RSAC 2026: A Product Designer’s Perspective​​​​​​​
Six Lessons About AI Cybersecurity Risks and How Product Design Could Help​​​​​​​
I walked out of Moscone Center in San Francisco with my head buzzing from all the news about AI-powered attacks and the new technology designed to get ahead of the rapidly expanding digital landscape. Here are the six lessons I learned to help us anticipate threats from high-reliance on automation. 


Lesson 1: Take AI Security Threat Seriously
AI-powered attacks are faster and more accurate than traditional techniques. According to VIPRE, 40% of all cyberattacks use AI to bypass standard security measures. And that number is expected to continue to rise.
•  Hackers are using GenAI and ML to gather information, exploit weaknesses, and create highly personalized, urgent and spoofed phishing campaigns.

•  AI-powered cyberattacks have already proved effective against the energy (power grids), telecom, government, financial sectors, healthcare, emergency and other high stakes targets.
The proliferation of AI Agents is a tough new challenge.


Lesson 2: Reduce Human Stress and Burnout to Improve Security in the Age of AI
High pressure, personal liability, and inadequate resources are some of the issues behind the rate of burnout. According to IANS and Artico report only 34% of cybersecurity professionals planned to stay in their current roles.
• Last year, Jason Clinton, Anthropic CISO, talked at RSAC 2025 about poor stability of the LLMs in training. Stability has to improve to have predictable safety rules and effective security.

• This year, Stephen Vintz, Tenable Co-CEO emphasized the gap between security strategy and the practical ability of engineers to manage AI-powered infrastructure. The fragmented AI ownership creates even more significant risk.

It’s getting harder to distinguish “good” AI Agent from “bad” AI-Powered attack

Lesson 3: Work Together to Put Up a Powerful Defence
Wendi Whitmore (Chief Security Intelligence Officer, Palo Alto Networks) talked about how AI is reshaping cyber risk and the critical importance of collaborative, continuous monitoring and incident response.
• Share Information: The goal is to create a unified identity system and shared intelligence feeds that work like a global “game map.” This way, what one defender does can help the whole system, making everyone feel more responsible and efficient.

• Work Together Across Departments:
There’s a strong push to make tools that easily connect NetOps and SecOps through a “one source of truth.” Similar to how teammates in a game use the same interface to coordinate their actions, so everyone is on the same page and up-to-date.

Lesson 4: Use Guardrails to Distinguish Between “Good” and “Bad” AI
It’s become significantly harder to distinguish between a “good” AI agent (legitimate automated tool) and a “bad” AI-powered attack. Both often utilize similar, highly sophisticated generative AI models to behave in human-like, unpredictable ways, making traditional signature-based detection ineffective. Meerah Rajavel, the CIO of Palo Alto Networks, emphasized that deterministic guardrails are essential for monitoring AI used in securing data and infrastructure.
• Trusted Identity: As we see more non-human identities we need clear “mission boundaries” and easier ways to keep track, so these agents stay within what they’re supposed to do.
• Deterministic vs. AI-Based Guardrails: While deterministic guards are fast, cheap, and predictable, they may struggle with nuances that AI-based guardrails (which use AI to monitor AI) can catch. A robust system often uses a layered approach, combining deterministic rules for basic security with AI-based systems for context-aware safety.

Adam Savage of MythBusters at RSAC 2026


Lesson 5: Solve Complex Problems With Maker Mindset
In his keynote, Adam Savage explained how adopting a “Maker’s Mindset” means embracing curiosity, hands-on problem solving, and collaboration.
• Momentum & Iteration: Rapid prototyping and testing helps to get better feedback solving new problems with new tools.
• Organization-as-Code: Improve accountability and collaboration by defining the “blueprint” of the team — such as hierarchy, reporting lines, and operational policies — in machine-readable, version-controlled configuration files.


“AI may become devil’s bargain because it promises infinite benefit. At the same time, there’s very high risk for humanity. If we create robust guardrails now, we wouldn't have to build bunkers later.
Tristan Harris, Co-Founder of the Center for Humane Technology


Lesson 6: Be Ready for Setbacks if You Can’t Stop Them
Christy Wyatt (CEO, Absolute Security) emphasized that resilience requires being prepared for breaches and recovering quickly when they occur.
• “Blast Radius”: Kind of like game levels. If one level gets compromised, the important info stays safe in another, so failure can be handled with grace, and the system keeps running smoothly.
• Continuous Validation: Move away from static risk scores to real-time, “live” models that keep testing and checking defenses. This keeps engineers always learning and getting better at dealing with new threats.



Final Thoughts
RSAC 2026 showcases smart teams successfully solving complex problems. Still, currently 68% of organizations struggling to differentiate between human and AI activity, and 92% of security professionals concerned about agent security. The scope and the pace of change raise more questions:
• Does AI adoption mean less integrity in the cybersecurity systems?

• Are there new better ways for cybersecurity industry to collaborate in the face of AI attacks?