AI Isn’t the Problem: The Real Issue Is Human Responsibility
Experts at the Black Hat and BSides Las Vegas 2026 conferences emphasized that the challenges surrounding artificial intelligence stem not from the technology itself but from human approaches to its development and deployment.
The Shift from “Pets” to “Cattle”
Dwayne McDaniel, principal developer advocate at GitGuardian, argued that AI models and agents are often mischaracterized as autonomous entities. These systems, he explained, are fundamentally mathematical constructs that should be treated as transient tools rather than sentient beings.
McDaniel drew a parallel between traditional server management and modern cloud computing to illustrate how human behavior shapes AI interactions.
Historically, servers were treated as long-term assets, often named and maintained with care. The cloud era, however, introduced a model where virtual machines are created, used, and discarded rapidly. This shift rendered the notion of “pets” obsolete, replacing it with a “cattle” mentality—where systems are viewed as disposable and replaced without sentiment.
“Nothing that’s not human should have a password,” he asserted, emphasizing that AI systems lack intent and should not be granted access based on assumptions of trust.
Reimagining Agency Governance
Ben Hanson, field CTO at Zenity Global, added that current governance strategies focus on restricting AI access to sensitive data through API keys, a method akin to issuing passwords to humans. However, this approach fails to address the underlying complexity of managing agency within AI systems.
Hanson introduced the concept of “least agency” as a framework for securing AI systems, contrasting it with the traditional “least privilege” model.
He described agency as a multifaceted construct involving eight interrelated components: trust, context, intent, behavior, authority, control, boundaries, and risk. Unlike privilege, which can be adjusted incrementally, agency requires a holistic approach to governance.
“Risk emerges from interactions, not individual components,” he explained, using the example of an iceberg posing a threat to a ship but reducing risk for a seal.
The AI “Lethal Trifecta”
Emily Choi-Greene, CEO of ClearlyAI, stressed that the assumption of perfect compliance from AI agents is flawed. Instead of attempting to enforce rigid control, she advocated for narrowing the scope of AI tasks to minimize potential risks.
Choi-Greene introduced the concept of the “lethal trifecta,” a scenario where AI agents combine access to private data, exposure to untrusted external content, and the ability to communicate externally.
This combination enables vulnerabilities such as prompt injection and data exfiltration. To mitigate risks, she recommended breaking down complex tasks into smaller, specialized functions.
“Limiting an agent’s scope reduces the impact of security failures,” Choi-Greene said. She warned against relying on AI for ambiguous or probabilistic tasks, advocating instead for clear objectives and controlled environments.
Preparing for an Uncertain Future
Chris Inglis, former U.S. National Cyber Director, called for collaborative efforts to ensure AI development aligns with ethical and secure practices, while Nicholas Carlini, a research scientist at Anthropic, warned that the future of AI will bring unforeseen challenges requiring adaptive strategies.
Inglis described AI as an unstoppable force, comparing it to a “tsunami wave” that cannot be halted but must be guided.
He highlighted the importance of collaborative policies to ensure responsible AI development, referencing initiatives like the Mythos consortium. However, he cautioned that defensive strategies must evolve to match the pace of malicious actors.
“The problems we face in a year will be new and different,” he said, urging organizations to abandon outdated security models and prepare for unpredictable scenarios.
The Need for Systemic Change
Speakers at the conference agreed that traditional security paradigms are insufficient for managing AI. McDaniel emphasized that governance must focus on system-wide structures rather than isolated controls. Hanson concluded that failure to adapt will result in recurring security breaches, while Choi-Greene stressed the importance of aligning AI use with specific, well-defined goals.
As AI continues to reshape the technological landscape, the consensus among experts is clear: the responsibility for safe deployment lies with humans, not the machines themselves.
