Logo
FrontierNews.ai

Why Governments and Tech Companies Are Finally Sitting Down Together on AI Security

Governments and technology companies are moving beyond rhetoric to build real working relationships on AI security and governance. At Black Hat 2026, U.S. government agencies participated at a scale not seen in previous years, marking a turning point in how public and private sectors are addressing the intersection of AI, emerging threats, and regulatory complexity.

What Changed at Black Hat 2026?

The increased presence of government cybersecurity officials from agencies like CISA (Cybersecurity and Infrastructure Security Agency), the Cyber Security Agency of Singapore, and the European Union Agency for Cybersecurity (ENISA) reflected a broader recognition that technology providers cannot secure today's digital environment alone. This shift also drew greater participation from international cyber agencies, allied governments, standards organizations, and other institutional stakeholders, creating an unusual opportunity for direct dialogue between sectors that typically operate at arm's length.

The timing matters because cyber threats no longer respect borders. Cybercrime, supply chain risks, AI-driven attacks, and vulnerabilities in widely deployed technologies readily cross jurisdictions, making collaboration among governments and between public and private sectors equally critical.

How Are AI and Emerging Technologies Reshaping the Threat Landscape?

AI emerged as a central concern in these discussions, but not as a single policy issue. Instead, governments and industry are grappling with several interconnected challenges at once. On the defensive side, AI provides security teams with new methods for detecting vulnerabilities, analyzing threats, automating investigations, and accelerating response times. On the offensive side, threat actors are using AI to improve scams, fraud, impersonation, deepfakes, and social engineering tactics.

The asymmetry is troubling. As AI-enhanced tools detect potential vulnerabilities faster and at far greater scale, vendors face new challenges in validating, prioritizing, disclosing, and remediating them. Customers face a related problem: determining which disclosures require urgent action without being overwhelmed by an unmanageable stream of patches. In regulated sectors such as financial services and healthcare, every change may require testing, approval, and carefully scheduled deployment, making an unprioritized surge of disclosures particularly disruptive.

Steps to Building Effective Public-Private Cybersecurity Partnerships

  • Establish Trust Before Crisis: Effective coordination depends on relationships established well before an emergency occurs. Consistent engagement, responsible transparency, technical credibility, and candid discussion about what is and is not working form the foundation of trusted partnerships.
  • Create Channels for Information Sharing: Public-private partnerships must combine government authority and convening power with private-sector threat intelligence and technical expertise to improve preparedness, information sharing, and coordinated action against cyberthreats.
  • Pair Faster Discovery with Risk-Based Prioritization: Rather than slowing vulnerability discovery, the answer is to pair faster detection with risk-based prioritization, responsible disclosure, clear communication, and remediation processes that reflect customers' actual operations.
  • Balance Regulation with Operational Flexibility: Rules should define clear outcomes and responsibilities while allowing flexibility in the tools and methods defenders can employ, ensuring that security regulations do not hinder defenders' ability to adapt to evolving threats.

Why Regulatory Agility Matters More Than Ever

Cyber policy operates in an unusually fast-moving environment. Technology and threat methods can evolve significantly while regulatory frameworks are still being developed and enforced. This reality highlights the importance of what experts call regulatory agility.

"Overly prescriptive requirements risk locking organisations into outdated assumptions that no longer match the current threat landscape. Regulations meant to enhance security should not hinder defenders' ability to adapt," noted Hugh Carroll, writing on behalf of Fortinet's cybersecurity leadership.

Hugh Carroll, Fortinet

Ongoing industry engagements, such as those at Black Hat, help policymakers understand the operational consequences of different regulatory approaches before those approaches become difficult to change. They also give industry a clearer view of the public interests and national priorities that regulations are intended to protect.

What Role Does Sovereignty Play in AI Governance?

Sovereignty introduces an additional layer of complexity. Governments and regulated organizations are increasingly demanding proof that the technologies they adopt comply with regional standards for data management, product security, certification, and operational oversight. Satisfying these demands requires more than just a broad security guarantee; it relies on transparency, independently verified capabilities, and the capacity to assist customers in different regulatory settings.

This is particularly relevant as AI governance frameworks diverge across regions. The EU Cyber Resilience Act, product certification and testing requirements, and national and regional sovereignty concerns all emerged as recurring topics during Black Hat discussions. The challenge is ensuring that security standards do not fragment so severely that they become operationally impossible for global organizations to navigate.

What About Quantum Computing and Long-Term Security?

While quantum computing may be a less immediate concern than AI-driven threats, it remains an important part of the conversation. Governments and organizations must begin preparing for its long-term security implications, even though the timeline remains uncertain. The transition to quantum-safe security will require cooperation among technology providers, standards organizations, governments, and critical infrastructure operators.

Fortinet is already engaged in this effort as a technology partner in the NIST National Cybersecurity Center of Excellence Migration to Post-Quantum Cryptography project, which is working to identify cryptographic systems vulnerable to quantum attacks and test implementations of NIST-standardized post-quantum algorithms.

What Comes Next?

The increased presence of the public sector at Black Hat 2026 created an important opportunity to strengthen relationships between government and industry. However, participation is just the beginning. The true measure of progress will be whether these conversations lead to stronger information sharing, more effective product-security strategies, practical approaches to sovereignty and certification, and policy frameworks that can keep pace with the speed of cyber risk.

For organizations operating in regulated sectors or managing critical infrastructure, this shift signals that governance frameworks are moving from theoretical discussions to practical implementation. The partnerships being forged now will likely shape how AI governance, cybersecurity standards, and regulatory compliance evolve over the next several years.