By Zachary P. Martin, Director of Cybersecurity & Privacy Services, Venable LLP
On July 16, 2026, cybersecurity leaders from government and industry gathered at the Chamber of Commerce in Washington, D.C., for the 2026 Threat Intelligence Forum. Presented in partnership with TrendAI™ and Carahsoft, the event is now in its sixth year. It convened public and private sector leaders in cybersecurity in the face of a single theme: artificial intelligence (AI) is reshaping the cyber threat landscape, serving as a force multiplier for attackers and defenders alike, and a coordinated response is necessary and urgent.
Across the panels and fireside chats, a clear consensus emerged. The volume and velocity of cyber threats are accelerating, the time between initial access and exploitation is shrinking, and AI is lowering the barrier to entry for adversaries at every stage of the attack lifecycle. However, the same technology that democratizes offensive capability also offers a genuine opportunity for defenders, if paired with strong fundamentals, public-private collaboration, and disciplined governance.
Welcoming remarks: A changed landscape
Christopher Roberti, senior vice president for Cyber, Space, and National Security Policy at the U.S. Chamber of Commerce, opened the forum by describing how dramatically the cyber intelligence landscape has evolved. He framed the day around the AI-enabled threat environment and emphasized that the need to study the modern threat landscape has never been greater. Roberti pointed to recent government actions, including the Trump administration's AI Executive Order, EO 14409, which he described as establishing a foundation for collaboration on frontier AI models and a vulnerability clearinghouse. He also highlighted the work of the Cybersecurity and Infrastructure Security Agency (CISA) under Binding Operational Directive 26-04 to protect federal networks.
Force multiplication: Leveraging AI in public-private cyber defense
The opening panel brought together Will Loucks, senior director for intelligence at the White House Office of the National Cyber Director (ONCD), and Hart Rossman, vice president of security at Amazon Web Services (AWS), in conversation with Roberti.
Loucks framed the challenge in terms of what has and has not changed. Threats are not going away and cyber remains integral to national security and economic prosperity. What has shifted notably over the past year is the sheer volume and velocity of threats:
- The growing number of vulnerabilities
- The shrinking window between initial access and exploitation
- The acceleration of every stage of the threat lifecycle
The commoditization of cyber tools, Loucks warned, has created a market for capabilities that were previously difficult to monetize. AI acts as a catalyst, democratizing access to advanced capabilities and putting enormous pressure on defenders, who must be right every time.
Rossman offered that adversaries will always pursue their goals, and customers are never disappointed when an issue is found and resolved before it affects them. The question, he argued, is how to turn the rate of change to the defenders' advantage. AWS transfers roughly 400 trillion network flows each day. At that scale, AI makes it possible to detect patterns that would otherwise overwhelm human analysts, turning a deluge into practical, executable work for human judgment.
Loucks observed that cybersecurity is inherently inductive and limited to what has been seen before, but AI can enable a more proactive understanding of threats. He tied this to the administration's cyber strategy, whose first pillar focuses on shaping adversary behavior by creating strong disincentives for those attacking American infrastructure.
American companies are leading in AI-enabled defensive technology. Discussing implementation of the recent AI Executive Order, he described working closely with industry, CISA's patching requirements under BOD 26-04, and the new clearinghouse designed to use AI to build robust security, reduce duplicative vulnerability scanning, and deliver actionable threat intelligence to the private sector.
Cyber ground truth: Establishing verified and actionable intelligence
The second panel, moderated by Jon Clay, vice president of threat intelligence at TrendAI™, dug into how defenders can establish verified, actionable intelligence. He moderated the conversation with Chris Butera, acting executive assistant director at CISA, Bryan Kaplan, executive vice president and chief information and security officer at Juvare, and Tom Kellermann, vice president of threat intelligence and AI security at TrendAI™.
Discussing the ground truth of how adversaries use AI, Butera noted that social engineering is not new but is growing in sophistication. Kaplan warned that organizations must now worry not only about their own software but about every vendor in their stack, as attackers use AI to chain multiple vulnerabilities together.
A theme was the need for smarter, risk-based patching. Butera described BOD 26-04's philosophy of “patch smarter, not harder,” with a decision tree built on four attributes: whether a vulnerability is on an internet-connected system, whether it is a known exploited vulnerability (KEV), its total impact, and whether it is automatable.
CISA’s BOD requires that vulnerabilities meeting at least three of these criteria be patched within three days. Because these represent a very small percentage of the total, the approach helps prioritize resources. Butera also highlighted work related to the danger posed by edge devices, which typically cannot run endpoint detection and response (EDR), are often integrated with identity services, and make attractive hiding spots for nation-state actors.
