Follow the events that change operating models, not just marketing slides.

The point of this radar is not to list every conference. It is to track the events that can change how teams defend production systems, govern AI tools, and explain risk to leadership.

Which events are likely to produce practical guidance for AI agents, SOC copilots, and AppSec workflows?

Where will enterprise teams hear concrete patterns for identity, sandboxing, and operational AI controls?

Which conference themes are turning into real budgets, tooling, and board conversations?

The conferences most worth tracking next.

October 27-29, 2026San Francisco

[un]prompted II

A practitioner-led AI security conference is more likely to produce usable patterns for agent deployment, prompt-injection defense, governance, and operational failures than broad vendor events.

Agent security in production systemsPractical prompt and tool abuse lessonsWhat builders learned after shipping AI security controls

Featured videoBlack-Hat LLMs: How AI Is Rewriting the Rules of Vulnerability Research

November 2-3, 2026Arlington, Virginia + Virtual

SANS AI Cybersecurity Summit Fall 2026

SANS is a useful signal source because its AI security programming tends to translate hype into training, controls, and practitioner language.

AI-powered attacks and defensive automationSOC and incident-response operating patternsTraining material security teams can reuse

Featured videoJay Beale on Kubernetes, DEF CON, and AI Attack Paths

October 15-22, 2026Arlington, Virginia + Virtual

SANS DFIR Summit & Training 2026

AI-speed incidents still end in DFIR fundamentals: evidence, timelines, identity paths, cloud logs, ransomware decisions, and executive-ready incident narratives.

AI-assisted incident timelinesCloud forensics and identity evidenceRansomware and threat hunting playbooks

Featured videoSANS DFIR channel: investigation, cloud forensics, and response talks

October 6-8, 2026Toronto

SecTor 2026 AI x Cloud Security Summit

SecTor added an AI x Cloud Security Summit bundle in 2026, making it useful for tracking the intersection of cloud identity, AI workloads, and practical offensive research.

AI x cloud security patternsOffensive research with defender takeawaysCanadian and North American security signal

Featured videoBlack Hat channel: cloud, AI, and vulnerability research talks

November 9-12, 2026Salt Lake City

KubeCon + CloudNativeCon North America 2026

AI agents are becoming cloud-native workloads. KubeCon added an AI Inference + Agentic track in 2026, alongside security sessions on supply chain, identity, runtime protection, vulnerability management, and policy enforcement.

Kubernetes controls for agent runtimesAI Inference + Agentic trackCloud-native supply-chain securityRuntime observability for AI workloads

Featured videoCNCF channel: KubeCon keynotes and cloud-native security sessions

November 17-20, 2026Moscone Center, San Francisco + Digital

Microsoft Ignite 2026

Ignite is where Microsoft turns AI, identity, endpoint, cloud, and security defaults into enterprise operating guidance. That makes it important for CISO and platform teams.

Copilot governance and identity controlsDefender and cloud security integrationEnterprise AI rollout lessons

Featured videoZero-Trust Security for Autonomous AI Agents in Azure AI Foundry

November 30-December 4, 2026Las Vegas

AWS re:Invent 2026

re:Invent is where cloud identity, platform guardrails, and AI infrastructure choices get translated into defaults that large enterprises actually deploy.

Secure cloud agents and permission boundariesBedrock and foundation-model governance patternsIdentity, logging, and runtime controls at scale

Featured videoAWS re:Invent 2025 - Werner Vogels Keynote

Use conference videos as source material, not filler.

HackWednesday should embed or link conference videos when they help defenders understand a real control: AI agent isolation, cloud identity, SOC automation, software supply chain security, model evaluation, or incident response.

Track official keynotes and security sessions first; they are safer to cite and easier for readers to verify.

Prioritize videos that show architecture, demos, incident lessons, or governance patterns instead of generic product reels.

Turn each useful talk into one HackWednesday takeaway: what changed, what teams should test, and what controls matter next.