RSAC 2026 Conference Announcements Summary: AI Security and Governance

RSAC 2026 Conference Announcements Summary: AI Security and Governance

RSAC 2026 Conference Announcements Summary: AI Security and Governance

As hundreds of vendors descend on San Francisco for the RSAC 2026 Conference, the sheer volume of news can be overwhelming. To help you navigate the noise, we’re providing a daily digest of the most significant announcements.

Top AI Security and Governance Announcements

1Password Launches Unified Access Platform for Secure AI Agent Deployment

1Password announced 1Password Unified Access, a new agent security platform that enables organizations to securely deploy AI agents and automated workflows without losing control of credentials, secrets, and machine identities.

  • Unified Access gives AI builders the ability to discover, secure, and audit access at the moment it occurs.
  • At launch, 1Password is collaborating with Anthropic, Cursor, GitHub, Perplexity, and Vercel, as well as other category leaders in AI infrastructure, AI developer tools, MCP gateways, and AI browsers.

Action1 Adds Integrations with Rapid7, Tenable, CrowdStrike, and Microsoft

Action1 has announced new integrations between its endpoint management platform and four major vulnerability management and endpoint security tools from Rapid7, Tenable, CrowdStrike, and Microsoft.

  • Each integration correlates vulnerability scan data from the respective platform with Action1’s endpoint inventory and automated patching capabilities.
  • Action1 introduced a universal vulnerability data ingestion feature that accepts exported scan data from any vulnerability management tool.

Arcjet Adds Prompt Injection Detection to Application-Layer Security Platform

Arcjet has released a prompt injection protection capability that inspects and blocks malicious prompts before they reach AI models.

  • Enforcement happens earlier in the request path, where full application context (such as identity, session state, and routing) is available.
  • The feature integrates with Arcjet’s existing controls, including bot detection, rate limiting, and sensitive information detection.

Other Notable Announcements

Bonfy Launches Data Security Platform for AI Agents and Enterprise GenAI Workflows

Bonfy has released Adaptive Content Security (ACS) 2.0, a platform designed to monitor and control how sensitive data is accessed and handled by AI agents, copilots, and unsanctioned AI tools.

  • It covers a broad range of systems (Microsoft 365, Google Workspace, Salesforce, Slack, AWS S3, and on-premises file stores) and introduces an MCP server interface that allows AI agents to label and risk-score content before it reaches external services.
  • A browser extension provides real-time inspection of web traffic to detect shadow AI usage.

Booz Allen Hamilton Launches Vellox AI-Native Cyber Defense Suite

Booz Allen Hamilton launched Vellox, a suite of five AI-native cybersecurity tools covering malware analysis, detection engineering, adversary emulation, compliance monitoring, and autonomous remediation.

  • Vellox Reverser (generally available) automates malware reverse engineering to produce defensive recommendations.
  • Vellox Ranger (limited preview) autonomously maps customer environments to generate tailored detection logic.

Cobalt Expands Offensive Security Platform with New AI Capabilities and Managed Program Service

Cobalt announced two additions to its Offensive Security Platform: new AI-driven pentesting capabilities and a Security Program Manager service.

  • The platform now automates reconnaissance, vulnerability discovery, credential validation, and finding deduplication.
  • The Security Program Manager is a dedicated human expert who handles scheduling, remediation tracking, and asset inventory management for enterprise-scale pentesting programs.

Druva Launches Identity Resilience to Cover Okta, Active Directory, and Entra ID

Druva Identity Resilience extends the company’s data security platform to include identity protection and recovery across Okta, Microsoft Active Directory, and Microsoft Entra ID in a single SaaS platform.

  • Rather than treating identity as a static list of directory objects, the platform models it as a continuously evolving state (tracking how permissions, relationships, and non-human identities change over time) to help teams reconstruct what happened during an incident and restore access to a known-good state.

Entro Security Adds AI Agent Governance to Identity Platform

Entro Security has launched Agentic Governance & Administration (AGA), a new module that extends identity governance principles to AI agents and the non-human identities they use.

  • AGA builds a profile for each agent by correlating its sources (endpoint telemetry, agent foundries, cloud environments, MCP servers), the enterprise assets it accesses, and the identities it relies on.
  • It also provides MCP activity monitoring and policy enforcement.

Graylog Adds Threat Prioritization, Automated Investigations, and MCP Server to SIEM

Graylog announced three new capabilities for its SIEM platform.

  • A threat prioritization engine groups related alerts using entity context, asset criticality, vulnerability data, and threat campaign intelligence to surface high-priority incidents and suppress noise.
  • Context-aware incident response workflows automate evidence collection and generate AI-driven step-by-step response recommendations.
  • An open MCP server connects compatible LLMs to Graylog security data, enabling natural-language queries and agentic workflows such as automated triage, MITRE ATT&CK coverage mapping, and false-positive analysis.

Huntress Adds Endpoint and Identity Security Posture Management to Platform

Huntress has launched Managed Endpoint Security Posture Management (ESPM) and Managed Identity Security Posture Management (ISPM) as new additions to its platform.

  • Managed ESPM controls which applications can run on endpoints, integrates with Microsoft Defender for Endpoint for vulnerability prioritization and remediation, and generates compliance-ready reports.
  • Managed ISPM applies expert-built policies to Microsoft 365, continuously checks for misconfigurations, and automatically rolls back unauthorized changes.