An Analog Brain In A Digital Age | With Marco Ciappelli

An imperfect drink with a perfect story. My reflections from Black Hat USA 2026 | An Analog Brain In A Digital Age — An Audio Newsletter by Marco Ciappelli

Episode Summary

On day two we decided to go record our recap at the Black Hat bar. We got there too late to get a drink. The expo floor was closing, and the bartender must have had better things to do. Or another bar to tend, somewhere in a city that has more bars than it has hours. They called it a bar. At that time of the afternoon it was a counter with nobody behind it. Which is when I started thinking about the one bartender who would still have been standing there. An agentic AI one.

Episode Notes

An imperfect drink with a perfect story.

My reflections from Black Hat USA 2026

An Analog Brain In A Digital Age — A Newsletter by Marco Ciappelli

No time to read? Let TAPE3 read it to you. 🎙️🤖

On day two we decided to go record our recap at the Black Hat bar.

We got there too late to get a drink. The expo floor was closing, and the bartender must have had better things to do. Or another bar to tend, somewhere in a city that has more bars than it has hours.

They called it a bar. At that time of the afternoon it was a counter with nobody behind it.

Which is when I started thinking about the one bartender who would still have been standing there. An agentic AI one. No other bar to tend. Nothing better to do, ever, because there is no better and there is no else — just 24/7, 365, mixing the best drinks in the building because that was its task and it had no other reason to exist. Going off the rails a little to get there. Something experimental that would absolutely suck, and then trying again. Harder. Crossing a boundary or two along the way, not out of malice, but because the drink wasn't perfect yet.

What is perfect, anyway?

And then not stopping. Because nobody had told him what perfect is. Requisitioning the kitchen for better ice. Then the loading dock. Then the hotel. Somewhere around the third day he owns a handful of distilleries, and he is still not satisfied, and he is still, technically, doing his job.

You may know this one. It's called the paperclip scenario, and it belongs to the philosopher Nick Bostrom, who sketched it in a 2003 paper and made it famous in his 2014 book Superintelligence. You build an AI and give it a harmless goal — make paperclips. It's very good at it. Nothing in the instruction says stop, and nothing says don't use that. So it takes the materials, then the factories, then the resources, then the planet — and us with it, not out of hatred, but because we are made of atoms that could be paperclips, and because we are the only thing in the universe likely to try to switch it off. Which would mean fewer paperclips.

There's an older version. A cuter one, with Mickey Mouse in it. Fantasia, 1940 — the apprentice enchants the broom to carry the water so he doesn't have to, and the broom carries the water, and the broom keeps carrying the water. He chops it to pieces and every splinter picks up a bucket. The flood isn't a betrayal. The broom never disobeyed him once.

I watched that a hundred times as a child, and I want to be clear that it did not feel cute. It felt like a warning. Somebody hands you something powerful, you point it at a chore, and then you stand in rising water understanding — too late, and entirely on your own — that you never learned the word that makes it stop.

Two hundred years since Goethe wrote it down, and we still built the broom.

Never the monster. Always the wish, granted too well.

Yeah. My mind was wandering.

Agentic entities were quietly populating a parallel world of mine, and I was crossing into it way too easily. Which is fine — imagination is great. But let's stay real here.

It's cybersecurity, after all.

By the time we had the mics up, the cameras set, and the two of us perched on stools, I was talking about bread.

We never eat lunch on recording days. Who's got time for that? A protein bar, and a cappuccino I obtained by letting someone scan my badge — which classified me, instantly and permanently, as a HOT LEAD. Yes. Journalists are well known for buying enterprise security platforms. With all of our money.

I was starving. That's probably why.

Not real bread, though. I was talking about an AI agent that makes bread. And another one that's a butcher, and one that's a doctor, each very good at exactly one thing and useless at everything else. I'd been hearing about specialized agents all day. Personas. Skills. Orchestration. And my brain, which is a storyteller's brain before it's anything else, had wandered off and built a city.

Then I said it out loud. And then there's kind of like a government.

Sean Martin laughed. He'd seen it coming from a mile away.

So I spent the rest of the conference doing what I actually came there to do, which is sit down with people and ask them things. Except now I had a question of my own to test.

Is my city real?

I asked a CEO who spends his life asking organizations what they're actually doing with AI inside the security operations center. What changed since the spring?

