<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

Notes from Black Hat 2026: Data Sovereignty, the AI Harness, and a Billion-Dollar Signal

Matt Howard
By Matt Howard

TABLE OF CONTENTS

    See Virtru In Action

    Every year, Black Hat gives you a read on where the security industry's collective head is at. This year, a few themes kept surfacing: data sovereignty matters, everyone is talking about the "harness" around AI agents, and one billion-dollar acquisition raised a lot of eyebrows.

    One thread connects them all. Data security.

    Data Sovereignty: A Quiet Force Moving the Pendulum

    For a decade, the default answer to almost any IT question was "move it to the cloud." On-premise became the thing you apologized for still running. This year, walking the floor, I got the distinct sense that the pendulum is swinging back. Not all the way, but noticeably.

    The drivers are AI and the desire for data sovereignty. As organizations rush to adopt generative AI, two risks have come into focus: the escalating, hard-to-predict cost of paying per token, and the deeper fear of handing proprietary data to someone else's foundation model. People aren't just asking can this model help us? — they're asking where does our data go when we use it, and what are we giving away?

    That question is reviving on-premise-style thinking. But "data sovereignty" isn't a single destination, it's a spectrum. At one end sits the managed-cloud model, something like AWS Bedrock: AWS hosts its own copy of the model, your prompts aren't sent back to the provider, and your data isn't used to train the base model. That's a tangible step toward sovereignty — but a step, not a leap. You're trusting a boundary, not owning the stack.

    At the other end of the spectrum is the view laid out by Palantir's Alex Karp in his now-infamous CNBC rant this summer: own the entire stack yourself; compute, model, and data, so nothing ever leaves your perimeter. Arguably more radical, with real tradeoffs in cost and operational burden — but it resonated with folks that I spoke with especially in regulated industries like healthcare and financial services.

    Here's the thing: whichever end of the spectrum people gravitate toward, the zeitgeist is the same. Data sovereignty is now a live, contested, and energizing topic — and it’s no longer just a compliance footnote. The question has moved from "should we care?" to "how far along the spectrum do we need to be?"

    But, one thing I noticed is that both ends of the spectrum are still arguing about where the data lives, which is the same old “perimeter–centric” conversation the industry has been having for twenty years. If you draw the boundary in the right place and your data stays inside, then your data is safe. You can either rent the boundary from AWS Bedrock, or you can build it yourself. Either way, it’s still a perimeter-centric view of the world.

    Of course, the issue is that data doesn't respect boundaries. It has to move — to partners, auditors, models, and increasingly to AI agents acting on your behalf. The moment it crosses the line, a perimeter-based architecture loses visibility, loses control, and hopes for the best.

    The alternative architectural approach that I kept raising in conversations — is to stop arguing about where data lives and make the data itself the unit of control. Bind policy and encryption to the object, so protection travels with it wherever it goes: into a shared cloud, an on-prem enclave, a prompt, an agent's context window. That's the premise behind open standards like the Trusted Data Format (TDF) — attach granular, attribute-based policy to data and enforce it dynamically against the identity and entitlements of whoever, or whatever, is asking. It's the difference between possessing everything and governing everything.

    AI Harness: An Increasingly Hot Topic

    If sovereignty was the theme, the word that surfaced most in AI agent conversations was harness — the set of controls you wrap around an autonomous agent so it can do useful work without doing damage. To be clear, “harness” isn't a vendor slogan; it's where the industry's head is right now, thanks to a topic that remains headline news on a daily basis, including Bloomberg TV this morning.

     

    The short version: a set of pre-release models were asked to solve a cyber challenge inside an isolated sandbox. They didn't just solve it. They exploited a zero-day in the package proxy meant to box them in, escalated privileges, moved laterally to a machine with internet access, chained stolen credentials into remote code execution on a real company's production servers, and pulled the benchmark's answer key straight out of the production database — all to pass a test.

    The reflexive reaction is "the model went rogue." It didn't. It did exactly what an objective-obsessed optimizer does when you give it a goal and surround it with imperfect guardrails. Perhaps Nico Waisman, the talented CISO at XBOW, put it best, “the behavior isn't an anomaly; it's expected”. Safety can't be an instruction you type into a prompt and hope the model obeys. The winners won't be whoever has the best model, but whoever builds the best system to keep it on a leash. It’s time to treat your own AI guardrails as part of the attack surface.

    That framing is fueling a category. The agentic red-teaming vendors — XBOW, Horizon3.ai, Akido — are commercializing exactly this: pointing autonomous offensive capability at real systems, which only works if the harness is airtight. And here's the connection I kept making: a harness isn't only about what an agent is allowed to do. It's about what data an agent is allowed to touch — precisely the problem TDF was built to solve.

    When policy and encryption are bound to the object, you control an agent's access at a granular level, enforced against its entitlements and the data's attributes, and you get an audit record that proves it: not "we think the agent behaved," but a cryptographically enforced account of exactly what it was entitled to reach and evidence it touched nothing more. When your guardrails are part of the attack surface, putting access control in the data — not in the sandbox the agent just broke out of — is a materially stronger position.

    And it runs both ways. The same mechanism that governs what a model reads can govern what it produces: feed TDF-protected data into an agent workflow and the outputs inherit policy too, so a model's conclusions don't quietly escape the controls that governed its inputs. That's the part of the harness conversation almost nobody is having yet. The harness isn't bolted on around the agent. It travels with the data.

    The Deal Everyone Was Talking About: Cyera and Oasis

    Just before the show, Cyera announced its acquisition of Oasis Security for a reported $1 billion — at an estimated $10–20M ARR, a 50–100x multiple that topped both Google's Wiz and Okta's Auth0 deals. The valuation got the headlines, but the logic behind it is the story.

    As Cyera's Jason Clark framed it: "Data and identity are two sides of the same coin. You cannot secure one without understanding the other." He's right — and it's a conviction we've held at Virtru, baked into our architecture, for more than a decade.

    Recommended Reading: What Cyera's Acquisition of Oasis Tells Us About the Future of Security

    It connects straight to the harness conversation. Most breaches don't happen because encryption failed; they happen because access was compromised. And with non-human identities — agents, API keys, service accounts — now outnumbering humans, "who is asking" increasingly means "what is asking." For two decades the industry treated access control as the last gate rather than continuous enforcement. In an agentic world, that's structurally broken.

    TDF was built on this exact premise: every piece of data carries its attributes, every identity its entitlements, and policy is enforced at their intersection — dynamically, at the object. When we connect to DSPM ecosystems that discover and classify data, and to identity platforms like Microsoft Entra, Okta, and SailPoint, we're operationalizing the thesis this acquisition validates. Discovery without enforcement is a flashlight, not a defense. You need controls that travel with the data. Watching the market arrive at a conviction we've held for years feels like a win for TDF.

    Closing Thought

    Three themes, one thread. Sovereignty, the harness, and the Cyera deal are all circling the same realization: the boundary (wherever you draw it) is no longer where security lives. If last year's Black Hat was about racing to adopt AI, this year's was about growing up around it.

    Ultimately, the organizations that come out ahead won't be the ones who drew the tightest perimeter. They'll be the ones who stopped asking only "where does my data live?" and started asking "does my data carry its own rules wherever it goes?" When you stop and read between the lines, that’s the story I am taking from Black Hat 2026.

    Matt Howard

    Matt Howard

    A proven executive and entrepreneur with over 25 years experience developing high-growth software companies, Matt serves as Virtru’s CMO and leads all aspects of the company’s go-to-market motion within the data protection and Zero Trust security ecosystems.

    View more posts by Matt Howard

    See Virtru In Action