No. 19 / 339

What changes for cybersecurity with AI?

The shift

Tier-1 triage — enriching alerts, pivoting across logs, writing up what happened — goes from scarce analyst-hours to abundant, near-instant, and running at machine scale on both sides of the fight. The same shift that lets a SOC absorb thousands of alerts a shift lets an attacker automate reconnaissance, phishing, and exploit generation at the same speed.

The axioms

  • Alert volume is bounded by analyst headcount, so triage capacity is scarce and rationed by tier.
  • Writing working exploit code and chaining vulnerabilities requires scarce, specialized offensive skill.
  • The attacker needs more time and resources than the defender to find a way in, so patching cadence can lag.
  • A human reviewing a login, a device, or a service account can tell trusted from untrusted.
  • Identity and access are governable because the set of identities needing accounts is finite and mostly human.
  • Security tooling output is trustworthy because a human wrote the detection logic and can explain why it fired.
  • Someone is accountable when a breach happens — a named owner who approved the control or missed the gap.
  • Novel attack judgment — is this actually an intrusion, do we contain or watch — requires scarce contextual expertise.

Invalid axioms

  1. Alert volume is bounded by analyst headcount. Triage synthesis — correlating logs, enriching IOCs, drafting the incident note — is now abundant and near-free; agentic SOC platforms handle Tier-1 volume no human team could match. The habit-trap: orgs still staff and structure SOCs around a Tier-1/Tier-2/Tier-3 ladder built for headcount-constrained triage, and still hire entry-level analysts to do console-clicking work that's already been automated.
  2. Writing working exploit code requires scarce, specialized offensive skill. LLMs pattern-match against nearly every public exploit and CVE writeup ever written, so a plausible proof-of-concept for a known vulnerability class is now a prompt away. The habit-trap: security teams still price and schedule vulnerability response as if weaponization takes attacker-side expertise and days — 2026 data already shows continuous, agent-led testing covering ground manual pentest cycles couldn't touch, and attackers are moving on the same clock.
  3. The defender has more time than the attacker to close a gap. Patch-to-exploit windows assumed defenders had days between disclosure and a working attack; AI collapses reconnaissance and exploit generation to hours. The habit-trap: patch cadences, change-approval boards, and quarterly vulnerability scans are still sequenced for a threat clock that no longer exists.

Unchanged axioms

  1. Someone is accountable when a breach happens. A model cannot be named in a regulatory filing or fired. The CISO, the board, and the analyst who approved the containment call remain the answerable parties — AI adoption without a named owner for AI-driven decisions is itself the finding auditors are starting to flag.
  2. Novel, high-stakes judgment under ambiguity stays human. AI can flag the anomaly; it cannot reliably answer what happened, what it means for this specific business, or whether to contain or watch — that verdict rests on organizational context, risk appetite, and legal exposure no model has ground truth on. This is exactly where SOC analysts are shifting effort, not disappearing.
  3. Physical and transactional containment is still an action, not a token. Isolating a segment, rotating a credential, calling law enforcement, notifying customers — these require systems access, authority, and legal standing that generation alone doesn't confer, even as agentic tools increasingly execute the mechanical steps under supervision.
  4. Trust between a defender and the systems they're securing has to be earned, not generated. A confidently-wrong detection or a hallucinated root-cause is more dangerous than a slow but correct one, because the cost of acting on it — false containment, missed real intrusion — is asymmetric. Verification of the AI's own output stays a scarce, human-gated step.

New axioms

  1. Machine identities now outnumber human ones by two orders of magnitude, and nobody owns their lifecycle. When AI agents can call APIs, spawn sub-agents, and acquire permissions dynamically at runtime, identity governance built for a mostly-human, mostly-static set of accounts has no answer for who provisioned an agent, what it can reach, or when it should be deprovisioned.
  2. Verifying AI-generated security output at the volume AI produces it is itself unsolved. When a SOC platform can generate ten times the investigations a human team could, the bottleneck moves to spot-checking that abundance for confidently-wrong verdicts — and nobody has sized the human review capacity that requires.
  3. Attackers adopt unvetted AI faster than defenders can govern vetted AI. Threat actors have no compliance process slowing them down, so they operationalize each new capability immediately; defenders are stuck integrating the same capability through procurement, model risk review, and change control. The asymmetry in adoption speed, not just capability, is the new gap.
  4. Shadow AI inside the org is now a first-class attack surface. Employees and even security tools are already running unsanctioned AI against production systems and third-party data before anyone approved it, and most organizations can't yet detect, let alone contain, that usage if it's misused.
  5. AI red-teaming has to cover a target that didn't exist before — the model itself. Prompt injection, jailbreaks, and data leakage through retrieved context don't show up in a SAST scanner or a traditional pentest playbook, so testing programs built for code and network vulnerabilities are structurally blind to a growing share of what they're now expected to certify as safe.

Where it breaks

SOCs are restructuring analysts around AI-run triage (invalid axiom: headcount gates alert volume) at the same moment machine identities and shadow AI have quietly become the largest ungoverned attack surface in the enterprise (new problem: nobody owns non-human identity lifecycle). The team best positioned to own that gap — freed-up Tier-1 analysts — is being redeployed toward "strategic" investigation work, not toward the unglamorous job of inventorying and governing the agents the org itself just deployed.

Vulnerability response still runs on a patch-cycle clock built for a defender-has-more-time world (invalid), while AI has collapsed exploit generation to hours and continuous agentic testing already outpaces what change-approval boards can absorb (new). The result is faster, better vulnerability discovery feeding into a remediation process that still moves at pre-AI speed — widening, not closing, the exposure window.

Related axioms

Other axioms