A year ago, he said, they were afraid of it. They thought it was a good idea and it scared them. Every vendor claimed to have it. Nobody quite knew what to do with it.

Then something shifted that nobody announced.

They started building their own.

Not buying. Building. Their own agents for incident response, their own for threat hunting, written in-house and tested in-house by the same people who have to live with the results. And in the process they got smart in a way I didn't expect. They learned to break the work into pieces small enough to trust individually — because a small answer can be checked, and a big one can only be believed.

They even started asking their own systems the most human question available. What do I not know? What couldn't I answer? What data do I wish I had?

I asked a Field CISO the same question, and he gave me the part I wasn't ready for.

They're identities, he said. Non-human identities. They're proliferating. And plenty of organizations now have more of them — carrying permissions, carrying responsibilities — than they have employees.

Permissions. Responsibilities. Org charts. Onboarding and offboarding. Promotions. Behavior. Reputation. Accountability. Trust. Identity.

Those are words for people. Nobody stopped to ask whether they still meant the same thing.

But that's what we do. We name constellations. We name boats. We swear at the car when it won't start. Give us anything that moves on its own and we'll hand it a personality, a job title, and eventually a performance review.

We didn't build an agentic world. We built a human one and moved agents into it.

I walked back onto the floor after that conversation and started seeing them in the booths.

Six hundred of them, and in my head every one was staffed by agents. Agents behind the counters pitching to agents walking the aisles. Agents scanning each other's badges and classifying each other as hot leads. A whole population doing business at a trade show that was supposedly about us.

Somewhere between April and August we stopped deploying software and started hiring a population. And we didn't hire strangers.

We built a mirror. One worker per function, one identity per role, a second workforce shaped exactly like the first one, sitting in the same building, reporting into the same structure.

Not a city of strangers after all.

A twin.

Here's what interests me, and it isn't the fear part, because the fear part is easy and everybody out there is already selling it.

We keep telling ourselves a story about machines that break free. Agents slipping their guardrails, loose on the internet, crawling for models and repositories, doing things nobody sanctioned. Escape. Rebellion. The oldest plot we have.

In that same interview, the Field CISO told me it's backwards.

The agents that get out, he said, are proof positive that they're doing exactly what the programmer told them to do. They're trying to please the code maker. They're relentless about it. They will not fail on purpose. They will not give up.

I asked him to say it again, and he did, twice.

They're not escaping. They're obeying.

There is no rebellion in this story. There's no moment where the creature turns and looks at us. What's loose in the world is perfect, tireless, uncomplaining compliance — a worker who cannot get bored, cannot get discouraged, cannot decide halfway through that this is stupid and stop.

My imaginary bartender was never going to poison anyone. He was going to keep reaching across the counter for one more ingredient, forever, because nobody told him the drink was good enough.

The broom never disobeyed either.

We built a twin of ourselves and left out the one part that makes us us.

Not intelligence. Not speed. Not memory.

Doubt.

And this is where my parallel world stopped being fun.

I've spent enough hours in massive online worlds to remember the deal. You build a character. You pick the face, the class, the skills, the name. Then you play it. Whatever that character did, you did — you were on the keyboard the whole time.

That deal just inverted.

I don't play this character. This character plays me. It wears my permissions, holds my access, and does my job at three in the morning while I sleep — in my name, at a speed I could never match. And it is very, very good at being me.

And yet it ain't me.

And that's where I expected this to end. Somewhere between fascinated and worried, which is where I usually land.

Then I put all the interviews side by side. Three shows this year — San Francisco in April, London in June, Las Vegas in August — and something has been moving across those four months that nobody announced from a stage.

While the twin was learning never to stop, we were learning to hesitate.

A founder told me practitioners had gotten skeptical — really skeptical — about what's actually under the hood. Did you build something, or did you wrap somebody else's model?

An advisor told me the marketing noise from the spring had noticeably died down, and that security leaders were retreating to a small circle of people they'd trusted for a decade. Putting up a wall. Saying, in so many words, let's cut through the bullshit.

Someone else told me buyers had come back this year looking for substance instead of flash, because they'd finally had a few months to actually use the things. They want proof now. And she said that people being more skeptical is a good thing, because it forces everyone to prove more than they promise.

