The one-day executive AI course at Black Hat USA 2026 walks a security leader through four blocks in a single day: what AI really does for security, the governance frameworks that land on a CISO’s desk, the AI-powered threats worth planning for, and how to evaluate the vendors selling into all of it. You leave able to interrogate a vendor, gate a deployment, and answer a board with specifics. No code, no labs.
Black Hat USA 2026 runs August 1 to 4 at Mandalay Bay in Las Vegas. A Cyber Executive’s Guide for Artificial Intelligence is the one-day option on August 3. Here is what that day actually looks like from the seat.
Morning: what AI can and cannot do for security
The day opens by separating the real from the sold. Every vendor deck claims AI. Most security leaders cannot yet tell a genuine capability from a demo built to survive a sales call. So the first block draws that line: where machine learning and large language models actually move the needle in detection, triage, and analysis, and where they quietly fail or add risk.
This is not an AI theory lecture. It is the grounding a leader needs to walk into the next vendor meeting and ask a question the salesperson did not rehearse. By mid-morning you can hear a capability claim and know whether it is plausible, and just as important, you can tell your own team which AI ideas are worth piloting and which are hype dressed up in a roadmap.
Late morning: governance frameworks that reach your desk
The second block is the one CISOs ask for by name: governance. It covers the NIST AI Risk Management Framework as the operational backbone, the EU AI Act as the compliance overlay that applies to any organization with EU customers or operations, and how to map both onto the security and risk program you already run.
The emphasis is practical, not a framework recital. Which controls map to which obligations. Where the gaps usually sit. What auditable evidence actually looks like when a regulator or a board asks. You leave this block able to tier AI risk in an inventory and gate new AI systems through an approval process, instead of signing policy you cannot enforce.
If you want the deeper version of this material before you go, the post on AI governance training for security executives covers the framework stack in detail.
Early afternoon: AI-powered threats, from the defender’s chair
After lunch the course turns to offense: how AI changes the threat model. Deepfakes in social engineering and fraud. Adversarial AI against the models you might deploy. AI-enabled attacks that scale what used to take a human. Prompt injection and RAG poisoning against the LLM assistants moving into enterprises now.
The framing stays at the altitude a leader operates from: not how to write the exploit, but what the attack means for your risk register, your controls, and the questions you should be asking your own engineers. The companion read on AI risk blind spots CISOs miss covers several of these in more depth.
Late afternoon: vendor evaluation and organizational readiness
The final working block is where the day pays for itself. Vendor evaluation: how to question AI capability claims, what training-data and evaluation-methodology questions to ask, and how to design a proof of concept that produces evidence instead of a polished narrative. This is the skill that kills a bad six-figure contract before the renewal locks in.
It closes on organizational readiness: what an AI-ready security program looks like, where the gaps usually are, and how to sequence the build. You leave with a picture of your own program’s next three moves, not a generic maturity model.
Two things make the room work. First, the material comes from working practitioners who have sat across the table from AI vendors and stood up governance inside real security programs, not from full-time trainers reading a deck. Executives can tell the difference, and the vendor-evaluation block in particular lands because it is drawn from decisions the instructors have actually made. Second, the peers in the seats next to you are other CISOs and senior security leaders wrestling with the same AI decisions, which is its own reason to be there. The hallway conversations at an executive course are frequently worth the trip on their own.
What you walk out able to do
By the end of the day the deliverable is judgment, not a binder. A CISO who took the course can:
- Interrogate an AI vendor’s claims and recognize a non-answer.
- Map an AI deployment to NIST AI RMF and the EU AI Act.
- Tier AI risk in an inventory and gate deployments through an approval process.
- Speak to AI risk in a board conversation with specifics instead of hand-waving.
That is a full day at executive altitude, and it is the reason the format is one focused day rather than a week. If you are deciding whether to send a member of your leadership team, the companion post on sending your security leaders works the budget and ROI side. For how the course fits with GTK’s consulting and the CISO Brief, see the for-executives hub.
Full details and registration are on the executive course page and the Black Hat 2026 training page. For a custom on-site version tailored to your regulatory environment and AI roadmap, contact us. The seat is one day; the decisions it improves run for years.