Table of contents
That’s a wrap: Mend.io at Black Hat USA 2026
Another Black Hat USA is in the books, and what a week it was. From a main stage keynote at the AI Summit to candid podcast conversations, a video interview with Cyber Defense Magazine, and a booth game that just wouldn’t quit, Mend.io showed up in Las Vegas ready to talk about the question every security leader is wrestling with right now: as AI reshapes both the software we ship and the systems we have to defend, who do we trust to verify that it’s safe?
Here’s a full recap of everything Mend.io got up to on the show floor and beyond.
Tuesday, August 4: Taking the main stage at the AI Summit
We kicked things off with a main stage keynote at the Black Hat AI Summit, where Asaf Saar, EVP and Chief Product Officer of Mend.io, presented “The verification layer: Why AI security can’t be left to AI.”
The session tackled a shift happening in real time: AI has changed both the software organizations ship and the systems they now have to secure. Code is increasingly generated by AI, while products themselves are being rebuilt around models, agents, prompts, RAG pipelines, and autonomous workflows. That creates a new trust problem for security leaders. The same AI systems that can generate software can also reason about how to exploit it, and the same AI applications that create business value can also be manipulated, bypassed, or abused in ways traditional security programs were never designed to catch.
Asaf’s central argument: the next era of AI security depends on independent verification. Not a self-check, not a model grading its own homework, but a security layer that is neutral to the model, separate from the system being tested, and continuous enough to keep pace with AI-driven development. He walked the audience through why vulnerability discovery is getting cheaper and louder, why self-attestation doesn’t count as security, and why defenders need to rethink verification across both AI-generated code and AI-powered applications.
Attendees left with a practical framework for answering three questions that now sit at the center of every AI security conversation: what are we protecting, who do we trust to verify it, and how do we secure AI systems fast enough to match the speed at which they’re being built.
The talk made headlines
The timing of Asaf’s keynote turned out to be especially relevant. In the days that followed, the security industry erupted into debate over the OpenAI/Hugging Face incident and what it means for how much autonomy we hand AI agents. Asaf was quoted in SiliconANGLE’s coverage of the story:
“The Hugging Face breach has sparked a rigorous debate within the security industry over how AI agents should be viewed. In a presentation on Wednesday, Asaf Saar, Executive VP and Chief Product Officer of Mend.io, noted that giving agentic technology too much self-supervision can be a bad idea.”
“Basically, the agent took an exam and it was able to find the answers in a way that was not how it was expected,” said Saar, during a discussion of the OpenAI/Hugging Face incident. “The model checks its own work and that’s a problem. The system that generates the risk can’t be the final reviewer.”
It’s the same thesis from his keynote, playing out in real time: when the system generating the risk is also the one grading itself, something has to sit outside that loop.
Named a Top InfoSec Innovator finalist
We closed out Tuesday with more good news: Mend.io was named a finalist in Cyber Defense Magazine’s Top InfoSec Innovator Awards for AI Security, part of CDM’s Top 25 Most Innovative Cybersecurity Companies in the World for 2026. The recognition reflects our comprehensive approach to identifying, assessing, and protecting AI components, from models and agents to system prompts and runtime interactions, across the full software development lifecycle.
As Azi Cohen, CEO of Mend.io, put it: “AI is transforming how applications are built, deployed, and secured, creating new challenges that require security solutions designed for this evolving landscape.”
Wednesday and Thursday, August 5 and 6 at Black Hat: Podcasts, booth interviews, and more
Wednesday and Thursday were two full production days. We sat down for multiple podcast recordings, taped a video interview with Cyber Defense Magazine at our booth, and made an appearance in Black Hat’s official daily social roundup.
Podcast: Azi Cohen on why AI changes everything security leaders thought they knew about AppSec
Azi Cohen, CEO of Mend.io, covered three big ideas:
AI is arming both sides of the fight. AI-powered security tools are uncovering more vulnerabilities than ever, while simultaneously giving attackers faster, more sophisticated ways to exploit them. Hackers are already weaponizing new vulnerabilities within days of discovery. The real business pressure isn’t detection anymore; it’s whether organizations can reduce risk faster than attackers can operationalize it.
There’s an attack surface most organizations aren’t accounting for. Risk has moved beyond code into the interaction between applications, AI models, agents, and runtime behavior. Most enterprise security programs, and the governance structures around them, were not built for this reality.
The winners will be defined by operational resilience, not tool adoption. The organizations that come out ahead won’t be the ones with the most sophisticated analysis. They’ll be the ones that build systems capable of continuously reducing risk at enterprise scale, without breaking the speed of the business.
Podcast: Asaf Saar on boardroom AppSec and the shift to exposure management
Asaf’s podcast picked up where his keynote left off, digging into two themes.
On AppSec in the boardroom: boards don’t want a vulnerability count, they want a trend line and a plan, which means reframing AI and agentic risk the way executives already think about financial and operational risk. Asaf also made the case that fear-based framing backfires; the credible version of this conversation is calm, specific, and comparative, not alarming. He used Mend’s own AI governance work as a live case study for what that looks like in practice.
On the shift from vulnerability management to exposure management: “how many vulnerabilities do we have” is the wrong question once agents and MCP servers are in the mix, because that count keeps climbing regardless of what you do. What actually predicts breach risk is reachability, exploitability, and business context, and most programs still don’t measure any of the three. Asaf also talked through what changes operationally once a team adopts this lens: fewer tickets, more triage-by-exception, and a different definition of “done.”
On camera with Cyber Defense Magazine
We also sat down with Cyber Defense Magazine for an on-camera interview at our booth, and Mend.io was featured in Black Hat’s official daily social roundup. Great company to be in.
The booth: Catch the vulnerabilities
If you stopped by our booth, there’s a good chance you tried your hand at Catch the Vulnerabilities, our game that turned into one of the week’s genuine crowd-pleasers. Over a thousand sessions played, a leaderboard full of impressively fast reflexes, and a lot of great conversations along the way. Congratulations to everyone who topped the charts.
Thank you!
Black Hat USA 2026 was a reminder of how fast this space is moving and how much appetite there is for a real conversation about what AI security actually requires. Thank you to everyone who stopped by our booth, sat in on the keynote, joined a podcast conversation, or just came by to talk shop. We especially want to thank the customers who took the time to visit with us. Partnership is at the center of how we think about this work, and it showed up all week.
Mend.io is built for every risk, across AI and AppSec. By securing the code layer and the AI layer, and the interactions between them, where modern application risk now lives, Mend.io extends proven AppSec workflows to the models, prompts, and agents inside today’s applications, delivering continuous protection across the entire AI application lifecycle.
Until next year, Black Hat.