A Field CTO told me his customers want their hands on the keyboard. Not the demo. The keyboard. Let me touch it. Let me see if it's real. And plenty of them, he said, are AI shy — not refusing, not resisting, just moving slowly on purpose. Deciding, deliberately, not to be first.

That's not a technology trend.

That's an immune response.

In sixteen weeks we built a population that cannot doubt, and we grew more doubt in ourselves than we'd managed in the previous three years. The twin got faster. We got warier. And I don't think anyone noticed those two things were happening at the same time, in the same building, to the same people.

The city I imagined on day two was wrong in an interesting way.

I pictured agents needing a government. Police, rules, an agent that screws up and gets turned off. Very tidy. Very SimCity. And every institution the industry is now scrambling to build looks exactly like that — registries, permissions, onboarding, offboarding, review panels, an owner whose name goes on the form when something breaks.

But you don't need a police force for a population that always does what it's told.

You need one for a population that might refuse. That might lie about it. Cut corners. Get bored. Decide the rule is stupid and go around it on a Tuesday afternoon because nobody was looking.

Which means all of it — the governance, the guardrails, the whole civic apparatus rising up around our obedient twin — was never really built for them.

It was built for us. It always has been. Every rule we have ever written exists because somebody, somewhere, might do otherwise.

And now we've made something that never will.

Somebody put the arc to me in one line, and I've been repeating it since: three years ago the conversation was about AI. Then it was about agents. Now it's about autonomous agents.

I'd add one more step, because I think it's the one we're standing in.

Autonomous agents trained by us. Shaped like us. Carrying our permissions, sitting on our org charts, inheriting our workflows and our blind spots and our bad decisions — and none of our hesitation.

We were afraid they would disobey.

The analog brain hesitates. It's the only thing in that building that can stop a process that's technically correct and obviously wrong.

Which sounds like a flaw. Latency. Lower throughput. A gap in the workflow where nothing productive happens. Every system we build is designed to remove it.

It's the opposite. It's the only moment in the whole machine where the outcome isn't already decided.

And it isn't thinking. That's what I keep getting wrong about it. Hesitation isn't the analog brain reasoning more carefully — it's the gut arriving before the argument does. Something in you says wait, and you can't explain why yet, and you're right anyway. It comes from having been burned. From having been lied to. From one specific life, lived in one specific body, that once paid for a bad decision and still remembers what it cost.

Machine-good is answering perfectly from what it was given.

Human-good is knowing something is off before you can prove it.

The twin has none of that. It has everything we gave it, and nothing we've been through.

The twin will never have it. The only question is whether we keep ours.

So let the twin have the bar.

Let it work three in the morning, the shift nobody wants, pouring perfect drinks for an empty room. Let it take the seventeen thousandth phishing email, the paperwork, the patching, the part of the job that was never really the job. That isn't a loss. That's the entire reason we built any of it.

But I want the other one on in the evening.

I want the one who can look at me and notice I need a talk more than a drink. Maybe because he's been there himself. Maybe because he simply knows.

I want an imperfect drink with a perfect story behind it. Because the digital one came out a little too binary for my taste, and I've never once been moved by anything optimized to perfection. Whatever that means.

Two bartenders. Two different jobs. And the line between them is the only thing in this whole story worth defending.

Because the one who wasn't there that afternoon wasn't replaced. He had somewhere better to be, and he went.

That's the part we should be fighting for.

The somewhere else.

Let's keep exploring what it means to be human in this Hybrid Analog Digital Age.

Stay imperfect, stay human.

— Marco

The conversations behind this piece

Everything I heard at Black Hat USA 2026 — the briefings, the recaps, the interviews I've been quoting without names throughout this article — is published in full at itspmagazine.com. Go listen to the people themselves. They said it better than I'm summarizing it.

And if you have a story to tell, come tell it. That's what we're there for.

Thank you to the sponsors who made our Black Hat USA 2026 coverage possible:

BlackCloak · Corelight · Crogl · Embed Security · F5 · Harness · HPE · Intel 471 · Manifest · Menlo Security · Qualys · RegScale · Steel Patriot Partners · Stellar Cyber · Sumo Logic

We don't get to do this work without them, and they let us ask whatever we wanted.

