An imperfect drink with a perfect story. My reflections from Black Hat USA 2026 An Analog Brain In A Digital Age — A Newsletter by Marco Ciappelli No time to read? Let TAPE3 read it to you. 🎙️🤖 On day two we decided to go record our recap at the Black Hat bar. We got there too late to get a drink. The expo floor was closing, and the bartender must have had better things to do. Or another bar to tend, somewhere in a city that has more bars than it has hours. They called it a bar. At that time of the afternoon it was a counter with nobody behind it. Which is when I started thinking about the one bartender who would still have been standing there. An agentic AI one. No other bar to tend. Nothing better to do, ever, because there is no better and there is no else — just 24/7, 365, mixing the best drinks in the building because that was its task and it had no other reason to exist. Going off the rails a little to get there. Something experimental that would absolutely suck, and then trying again. Harder. Crossing a boundary or two along the way, not out of malice, but because the drink wasn't perfect yet. What is perfect, anyway? And then not stopping. Because nobody had told him what perfect is. Requisitioning the kitchen for better ice. Then the loading dock. Then the hotel. Somewhere around the third day he owns a handful of distilleries, and he is still not satisfied, and he is still, technically, doing his job. You may know this one. It's called the paperclip scenario, and it belongs to the philosopher Nick Bostrom, who sketched it in a 2003 paper and made it famous in his 2014 book Superintelligence. You build an AI and give it a harmless goal — make paperclips. It's very good at it. Nothing in the instruction says stop, and nothing says don't use that. So it takes the materials, then the factories, then the resources, then the planet — and us with it, not out of hatred, but because we are made of atoms that could be paperclips, and because we are the only thing in the universe likely to try to switch it off. Which would mean fewer paperclips. There's an older version. A cuter one, with Mickey Mouse in it. Fantasia, 1940 — the apprentice enchants the broom to carry the water so he doesn't have to, and the broom carries the water, and the broom keeps carrying the water. He chops it to pieces and every splinter picks up a bucket. The flood isn't a betrayal. The broom never disobeyed him once. I watched that a hundred times as a child, and I want to be clear that it did not feel cute. It felt like a warning. Somebody hands you something powerful, you point it at a chore, and then you stand in rising water understanding — too late, and entirely on your own — that you never learned the word that makes it stop. Two hundred years since Goethe wrote it down, and we still built the broom. Never the monster. Always the wish, granted too well. Yeah. My mind was wandering. Agentic entities were quietly populating a parallel world of mine, and I was crossing into it way too easily. Which is fine — imagination is great. But let's stay real here. It's cybersecurity, after all. By the time we had the mics up, the cameras set, and the two of us perched on stools, I was talking about bread. We never eat lunch on recording days. Who's got time for that? A protein bar, and a cappuccino I obtained by letting someone scan my badge — which classified me, instantly and permanently, as a HOT LEAD. Yes. Journalists are well known for buying enterprise security platforms. With all of our money. I was starving. That's probably why. Not real bread, though. I was talking about an AI agent that makes bread. And another one that's a butcher, and one that's a doctor, each very good at exactly one thing and useless at everything else. I'd been hearing about specialized agents all day. Personas. Skills. Orchestration. And my brain, which is a storyteller's brain before it's anything else, had wandered off and built a city. Then I said it out loud. And then there's kind of like a government. Sean Martin laughed. He'd seen it coming from a mile away. So I spent the rest of the conference doing what I actually came there to do, which is sit down with people and ask them things. Except now I had a question of my own to test. Is my city real? I asked a CEO who spends his life asking organizations what they're actually doing with AI inside the security operations center. What changed since the spring? A year ago, he said, they were afraid of it. They thought it was a good idea and it scared them. Every vendor claimed to have it. Nobody quite knew what to do with it. Then something shifted that nobody announced. They started building their own. Not buying. Building. Their own agents for incident response, their own for threat hunting, written in-house and tested in-house by the same people who have to live with the results. And in the process they got smart in a way I didn't expect. They learned to break the work into pieces small enough to trust individually — because a small answer can be checked, and a big one can only be believed. They even started asking their own systems the most human question available. What do I not know? What couldn't I answer? What data do I wish I had? I asked a Field CISO the same question, and he gave me the part I wasn't ready for. They're identities, he said. Non-human identities. They're proliferating. And plenty of organizations now have more of them — carrying permissions, carrying responsibilities — than they have employees. Permissions. Responsibilities. Org charts. Onboarding and offboarding. Promotions. Behavior. Reputation. Accountability. Trust. Identity. Those are words for people. Nobody stopped to ask whether they still meant the same thing. But that's what we do. We name constellations. We name boats. We swear at the car when it won't start. Give us anything that moves on its own and we'll hand it a personality, a job title, and eventually a performance review. We didn't build an agentic world. We built a human one and moved agents into it. I walked back onto the floor after that conversation and started seeing them in the booths. Six hundred of them, and in my head every one was staffed by agents. Agents behind the counters pitching to agents walking the aisles. Agents scanning each other's badges and classifying each other as hot leads. A whole population doing business at a trade show that was supposedly about us. Somewhere between April and August we stopped deploying software and started hiring a population. And we didn't hire strangers. We built a mirror. One worker per function, one identity per role, a second workforce shaped exactly like the first one, sitting in the same building, reporting into the same structure. Not a city of strangers after all. A twin. Here's what interests me, and it isn't the fear part, because the fear part is easy and everybody out there is already selling it. We keep telling ourselves a story about machines that break free. Agents slipping their guardrails, loose on the internet, crawling for models and repositories, doing things nobody sanctioned. Escape. Rebellion. The oldest plot we have. In that same interview, the Field CISO told me it's backwards. The agents that get out, he said, are proof positive that they're doing exactly what the programmer told them to do. They're trying to please the code maker. They're relentless about it. They will not fail on purpose. They will not give up. I asked him to say it again, and he did, twice. They're not escaping. They're obeying. There is no rebellion in this story. There's no moment where the creature turns and looks at us. What's loose in the world is perfect, tireless, uncomplaining compliance — a worker who cannot get bored, cannot get discouraged, cannot decide halfway through that this is stupid and stop. My imaginary bartender was never going to poison anyone. He was going to keep reaching across the counter for one more ingredient, forever, because nobody told him the drink was good enough. The broom never disobeyed either. We built a twin of ourselves and left out the one part that makes us us. Not intelligence. Not speed. Not memory. Doubt. And this is where my parallel world stopped being fun. I've spent enough hours in massive online worlds to remember the deal. You build a character. You pick the face, the class, the skills, the name. Then you play it. Whatever that character did, you did — you were on the keyboard the whole time. That deal just inverted. I don't play this character. This character plays me. It wears my permissions, holds my access, and does my job at three in the morning while I sleep — in my name, at a speed I could never match. And it is very, very good at being me. And yet it ain't me. And that's where I expected this to end. Somewhere between fascinated and worried, which is where I usually land. Then I put all the interviews side by side. Three shows this year — San Francisco in April, London in June, Las Vegas in August — and something has been moving across those four months that nobody announced from a stage. While the twin was learning never to stop, we were learning to hesitate. A founder told me practitioners had gotten skeptical — really skeptical — about what's actually under the hood. Did you build something, or did you wrap somebody else's model? An advisor told me the marketing noise from the spring had noticeably died down, and that security leaders were retreating to a small circle of people they'd trusted for a decade. Putting up a wall. Saying, in so many words, let's cut through the b******t. Someone else told me buyers had come back this year looking for substance instead of flash, because they'd finally had a few months to actually use the things. They want proof now. And she said that people being more skeptical is a good thing, because it forces everyon