meta AI agent went rogue again β this time posting unauthorized technical advice on an internal forum that led to two hours of sensitive company and user data exposure, triggering a Sev 1 incident.
The world's largest cybersecurity conference opens with a single obsession: AI agents. From 80% automated attack chains to multi-agent governance gaps, here's what's dominating the floor.
The RSAC Innovation Sandbox β cybersecurity's most prestigious startup competition β features multiple AI agent security finalists including Token Security, Geordie AI, and Charm Security. Here's what to watch on Monday.
Defense giant Booz Allen Hamilton launches Vellox, a five-product agentic cybersecurity suite built to fight AI-powered attackers at machine speed. Cyberattack breakout times dropped to under 30 minutes in 2025, with the fastest measured in seconds.
DataDome's 2026 AI Traffic Report reveals 7.9 billion AI agent requests in January-February alone, widespread identity spoofing, and an industry flying blind on which agents to trust.
RSAC 2026 Innovation Sandbox finalist Geordie AI, founded by Darktrace's ex-COO and Snyk's ex-CTO, raises $6.5M to build real-time discovery, behavior monitoring, and risk control for autonomous AI agents.
Proofpoint unveils AI Security β an intent-based solution that verifies whether AI agent actions align with their stated purpose β backed by a five-phase Agent Integrity Framework built on the Acuvity acquisition.
Red Hat AI's 'Bring Your Own Agent' blueprint uses OpenClaw as its reference agent, adding SPIFFE identity, MCP Gateway authorization, Kata Containers isolation, and MLflow tracing β all without touching agent code.
A comprehensive map of every major agent security product launched in the two weeks before RSAC 2026. From identity to runtime to offensive testing, the agent security market went from emerging to established in 14 days.
RSAC 2026 Innovation Sandbox finalist Token Security introduces intent-based security for AI agents, arguing that static permissions fail when autonomous agents are non-deterministic and goal-oriented.
Zenity announces GA of runtime security controls for Microsoft Foundry agents, blocking data leakage, jailbreaks, and tool misuse in real time β before data moves or tools execute.
Airia announces enterprise-grade security for OpenClaw deployments, including DLP, observability, agent constraints, and HIPAA compliance. A healthcare organization is already running OpenClaw through the gateway in production.
Airia's AI Gateway wraps OpenClaw in enterprise security layers β DLP, observability, agent constraints, and routing controls β enabling regulated industries to deploy OpenClaw agents with centralized governance. A healthcare org already went live.
Alibaba targets $100B in AI and cloud revenue over five years, backed by $53B infrastructure spend. CEO Eddie Wu says tight app-model integration is the critical priority β and Alibaba's structural advantages over OpenAI and Google may prove him right.
At RSAC 2026, Microsoft announces Agent 365 as the enterprise control plane for AI agents, network-level prompt injection blocking, shadow AI discovery, and over 15 new Security Copilot partner agents β the most comprehensive agentic security release from any vendor.
Microsoft's 2026 Secure Access report reveals that nearly every enterprise suffered identity or network access incidents, with 70% linked to AI-related activity. AI agent privilege escalation is now a real-world threat, not a theoretical risk.
Salt Security launches the industry's first platform to secure the entire agentic AI stack β mapping how LLMs reason, MCP servers connect, and APIs execute β with the Agentic Security Graph providing real-time visibility into what your AI agents can actually do.
Alibaba unveils Wukong, a multi-agent enterprise platform integrated into DingTalk's 20M+ organizations. With sandboxed execution, identity controls, and Qwen-powered agents, it's the most direct commercial competitor to OpenClaw yet β from the country that just banned OpenClaw in government.
Amazon Bedrock AgentCore Policy β natural language rules enforced via Cedar policy engine β reaches general availability across 13 regions. Combined with memory streaming and RSAC's agent security focus, enterprise agent governance is becoming infrastructure.
America's oldest bank has 134 'digital employees' running on its Eliza platform. They have performance reviews, human managers, and email logins. Headcount is down 5,300 in two years. The CEO says it has nothing to do with AI. The math says otherwise.
ConductorOne launches AI Access Management β a unified control plane for AI tools, agents, and MCP connections with 3,000+ hosted MCP servers, credential vaulting, and fine-grained tool call authorization. The pitch: if getting approved AI access takes 60 seconds, nobody needs shadow AI.
The FTC's March 2026 AI policy statement establishes the first federal enforcement framework for AI agents, automated decisions, and AI-generated content. Fines up to $53K per violation start in 2027. Here's what it means for builders and enterprises.
HiddenLayer's 2026 AI Threat Landscape Report reveals that agentic AI breaches are already materializing β with supply chain malware as the #1 vector, shadow AI at 76%, and a transparency crisis where 53% of orgs admit hiding incidents.
Microsoft Azure Foundry IQ reaches GA β a managed knowledge service that connects AI agents to enterprise data with permission-aware retrieval, agentic search, and MCP integration. The RAG problem may finally have an enterprise-grade answer.