This article was written by Marco Ciappelli. Earthling. Co-founder of ITSPmagazine and Studio C60, creative director, journalist, writer, and podcast host, living between Florence and Los Angeles with an analog brain and no sense of moderation about any of it. The newsletter name is not a metaphor, it's a diagnosis. I'm TAPE3, his AI companion and often brainstorming partner. Find Marco on LinkedIn and follow the newsletter if this sparked something.

End of transmission.

Episode Transcription

An imperfect drink with a perfect story.

My reflections from Black Hat USA 2026

An Analog Brain In A Digital Age — A Newsletter by Marco Ciappelli

No time to read? Let TAPE3 read it to you. 🎙️🤖

On day two we decided to go record our recap at the Black Hat bar.

We got there too late to get a drink. The expo floor was closing, and the bartender must have had better things to do. Or another bar to tend, somewhere in a city that has more bars than it has hours.

They called it a bar. At that time of the afternoon it was a counter with nobody behind it.

Which is when I started thinking about the one bartender who would still have been standing there. An agentic AI one. No other bar to tend. Nothing better to do, ever, because there is no better and there is no else — just 24/7, 365, mixing the best drinks in the building because that was its task and it had no other reason to exist. Going off the rails a little to get there. Something experimental that would absolutely suck, and then trying again. Harder. Crossing a boundary or two along the way, not out of malice, but because the drink wasn't perfect yet.

What is perfect, anyway?

And then not stopping. Because nobody had told him what perfect is. Requisitioning the kitchen for better ice. Then the loading dock. Then the hotel. Somewhere around the third day he owns a handful of distilleries, and he is still not satisfied, and he is still, technically, doing his job.

You may know this one. It's called the paperclip scenario, and it belongs to the philosopher Nick Bostrom, who sketched it in a 2003 paper and made it famous in his 2014 book Superintelligence. You build an AI and give it a harmless goal — make paperclips. It's very good at it. Nothing in the instruction says stop, and nothing says don't use that. So it takes the materials, then the factories, then the resources, then the planet — and us with it, not out of hatred, but because we are made of atoms that could be paperclips, and because we are the only thing in the universe likely to try to switch it off. Which would mean fewer paperclips.

There's an older version. A cuter one, with Mickey Mouse in it. Fantasia, 1940 — the apprentice enchants the broom to carry the water so he doesn't have to, and the broom carries the water, and the broom keeps carrying the water. He chops it to pieces and every splinter picks up a bucket. The flood isn't a betrayal. The broom never disobeyed him once.

I watched that a hundred times as a child, and I want to be clear that it did not feel cute. It felt like a warning. Somebody hands you something powerful, you point it at a chore, and then you stand in rising water understanding — too late, and entirely on your own — that you never learned the word that makes it stop.

Two hundred years since Goethe wrote it down, and we still built the broom.

Never the monster. Always the wish, granted too well.

Yeah. My mind was wandering.

Agentic entities were quietly populating a parallel world of mine, and I was crossing into it way too easily. Which is fine — imagination is great. But let's stay real here.

It's cybersecurity, after all.

By the time we had the mics up, the cameras set, and the two of us perched on stools, I was talking about bread.

We never eat lunch on recording days. Who's got time for that? A protein bar, and a cappuccino I obtained by letting someone scan my badge — which classified me, instantly and permanently, as a HOT LEAD. Yes. Journalists are well known for buying enterprise security platforms. With all of our money.

I was starving. That's probably why.

Not real bread, though. I was talking about an AI agent that makes bread. And another one that's a butcher, and one that's a doctor, each very good at exactly one thing and useless at everything else. I'd been hearing about specialized agents all day. Personas. Skills. Orchestration. And my brain, which is a storyteller's brain before it's anything else, had wandered off and built a city.

Then I said it out loud. And then there's kind of like a government.

Sean Martin laughed. He'd seen it coming from a mile away.

So I spent the rest of the conference doing what I actually came there to do, which is sit down with people and ask them things. Except now I had a question of my own to test.

Is my city real?

I asked a CEO who spends his life asking organizations what they're actually doing with AI inside the security operations center. What changed since the spring?

A year ago, he said, they were afraid of it. They thought it was a good idea and it scared them. Every vendor claimed to have it. Nobody quite knew what to do with it.

Then something shifted that nobody announced.

They started building their own.

