by | Apr 3, 2026

RSA Conference 2026 recap: AI gets real (and a little complicated)

By Jay Smith, Senior Account Supervisor

The Touchdown PR team just wrapped up another packed week in San Francisco for RSAC 2026. With some 43,000 cybersecurity leaders, practitioners and innovators gathering once again, the energy on the ground made one thing clear: the industry has moved well beyond exploring AI and is now grappling with how to manage it.

This year, seven Touchdown clients joined us at the show alongside five team members supporting media and analyst conversations, client meetings and plenty of on-the-ground trend spotting.

And yes, we still made time for a few San Francisco staples: a Giants game, a stop at Ghirardelli Square and Fisherman’s Wharf. And there were some unexpected moments (including AI-generated album covers and Jack Sparrow, Marilyn Monroe and Taylor Swift impersonators wandering the show floor).

 

What We Saw on the Ground

From a returning attendee’s perspective: Jay Smith

Five RSACs in, and this one felt different. In 2025, most conversations centered around what AI might unlock. This year, that question barely came up. AI is already embedded into all aspects of how security teams operate. The conversations shifted to what happens after deployment: who’s accountable, what data was touched, and how teams even know what these systems are doing.

Attendees were more specific. Not “we’re exploring AI,” but “our agents are already in production and we’re figuring out governance.” Conversations centered on access, visibility and control. What happens when an AI system connects to internal tools? Who owns the output? How do you track what it touched?

That level of detail showed up everywhere from sessions, booth conversations and quick chats waiting for coffee. It also changed how companies showed up. Broad AI messaging didn’t land the same way it did a year ago. The conversations that stuck were grounded in specific problems and real use cases.

That shift changes the expectations on both sides. Security teams are looking for clear answers, and companies have to explain what their technology is actually doing in real environments. General AI messaging doesn’t carry the same weight anymore.

From an RSAC first timer’s perspective: (Patrick Ingraham)

Walking into RSAC for the first time, the scale hits you immediately. I’ve been to plenty of industry events, but this was unlike anything I had experienced before. The Moscone Center was absolutely packed, and the activity spilled well beyond it. You’d hear the same conversations continuing outside at coffee shops and bars, around Fisherman’s Wharf, in Ubers, even on flights in and out of San Francisco. Deals, demos and debates weren’t confined to the show floor.

AI dominated nearly every discussion, but the tone felt more grounded than expected. People weren’t debating its potential as much as they were trying to get a good handle on risk, governance and visibility. There was a clear sense that things have moved fast, and teams are now figuring out what’s actually running in their environments and how to control it.

The media presence stood out, too. Cyber Risk Alliance had a strong footprint, and the briefing rooms stayed busy all week. Journalists were engaged and asking detailed questions, not just taking high-level pitches. On the floor, attendees were open to conversations and quick to engage with our client surveys around AI security and governance, which says a lot about where priorities are right now.

And then there were the moments outside the conference, like catching a Giants exhibition game with clear weather, beers and hot dogs by the bay was a solid reset in the middle of a packed week. It balanced the show’s intensity and made the whole trip feel a bit more laid-back.

From an RSA first timer’s perspective: Abby Veach

My first RSAC in San Francisco went way beyond what I expected. Walking onto the expo floor felt a little surreal; the booths were massive, loud and honestly kind of wild. There was mechanical bull riding, wrestling and extravagant setups designed to pull people in. I didn’t realize how far vendors would go to stand out, and it made the whole experience feel energetic and competitive in a fun way.

What stuck with me was the level of effort behind it all. People clearly care about what they’re building and how they show up. You could feel that pride in the details, in the conversations, in how teams presented themselves. For someone early in my career, it was motivating to see how much ownership people take in their work.

The highlight for me was attending the Women in Cybersecurity breakfast panel hosted by Security Scorecard. Sitting in a room full of women who are trailblazing in this industry, hearing them talk candidly about their paths and what’s ahead, was really impactful. Having the opportunity to listen to Kara Sprague, CEO of HackerOne and a Touchdown client, made it even more meaningful. She shared thoughtful insights on risk, AI, cybersecurity and safety, in addition to giving advice that actually felt actionable.

It was a great first conference experience, and I’m already excited for the next one!

The Moments That Made It RSAC

 

Beyond the sessions and strategy, RSAC is still about the experience. This year had no shortage of memorable moments:

  • Creating AI-generated album covers at one of the booths
  • Spotting a surprisingly convincing Jack Sparrow, Taylor Swift and Marilyn Monroe impersonators on the show floor
  • A ‘No AI Cafe’ designed for a short break from the AI talk
  • Seeing how vendors continue to push creativity in how they tell their stories

These moments matter more than they seem. They’re what turn a packed conference into something people actually remember.

Stay tuned for part two of our blog that highlights our media, analyst and client takeaways from the event.