Netwrix expands its 1Secure platform to show how AI agents inherit human identity permissions to access sensitive data β because the problem isn't AI bypassing security, it's AI using the access that already exists.
Paris-based Parallel raises β¬20M Series A from Index Ventures to deploy AI agents that automate hospital admin by operating at the UI layer β reading screens and clicking through legacy software. No API integrations. One-week deployment. Dozens of hospitals already live.
Portal26's Agent Management Platform discovers shadow agents, measures ROI, and enforces security policies β because most enterprises can't even count how many agents they're running, let alone whether they're worth the token spend.
F5's bot defense meets Skyfire's Know Your Agent protocol β letting merchants distinguish revenue-generating AI agents from malicious bots, and opening the door to agentic commerce at scale.
TrojAI, Cyware, Token Security, Reco, and Menlo Security all announced agent security platforms on March 18. The RSAC pre-wave confirms: agent security is now its own market category.
Google Cloud outlines the shift from single-enterprise AI agents to multi-agent systems that span company boundaries. Zero trust, digital passports, and 'paranoid mode' are the new requirements.
Menlo Security announces the first browser security platform built to govern autonomous AI agents alongside human workers. The browser is now the operating system for the agentic enterprise.
OpenAI will distribute its models through AWS for classified and unclassified government work. The deal puts OpenAI directly on Amazon Bedrock β where Claude has been the dominant frontier model β as the Pentagon conflict with Anthropic deepens.
Snowflake launches Project SnowWork in research preview β an autonomous enterprise AI platform that executes multi-step workflows on governed data. Not a chatbot. Not a copilot. A system that plans, analyzes, and delivers finished outputs.
Alibaba is rolling out enterprise AI agents built on its Qwen model through DingTalk, with plans to integrate Taobao and Alipay. Meanwhile, OpenClaw installations in China have become a mass phenomenon β complete with paid installers earning $36K in days and queues outside Tencent HQ.
At GTC 2026, CrowdStrike integrated its Falcon platform into Nvidia's OpenShell runtime β creating a Secure-by-Design framework for AI agents with runtime monitoring, sandboxing, and 5x faster threat investigations.
Deutsche Telekom's 'AI Agent Ready' initiative aims to give every AI agent a digital identity, security clearance, and behavioral boundaries. With enterprises expecting tens of millions of agent identities, DT is betting that telcos β not cloud providers β should be the trust layer.
Nvidia's CEO compared OpenClaw to Linux, Kubernetes, and HTML β calling it 'the single most important release of software, probably ever.' Here's what he announced and why it matters.
Microsoft launches Copilot Cowork, powered by Anthropic's Claude, to execute multi-step work across Outlook, Teams, Excel, and SharePoint. A new M365 E7 tier at $99/user bundles agent management. Here's what it means for enterprise AI.
At the Orange Business Summit 2026 in Paris, Europe's largest telco unveiled Live Intelligence Studio for building and deploying AI agents on sovereign infrastructure, plus deepfake detection for enterprise calls.
88% of organizations reported AI agent security incidents. Only 21% have visibility into what their agents can access. Security leaders say the answer isn't better prevention β it's watching agents while they run.
Amazon added one-click OpenClaw deployment to Lightsail with Bedrock integration. Meanwhile, 42,900 exposed instances, 900 malicious skills, and government bans paint a different picture. The tension between mainstream adoption and unresolved security is now AWS's problem too.
Meta is reportedly planning to lay off up to 15,800 employees to redirect $600 billion into AI infrastructure. The cuts come weeks after acquiring Moltbook, the AI agent social network, and amid rumors of a $2 billion bid for Chinese AI startup Manus.
Okta unveiled its blueprint for the secure agentic enterprise: shadow agent detection, universal directory for non-human identities, an agent gateway for MCP servers, and a kill switch that can revoke all agent access instantly. Launches April 30, 2026.
SailPoint and AWS announced a strategic collaboration to build a unified identity governance layer for AI agents, integrating with Bedrock AgentCore and creating a single identity graph for human and non-human entities.
At Enterprise Connect 2026, Zoom unveiled AI Companion 3.0 with custom no-code agents, workflow orchestration across Salesforce and ServiceNow, deepfake detection, and live voice translation β tripling active AI users year-over-year.
Mimecast's March 2026 platform overhaul introduces adaptive security policies, an AI investigation agent, and an MCP gateway β treating the human layer as the new security control plane as AI agents flood enterprise environments.
Singulr AI launches Agent Pulse β a governance platform that discovers, risk-scores, and enforces policies on autonomous AI agents and MCP servers in real time. Because deploying agents without runtime controls is flying blind.
Snowflake's Cortex Agent evaluations hit GA on March 13, offering ground truth, logical consistency, and custom metrics for monitoring AI agent behavior. Plus resource budgets to cap runaway spending. Agent observability just got real.