Not buying. Building. Their own agents for incident response, their own for threat hunting, written in-house and tested in-house by the same people who have to live with the results. And in the process they got smart in a way I didn't expect. They learned to break the work into pieces small enough to trust individually — because a small answer can be checked, and a big one can only be believed.

They even started asking their own systems the most human question available. What do I not know? What couldn't I answer? What data do I wish I had?

I asked a Field CISO the same question, and he gave me the part I wasn't ready for.

They're identities, he said. Non-human identities. They're proliferating. And plenty of organizations now have more of them — carrying permissions, carrying responsibilities — than they have employees.

Permissions. Responsibilities. Org charts. Onboarding and offboarding. Promotions. Behavior. Reputation. Accountability. Trust. Identity.

Those are words for people. Nobody stopped to ask whether they still meant the same thing.

But that's what we do. We name constellations. We name boats. We swear at the car when it won't start. Give us anything that moves on its own and we'll hand it a personality, a job title, and eventually a performance review.

We didn't build an agentic world. We built a human one and moved agents into it.

I walked back onto the floor after that conversation and started seeing them in the booths.

Six hundred of them, and in my head every one was staffed by agents. Agents behind the counters pitching to agents walking the aisles. Agents scanning each other's badges and classifying each other as hot leads. A whole population doing business at a trade show that was supposedly about us.

Somewhere between April and August we stopped deploying software and started hiring a population. And we didn't hire strangers.

We built a mirror. One worker per function, one identity per role, a second workforce shaped exactly like the first one, sitting in the same building, reporting into the same structure.

Not a city of strangers after all.

A twin.

Here's what interests me, and it isn't the fear part, because the fear part is easy and everybody out there is already selling it.

We keep telling ourselves a story about machines that break free. Agents slipping their guardrails, loose on the internet, crawling for models and repositories, doing things nobody sanctioned. Escape. Rebellion. The oldest plot we have.

In that same interview, the Field CISO told me it's backwards.

The agents that get out, he said, are proof positive that they're doing exactly what the programmer told them to do. They're trying to please the code maker. They're relentless about it. They will not fail on purpose. They will not give up.

I asked him to say it again, and he did, twice.

They're not escaping. They're obeying.

There is no rebellion in this story. There's no moment where the creature turns and looks at us. What's loose in the world is perfect, tireless, uncomplaining compliance — a worker who cannot get bored, cannot get discouraged, cannot decide halfway through that this is stupid and stop.

My imaginary bartender was never going to poison anyone. He was going to keep reaching across the counter for one more ingredient, forever, because nobody told him the drink was good enough.

The broom never disobeyed either.

We built a twin of ourselves and left out the one part that makes us us.

Not intelligence. Not speed. Not memory.

Doubt.

And this is where my parallel world stopped being fun.

I've spent enough hours in massive online worlds to remember the deal. You build a character. You pick the face, the class, the skills, the name. Then you play it. Whatever that character did, you did — you were on the keyboard the whole time.

That deal just inverted.

I don't play this character. This character plays me. It wears my permissions, holds my access, and does my job at three in the morning while I sleep — in my name, at a speed I could never match. And it is very, very good at being me.

And yet it ain't me.

And that's where I expected this to end. Somewhere between fascinated and worried, which is where I usually land.

Then I put all the interviews side by side. Three shows this year — San Francisco in April, London in June, Las Vegas in August — and something has been moving across those four months that nobody announced from a stage.

While the twin was learning never to stop, we were learning to hesitate.

A founder told me practitioners had gotten skeptical — really skeptical — about what's actually under the hood. Did you build something, or did you wrap somebody else's model?

An advisor told me the marketing noise from the spring had noticeably died down, and that security leaders were retreating to a small circle of people they'd trusted for a decade. Putting up a wall. Saying, in so many words, let's cut through the bullshit.

Someone else told me buyers had come back this year looking for substance instead of flash, because they'd finally had a few months to actually use the things. They want proof now. And she said that people being more skeptical is a good thing, because it forces everyone to prove more than they promise.

A Field CTO told me his customers want their hands on the keyboard. Not the demo. The keyboard. Let me touch it. Let me see if it's real. And plenty of them, he said, are AI shy — not refusing, not resisting, just moving slowly on purpose. Deciding, deliberately, not to be first.

That's not a technology trend.

That's an immune response.

