INTERFACE Salt Lake City
September 22nd, 2026

  Presented by Marc Cressall, CISSP, President • ISC2 Salt Lake City

In a three-card monte game, the audience watches the lady (the card) and misses the move (the sleight of hand). The same thing is happening in AI security right now: teams are fixated on what the AI can do — the capability, the demo, the agent — while the real attack surface happens in the move: the data it's trained on, the prompts it trusts, the permissions it holds, the outputs it's allowed to act on.

What we cover:

  • Why "AI security theater" is the new compliance theater — green dashboards, checkbox governance, and visible controls that don't stop real risk
  • The three-card monte of AI: misdirection (watching the model), sleight of hand (unexamined agent permissions), audience management (performing for auditors), and the illusion of safety (false confidence from visible measures)
  • A live demonstration of the misdirection — watch the capability, miss the attack surface
  • The "Reclaim Reality" framework applied to AI: shift from compliance to capability, eliminate performative friction, foster a no-fault transparency culture, and measure reality (detection/response time, actual coverage) instead of appearance

Takeaways attendees walk away with:

  • A framework to spot AI security theater in their own programs
  • A Monday-morning checklist to audit their AI/agent attack surface
  • A practical path from checkbox governance to real AI security capability