Top Client Takeaways from RSAC: Where AI, Governance and Reality Converge
By Jay Smith, Senior Account Supervisor
RSAC continues to reflect where cybersecurity is headed, but this year’s conversations felt more grounded. AI is already part of how teams operate, and the focus is now on what it’s doing, how it’s managed and whether organizations can clearly explain it.
Across client, media and analyst conversations, the companies that stood out were the ones with clear answers and messaging. Below are the key takeaways coming out of RSAC on the media, analyst and our client experts.
The Media and Analyst Dynamic
The way media and analysts approach RSAC continues to shift. Journalists are more selective with meetings and spend more time in sessions, where they can hear multiple perspectives at once. When they do take briefings, they are looking for something specific: new data, a clear point of view or a strong take on a current issue.
During the week, we engaged in conversations with a number of media outlets including the NYSE, CSO, SC Media and SiliconANGLE, along with podcast discussions and ongoing contributor relationships. Analysts remain focused on in-person meetings. RSAC gives them a chance to compare how different companies are approaching similar problems and where categories are forming or shifting. For PR teams, this reinforces a shift we’ve been seeing for a while.
Access isn’t the challenge, relevance is. The companies that got time on calendars were the ones with a clear point of view, not just a presence at the show. RSA still brings the industry together in a way that’s hard to replicate. This year, the conversations felt more focused and more practical. AI is already part of how teams operate.
The challenge now is explaining it clearly. The companies that stood out weren’t the ones talking the most about AI, but the ones that could connect it to real problems and real outcomes.
Top Trends and Takeaways
AI was everywhere again, but the reaction has shifted. Security teams aren’t interested in hearing that a product uses AI. They want to know what it actually solves, and they’re quick to spot the gap between what’s marketed and what’s real.
Agents are already inside workflows investigating alerts, taking action and operating with limited human oversight. The question teams are wrestling with now is ownership and accountability after the fact, not whether to deploy. As Sentra’s David Stuart told SiliconANGLE, “Copilot and assistant agent adoption is accelerating fast within enterprises, but it is often being gated by security concerns about the data layer, and having telemetry about that data that they can trust to build controls.”
HackerOne CEO Kara Sprague further elaborated to SiliconANGLE that: “In just the last six months, the attack surface has expanded so fast, while the cost of an attack has come down so far. Humans are being told they have to use AI tools to do a better job, but they don’t understand how they work, so they are becoming huge sources of data leakage. CISOs and security teams will have to adjust the way they operate and focus on what is truly exploitable.”
Most organizations still can’t clearly explain how AI is operating across their environment: what’s running, what it can access and who is responsible. Governance is catching up to deployment rather than leading it.
EC-Council CEO Jay Bavisi put it plainly in a conversation covered by CSO: “Our attitude as a community has been shoot first, ask questions later. But what we should be doing is ask questions first, shoot later.” The data behind that is hard to dismiss. Bavisi noted that 84% of Fortune 500 companies reference AI implementation in their 10-K filings, while just 18% claim to have actual AI governance in place. With 72 countries having launched AI regulations or frameworks, the gap between disclosure and accountability is getting wider.
Singulr AI’s Richard Bird reinforced the same concern from the inside, telling CSO’s David Gee that the governance conversation remains largely performative within most enterprises — boards are discussing AI risk without the institutional mechanisms to actually manage it. That framing resonated with what we heard on the floor all week.
The focus has moved from AI models to data. If a team doesn’t have clear visibility into where sensitive data lives today, AI doesn’t solve that problem. It makes it more urgent.
Identity now includes more than users. Agents and automated systems are accessing sensitive environments and existing access models weren’t built with that in mind. Teams are actively rethinking permissions.
In a TechStrong TV interview, Lineaje CEO Javed Hasan highlighted that with the explosion of AI-generated code, organizations can no longer afford to simply “scan and pray.” By shifting vulnerability discovery to proactive threat elimination by swapping vulnerable dependencies, organizations ensure that applications are inherently secure from the ground up.
More dashboards and alerts are no longer the gap, as most teams already have visibility. The challenge is acting on it fast enough. Human oversight isn’t going away; it’s being redefined. Constant review doesn’t scale at machine speed, so the conversation has shifted to where human judgment actually adds value, rather than where it creates bottlenecks.
Last Thoughts
One thing was clear throughout RSAC: AI is already part of how security teams operate. The focus now is on ownership, governance and making sure systems are doing what organizations think they are.
There’s still a gap between how widely AI is being used and how well it’s understood or controlled. Closing that gap will require better visibility into data, updated approaches to identity that account for non-human actors and clearer decisions about where human oversight is most effective.
For companies working through this, the opportunity is practical. Those who can clearly connect AI to specific outcomes, and explain it in a way that resonates will stand out with customers, analysts and media. This year, the companies that earned attention were the clearest.