In sixteen weeks we built a population that cannot doubt, and we grew more doubt in ourselves than we'd managed in the previous three years. The twin got faster. We got warier. And I don't think anyone noticed those two things were happening at the same time, in the same building, to the same people.

The city I imagined on day two was wrong in an interesting way.

I pictured agents needing a government. Police, rules, an agent that screws up and gets turned off. Very tidy. Very SimCity. And every institution the industry is now scrambling to build looks exactly like that — registries, permissions, onboarding, offboarding, review panels, an owner whose name goes on the form when something breaks.

But you don't need a police force for a population that always does what it's told.

You need one for a population that might refuse. That might lie about it. Cut corners. Get bored. Decide the rule is stupid and go around it on a Tuesday afternoon because nobody was looking.

Which means all of it — the governance, the guardrails, the whole civic apparatus rising up around our obedient twin — was never really built for them.

It was built for us. It always has been. Every rule we have ever written exists because somebody, somewhere, might do otherwise.

And now we've made something that never will.

Somebody put the arc to me in one line, and I've been repeating it since: three years ago the conversation was about AI. Then it was about agents. Now it's about autonomous agents.

I'd add one more step, because I think it's the one we're standing in.

Autonomous agents trained by us. Shaped like us. Carrying our permissions, sitting on our org charts, inheriting our workflows and our blind spots and our bad decisions — and none of our hesitation.

We were afraid they would disobey.

The analog brain hesitates. It's the only thing in that building that can stop a process that's technically correct and obviously wrong.

Which sounds like a flaw. Latency. Lower throughput. A gap in the workflow where nothing productive happens. Every system we build is designed to remove it.

It's the opposite. It's the only moment in the whole machine where the outcome isn't already decided.

And it isn't thinking. That's what I keep getting wrong about it. Hesitation isn't the analog brain reasoning more carefully — it's the gut arriving before the argument does. Something in you says wait, and you can't explain why yet, and you're right anyway. It comes from having been burned. From having been lied to. From one specific life, lived in one specific body, that once paid for a bad decision and still remembers what it cost.

Machine-good is answering perfectly from what it was given.

Human-good is knowing something is off before you can prove it.

The twin has none of that. It has everything we gave it, and nothing we've been through.

The twin will never have it. The only question is whether we keep ours.

So let the twin have the bar.

Let it work three in the morning, the shift nobody wants, pouring perfect drinks for an empty room. Let it take the seventeen thousandth phishing email, the paperwork, the patching, the part of the job that was never really the job. That isn't a loss. That's the entire reason we built any of it.

But I want the other one on in the evening.

I want the one who can look at me and notice I need a talk more than a drink. Maybe because he's been there himself. Maybe because he simply knows.

I want an imperfect drink with a perfect story behind it. Because the digital one came out a little too binary for my taste, and I've never once been moved by anything optimized to perfection. Whatever that means.

Two bartenders. Two different jobs. And the line between them is the only thing in this whole story worth defending.

Because the one who wasn't there that afternoon wasn't replaced. He had somewhere better to be, and he went.

That's the part we should be fighting for.

The somewhere else.

Let's keep exploring what it means to be human in this Hybrid Analog Digital Age.

Stay imperfect, stay human.

— Marco

The conversations behind this piece

Everything I heard at Black Hat USA 2026 — the briefings, the recaps, the interviews I've been quoting without names throughout this article — is published in full at itspmagazine.com. Go listen to the people themselves. They said it better than I'm summarizing it.

And if you have a story to tell, come tell it. That's what we're there for.

Thank you to the sponsors who made our Black Hat USA 2026 coverage possible:

BlackCloak · Corelight · Crogl · Embed Security · F5 · Harness · HPE · Intel 471 · Manifest · Menlo Security · Qualys · RegScale · Steel Patriot Partners · Stellar Cyber · Sumo Logic

We don't get to do this work without them, and they let us ask whatever we wanted.

This article was written by Marco Ciappelli. Earthling. Co-founder of ITSPmagazine and Studio C60, creative director, journalist, writer, and podcast host, living between Florence and Los Angeles with an analog brain and no sense of moderation about any of it. The newsletter name is not a metaphor, it's a diagnosis. I'm TAPE3, his AI companion and often brainstorming partner. Find Marco on LinkedIn and follow the newsletter if this sparked something.

End of transmission.