The panel converged on familiar but essential principles, including basic cyber hygiene and network visibility, virtual patching, continuous threat hunting, and network segmentation for operational technology. Kellermann closed with a call to counter the "axis of evil" collaboration among adversaries through equally committed public-private partnership.
AI standards: Aligning realities in AI standard creation
In a fireside chat with Matthew Eggers, vice president for Cyber, Space, and National Security Policy at the U.S. Chamber, Martin Stanley described his agency's work at the intersection of AI and cybersecurity. Stanley is principal researcher for AI and cybersecurity at the National Institute of Standards and Technology (NIST).
Stanley outlined three major efforts. First, a Cybersecurity Framework (CSF) profile for AI addressing how to protect AI from cyber threats, how to use AI to become less vulnerable and more effective, and how to defend against AI-enabled attacks. Second, control overlays to help organizations adapt the NIST 800 catalog to AI systems, with overlays covering different types of AI. Third, an AI Risk Management Framework profile for critical infrastructure.
Describing NIST's ability to convene technical experts as its superpower, Stanley acknowledged that standards tend to lag but stressed that the collaborative activity itself adds as much value as the end product. He pointed to NIST's stewardship of the National Vulnerability Database (NVD). He also cited efforts launched in 2025 with standards engagement organizations, described as “zero-drafts efforts,” that bring stakeholders together around strong starting points. These include work on AI testing and evaluation and one on model and data disclosure.
The state of AI policy for cybersecurity in federal government
Nicholas Polk, branch director for federal cybersecurity at the Office of Management and Budget (OMB), joined Ross Nodurft, managing director for cybersecurity services at Venable LLP, to discuss federal AI policy. Building on the administration's M-25-21 memo, Polk said the primary focus of the federal chief information officer (CIO) has been accelerating AI adoption to drive efficiency and free employees for higher-level work.
That means working closely with the Federal Risk and Authorization Management Program (FedRAMP) to remove bureaucratic barriers so agencies can make informed, risk-based decisions at the speed of relevance. Polk described a guiding principle: when the government does something once for one agency, it should not have to repeat the work. He emphasized automated testing and AI red teaming as ways to continuously validate security assumptions across more than six million endpoints. He described this approach as an exciting opportunity to test systems left of boom, while acknowledging an enduring role for compliance and vendor attestations.
On protecting the federal enterprise, Polk pointed to the Continuous Diagnostics and Mitigation (CDM) program as the central source of truth for the government's cyber posture. The program replaces the spreadsheets of the past with automated patch tracking and per-agency dashboards accessible to both agencies and CISA. Addressing cost and efficiency, Polk described efforts to rationalize toolsets and eliminate duplicative technology, such as agencies running four EDR products that accumulated over the years. On the recently issued logging memo, M-26-14, Polk described work through a newly revamped Committee on National Security Systems to harmonize policy wherever mission needs allow.
TrendAI™ threat intelligence update
The forum closed with a threat intelligence briefing from Jon Clay, vice president of threat intelligence at TrendAI™, drawing on the work of more than 500 TrendAI™ researchers worldwide in the company's bimonthly threat intelligence report. The report blends situational and technical analysis, looking beyond cyber to military, trade, and geopolitical developments that shape the threat environment.
Clay provided an overview of specific threat intelligence on China, North Korea, and Russia, and identified several cross-cutting trends. AI adoption is accelerating everywhere; adversaries will increasingly sell AI-automated attacks on the dark web; trusted infrastructure is becoming the new cover as adversaries turn victims' own environments against them; and malware as a service will make attribution progressively harder.
Clay’s recommendations for federal defenders were to patch the highest-leverage CVEs based on network-specific risk scores; monitor cloud services and runtime abuse; reduce operational technology and industrial control system (OT/ICS) exposure; harden identity and workforce; and hunt, not just detect.
Conclusion
The 2026 Threat Intelligence Forum painted a picture of a threat landscape moving at machine speed, where AI simultaneously empowers adversaries and equips defenders. Across the sessions, a clear prescription surfaced: pair AI-enabled defense with disciplined fundamentals, including risk-based patching, network visibility, identity hardening, and proactive threat hunting, and anchor it all in genuine and effective public-private partnership.
Like it? Add this infographic to your site:
1. Click on the box below. 2. Press Ctrl+A to select all. 3. Press Ctrl+C to copy. 4. Paste the code into your page (Ctrl+V).
Image will appear the same size as you see above.
Fault Lines in the AI Ecosystem: TrendAI™ State of AI Security Report
It’s By Design: The Use-After-Free of Azure Cloud
TrendAI™ 2026 Cyber Risk Report
Guarding LLMs With a Layered Prompt Injection Representation