Heard at .conf26: Trust in AI at Scale Is Earned One Step at a Time

Artificial Intelligence Megan Ritchie

Key takeaways

  1. Organizations are testing AI agents extensively before production use, gradually expanding their permissions only as the agents prove reliable over time.
  2. Clean, accurate data is critical for AI success, as one company saw a 90% false positive rate when rolling out automation on unprepared data.
  3. Companies are adding safeguards like a second AI agent to review decisions, limiting how many actions an agent can take, and requiring human approval for critical actions.

Step into the Pavilion to be greeted with buzz, buffered by thoughtfully designed pockets of calm. To the left, the Splunk T-shirt store displayed newly minted tees. “On Wednesdays, we wear black,” read one (in a Splunky wink, the “black” rendered in pink). Another, which read: “Stuck in the MDL with you,” made an appearance on more than one speaker during the day two keynotes.

To the right, a spacious lounge with low-set furniture yawned into the West Theater, which hosted a steady rotation of speakers and sessions ranging from the Splunkie Awards Ceremony to a thought-provoking talk on what an autonomous SOC looks like.

Beyond that? A world of cool, from the perennial favorite Boss of the SOC (BOTS) to Innovation Labs, an NDA-protected space where customers got a behind-the-scenes look at what’s next and what might be — early ideas ready to be explored, questioned, challenged, and improved.

What Does Trusted AI at Scale Look Like?

This year’s mile-high .conf was one for the books. Energy engineers traded notes with SOC directors and security leaders swapped stories with the community members who've been attending .conf for more than a decade. We talked to as many attendees as we could. And of course, top of mind was autonomous AI.

One attendee described an AI agent tasked with cracking a QR code. When it failed, it improvised: dialing random phone numbers until a person picked up. Another customer described a fast-food chatbot that got talked into solving a customer's homework in exchange for a free order. These stories got laughs on the show floor, but they also captured something serious: AI agents are already acting in the world, and they don't (by design) act the way anyone expected. So, we asked: How do you scale AI you can actually trust?

Here's what we heard.

1. Trust Is Built, Not Assumed

Several attendees, ranging from CTOs of large national infrastructure organizations to professional services companies, described testing automation to exhaustion before letting it near production, signing off only once results are as close to human-verified accuracy as possible.

Asurion's Bill Ouellette put it plainly from the Day two stage: "Like interns, agents earn trust, not assume it. Our trust but verify model moves each agent up a trust ladder as it proves itself, steadily expanding what it's allowed to own."

From the same stage, Anthropic's Jenny Sha described the same standard in more personal terms: "I can see what it did. I understand why. It stays inside the permissions I gave it."

asurion-keynote-use.jpg

2. Fundamentals Still Decide the Outcome

Several conversations circled back to a less glamorous truth: AI amplifies whatever foundation it's built on. Over a cup of coffee on the Blackbird Terrace, one CISO posited that the answer to security is in the fundamentals, pointing to accurate asset inventories and real patching discipline, and warned that AI is making it easier to chase technical fixes for problems that are fundamentally human.

Hossein Khorsha of Constellation Energy, a keynote speaker on the second day of .conf26, offered a concrete version of the same lesson: An early risk-based alerting rollout produced near-total (90%) false positives because the underlying data wasn't ready.

But that clean, reliable data that AI needs can cost organizations many, many dollars. It’s enough that Kamal Hathi, General Manager for Splunk at Cisco, named spend directly as one of three constraints holding teams back this year, alongside skill and speed.

3. Governance Is the Discipline That Makes Autonomy Possible

A Splunk partner and early adopter of AI Launchpad described building a "challenger model," a second agent whose only job is to review and, if needed, veto the first agent's decision before it executes. His team also caps agentic workflows at eight to 10 actions on purpose, limiting how much damage a single misstep can cause, and ties every agent's access to the specific permissions its human counterpart holds, not a shared, broader set.

And with so many nerds consolidated in one spot, of course the Marvel Universe entered the chat. One security director compared unchecked AI innovation to Tony Stark building Ultron: constant progress with no one assigned to watch for what it might become.

Constellation Energy’s Khorsha noted that some decisions, like shutting down operational technology, still require a human signature every time, regardless of how much an agent has proven itself elsewhere. John Morgan's day two keynote named this explicitly as one of the four pillars of the agentic SOC: governance and policy, grounded in standard operating procedures, approvals, and auditability.

A Brain Trust That’s up To Task

Across every conversation, keynote, and session, a consistent pattern held: trust-building, clean, reliable data, and governance promise to compound into something durable enough to call “trust at scale.”

The Pavilion crowds, the hallway debates, and the t-shirt puns added up to exactly what .conf26 set out to be: a brain trust, gathered for three days in early September at 5,280 feet above sea level to wrestle with some of the most consequential questions not just in tech, but in the world at large.

Thanks for a very Splunky .conf26. See you next year in the Windy City.

conf-chicago-1.jpg

Related Articles

Navigating NIS2 - Accelerating IT/OT Security in Manufacturing with Splunk, Claroty and AWS
Security

Navigating NIS2 - Accelerating IT/OT Security in Manufacturing with Splunk, Claroty and AWS

Explore the 3 biggest manufacturing challenges in 2026: NIS2 compliance, cyber risks, and IT/OT convergence. Learn how an integrated ecosystem from Claroty, AWS, and Splunk enables a secure risk reduction journey for your industrial operations. Stay resilient and compliant in a connected world.
Approaching Linux Post-Exploitation with Splunk Attack Range
Security
7 Minute Read

Approaching Linux Post-Exploitation with Splunk Attack Range

An introduction to linux post exploitation simulation and threat detection using Splunk Attack Range and linux Sysmon.
These Are The Drivers You Are Looking For: Detect and Prevent Malicious Drivers
Security
15 Minute Read

These Are The Drivers You Are Looking For: Detect and Prevent Malicious Drivers

The Splunk Threat Research Team explores how to detect and prevent malicious drivers and discusses Splunk Security Content available to defend against these types of attacks.