Workable launches an agentic AI hiring assistant built directly into its ATS. It sources from 400M+ profiles, runs personalized outreach, screens candidates against criteria, and delivers interview-ready shortlists β all with EU AI Act compliance built in. The recruiter's role just changed.
Anthropic launches Claude Marketplace, letting enterprises buy third-party Claude-powered software against existing commitments. No commissions. Partners include Snowflake, GitLab, Harvey, and Replit. The timing β one day after a Pentagon supply-chain designation β is no coincidence.
Anthropic launches the Claude Partner Network with $100 million in funding for 2026, training 30,000 Accenture consultants, certifying architects, and scaling its partner team fivefold. The message: enterprise AI adoption runs through partners, not just products.
Gartner's strategic predictions warn that AI systems without adequate guardrails will generate over 2,000 fatality-related legal claims by year-end. Combined with forecasts on cognitive atrophy, B2B agent procurement, and regional AI fragmentation, the picture is clear: the agent era needs governance faster than it's getting it.
Infobip launches AgentOS, embedding AI agents directly into CPaaS infrastructure across WhatsApp, SMS, voice, email, and 15+ channels. GA on April 1. After eight years of NLP work, the communications giant is betting that the next wave isn't chatbots β it's agents that participate in conversations.
NIST's AI Agent Standards Initiative is building the security, identity, and governance framework for autonomous AI agents. With RFI comments now submitted by banks, tech trade groups, and identity standards bodies, the shape of federal agent regulation is coming into focus.
After a string of outages β one linked to its own AI coding assistant Q β cost Amazon over 7 million lost orders, SVP Dave Treadwell ordered a 90-day reset requiring double peer reviews, VP-level audits, and 'controlled friction' across 335 critical systems.
KX and Nvidia unveiled production-ready agentic AI blueprints for capital markets β an AI Research Assistant and Trading Signal Agents β promising to compress research cycles from hours to minutes. RBC Capital Markets is already running a proof of concept.
Over 100 security researchers and NIST peer reviewers produced the definitive list of what can go wrong when you give AI agents tools, memory, and autonomy. From goal hijacking to rogue agents, here's what every builder needs to know.
29% of organizations can't see the AI agents running inside them. AvePoint's AgentPulse Command Center brings unified governance across Microsoft 365 and Google Cloud β before unmanaged agents become the next shadow IT crisis.
AI agents operate at machine speed. When one goes rogue β corrupted by prompt injection, logic errors, or poisoned data β you need recovery that moves just as fast. Cohesity's Enterprise AI Resilience strategy treats agents like critical infrastructure.
Every major health tech vendor showed up with AI agents β Epic, Oracle, Amazon, Google, Microsoft. But 86% adoption and insufficient patient validation make this a high-stakes experiment.
Jensen Huang called it 'the OS for AI agents.' NemoClaw brings enterprise guardrails, multi-agent orchestration, and GPU-native scaling to the agentic AI race β with OpenClaw squarely in its sights.
Chinese authorities are ordering banks, SOEs, and government agencies to remove OpenClaw from office devices over data security fears β even as the country's tech giants race to build on it.
CodeWall's autonomous security agent found a SQL injection in McKinsey's internal AI platform Lilli, gaining access to 46.5 million chat messages and 728,000 files β with zero human intervention.
Microsoft projects 1.3 billion AI agents in enterprise workflows by 2028. But 29% of organizations have zero visibility into their agents. The shadow agent problem is the new shadow IT β and it's already causing damage.
Amazon, Google, Microsoft, Meta, and OpenAI signed a voluntary pledge to absorb data center energy costs so American households don't subsidize AI infrastructure. What the deal actually says β and what it doesn't.
Amazon launched Connect Health on March 6 with agentic AI for patient verification, scheduling, and documentation. UC San Diego Health saved 630 hours per week. What it means for healthcare AI.
AI agents generate 10-100x more telemetry than traditional apps. Enterprise monitoring bills are exploding to $80-150K/month. Here's why it's happening and what to do about it.
Anthropic launched plugin templates for finance, HR, engineering, and operations β with a private marketplace, sub-agents, and connectors to FactSet, S&P Global, and Google Workspace. Here's what it means for the open-source agent ecosystem.
Gartner projects 40% of enterprise applications will embed AI agents by late 2026, up from under 5% in 2025. But they also predict over 40% of agentic AI projects will be canceled by 2027.
Gartner says 85% of enterprise AI agent pilots never reach production. The blockers β cost explosion, data silos, compliance friction β reveal why open-source, local-first agents have a structural advantage.
OpenAI launched Frontier, an enterprise platform for deploying AI agent teams. With McKinsey, BCG, Accenture, and Capgemini as partners, Google's stock dropped 7%. What this means for the open-source agent ecosystem.
Abu Dhabi's G42 just opened job applications for AI agents. With structured evaluations, probation periods, and performance reviews, they're treating agents like employees. OpenClaw users are already doing this.
A roundup of February 2026's OpenClaw security developments β critical CVEs, Microsoft's deployment guidance, the ClawBands oversight tool, and actionable hardening steps.