Black Hat Asia 2026: Autonomous AI Cyber Threats and Data Sovereignty Take Centre Stage in Singapore
Cyber Security / Threat Detection | 5 min read
Black Hat Asia 2026, the premier cybersecurity event for the Asia-Pacific region, takes place 21–24 April 2026 at the Marina Bay Sands Expo and Convention Centre in Singapore. The event has announced its keynote programme — and the speakers and sessions reflect where the global security community's most urgent concerns currently lie: autonomous offensive AI systems, fracturing data privacy frameworks, and the hidden security vulnerabilities introduced by poorly implemented AI and automation. With APAC nations facing a surge in ransomware attacks and a fragmented regulatory landscape across jurisdictions, these threats pose unique challenges to the region's rapidly digitalising economies — and the Asia-Pacific region is projected to lead global cybersecurity spending in 2026.
Keynote 1 — Thursday 23 April: Data Sovereignty and the Privacy Reckoning
The opening keynote will be delivered by Violet Blue, a six-time award-winning author and investigative journalist whose bylines span WIRED, the Financial Times, Engadget, CNN, CBS News, and the San Francisco Chronicle. Blue will challenge the fracturing global consensus on data privacy — examining how researchers, scholars, and activists are redefining privacy and security through principles of agency and data sovereignty. Her session will explore what sustainable privacy policy looks like as traditional frameworks become increasingly obsolete across the Asia-Pacific region and beyond, at a time when cross-border data flows, surveillance expansion, and AI-driven data aggregation are outpacing the legal and regulatory structures designed to govern them.
Keynote 2 — Friday 24 April: From Prompt Tricks to Autonomous Hackers
The Friday keynote will be delivered by Ari Herbert-Voss, CEO and Co-Founder of RunSybil — an AI-native cybersecurity company pioneering automated offensive security solutions. Herbert-Voss will trace the three-year evolution of autonomous offensive security systems, evaluating where automation is already effective and where human expertise remains essential. Critically, the session will make the case that traditional point-in-time security testing is now obsolete — because attacks can run continuously at scale and without human intervention. The implications for defensive security strategy are profound: organisations that still rely on periodic penetration testing or point-in-time assessments are operating on a fundamentally different clock than the adversaries they face.
Main Stage Sessions: Defensive Blind Spots and AI Automation Failures
Two high-priority Main Stage sessions complement the keynotes by targeting specific, actionable blind spots that security teams cannot afford to ignore. On Thursday 23 April, Dick O'Brien, Principal Intelligence Analyst on the Symantec + Carbon Black Threat Hunter Team at Broadcom, will present "Vulnerable Drivers: The Gaping Hole in Defences that Nobody Wants to Talk About" — revealing why Microsoft's protections are failing and how attackers weaponise signed drivers undetected, alongside defensive counter-strategies. On Friday 24 April, Eoin Hinchy, co-founder and CEO of Tines (with 15 years of prior security operations leadership at eBay, PayPal, and DocuSign), will present "A Framework for Secure, Intelligent Workflows" — revealing how poorly implemented AI and automation introduce new security vulnerabilities, and offering a framework that combines human expertise, deterministic automation, and AI capabilities to scale operations without compromising control, auditability, or security.
Training Programme: AI Red Teaming and Agentic Threat Intelligence
The four-day Training programme (21–24 April) reflects the same AI-centred threat priorities. Key courses include AI Red Teaming: Attacks on LLMs, Agents, and Multimodal Systems — teaching systematic techniques to identify and exploit vulnerabilities in modern AI systems; Practical GenAI for Threat Intel: Real-World Agentic Workflows for Cyber Threat Intelligence — preparing security professionals to build and deploy AI-powered threat intelligence systems; and the FLARE Team's Guide to Reverse Engineering Modern Malware, focused on bypassing modern detection systems. Registration for Black Hat Asia 2026 is now open at blackhat.com/asia-26.
Key Takeaways
- • Black Hat Asia 2026 takes place 21–24 April at Marina Bay Sands, Singapore — with keynotes, briefings, trainings, and main stage sessions centred on autonomous AI offensive systems, data sovereignty, and the security risks of poorly implemented AI automation.
- • Violet Blue (WIRED, Financial Times, CNN) keynotes Thursday on the fracturing global consensus around data privacy — and what sustainable privacy policy looks like as traditional frameworks become obsolete across APAC.
- • Ari Herbert-Voss (CEO, RunSybil) keynotes Friday on the three-year evolution of autonomous offensive AI — arguing that traditional point-in-time security testing is now obsolete when attacks can run continuously at scale without human intervention.
- • Two Main Stage sessions address: signed driver weaponisation exploiting gaps in Microsoft's protections (Dick O'Brien, Broadcom/Symantec); and a framework for secure, intelligent workflows showing how poorly implemented AI introduces new security vulnerabilities (Eoin Hinchy, CEO Tines).
- • Training courses include AI Red Teaming (attacks on LLMs, agents, and multimodal systems), Practical GenAI for Threat Intelligence (agentic workflows), and FLARE Team malware reverse engineering — reflecting the event's focus on AI as both the primary threat vector and defensive tool for 2026.
