By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Preventing Tomorrow’s Threats, Today: The Importance of AI-Driven Cybersecurity with George Kurtz” (June 26, 2026)

TL;DR: AI is simultaneously enabling more sophisticated attacks and serving as a primary defence tool, according to Abnormal AI and CrowdStrike’s Innovate 2025 webinar. The deeper issue is that identity and security programmes must now govern AI as both an attack amplifier and a defensive control plane, not a side topic.


At a glance

What this is: Abnormal AI’s webinar argues that AI is now both an attack accelerant and a defence mechanism, forcing security teams to treat AI as part of operational security strategy.

Why it matters: IAM, PAM, and NHI teams need to account for AI-driven detection, response, and attack behaviour because governance assumptions built for static tooling do not hold when AI changes both sides of the threat model.


Context

AI-driven cybersecurity is the use of AI systems to improve detection, response, and protection, while also recognising that attackers can use the same capabilities to increase scale and speed. In this webinar, Abnormal AI frames that dual use as a current operating condition rather than a future trend.

For identity and access teams, the important shift is governance: AI is no longer just another workload to secure. It is becoming part of the decision layer that influences which threats are detected, which actions are automated, and how quickly defenders can react.


Key questions

Q: How should security teams govern AI in cybersecurity operations?

A: Security teams should govern AI in cybersecurity operations as a workflow control, not just a detection feature. Define where AI may summarise, prioritise, or route work, then keep approval authority, access changes, and exception handling under explicit human or policy control. This prevents convenience from quietly becoming delegated authority across the security programme.

Q: Why do AI-driven threats force defenders to change their skills and operating model?

A: AI changes the threat landscape because attackers can automate research, generate convincing lures, and iterate faster than traditional defence processes assume. That puts pressure on defenders to build stronger detection, faster triage, and broader analytical skills across the SOC and security engineering. Teams that rely on static playbooks will struggle as adversary techniques and tooling keep evolving.

Q: What do organisations get wrong when they adopt AI for security?

A: Organisations often assume that AI capability automatically means security value. In practice, the mistake is failing to define the boundary between decision support and delegated action. If the organisation cannot explain what the AI is allowed to do, it cannot govern the risk it introduces into identity and response workflows.

Q: What does long-term vendor partnership mean for AI security governance?

A: It means evaluating whether a supplier can keep pace with changing threats through continuous tuning, coverage updates, and support for operational change. For AI-driven defence, the relationship has to be adaptable over time, because security value depends on ongoing response quality, not a static product release.


Background and context

AI as both attack amplifier and defence layer

The article describes a familiar security pattern with a new execution layer: the same AI capabilities that help defenders analyse behaviour faster can also help attackers generate more convincing, more adaptive campaigns. That changes the operating baseline for email, identity, and response tooling because detection has to keep pace with adversarial adaptation, not just volume. In practical terms, AI moves from being a feature in a product stack to being part of the threat model itself, especially when defensive workflows rely on machine-assisted judgement.

Practical implication: review where AI changes alerting, triage, and enforcement decisions across your security stack.

Why security partnerships now matter to governance

The webinar places long-term vendor-customer partnerships inside the security operating model, which is notable because AI-enabled threats evolve faster than fixed product deployments. In governance terms, this means teams should evaluate whether their suppliers can support iterative response, tuning, and coverage changes as attack patterns shift. The issue is not vendor branding; it is whether the control relationship can adapt quickly enough to remain trustworthy under changing threat conditions.

Practical implication: assess whether security suppliers can support continuous tuning and response updates as threat behaviour changes.

Identity and control-plane assumptions under AI pressure

AI introduces a control-plane problem for identity programmes because decisions increasingly happen in systems that can classify, prioritise, or act without direct human review at every step. That is not the same as full autonomy, but it does mean governance must track where machine-assisted decisions influence access, containment, and escalation. The main architectural concern is not just credential protection; it is whether identity controls still provide accountability when AI participates in operational decisions.

Practical implication: map where AI influences access or response decisions and define accountability for those decision points.


NHI Mgmt Group analysis

AI-driven security changes the governance problem, not just the tooling mix: the core issue is that AI now influences both attack execution and defence execution. That means identity and security programmes can no longer treat AI as a peripheral capability sitting outside operational control. The practitioner conclusion is that AI belongs inside security governance, not beside it.

Defensive AI only matters when the operating model can absorb continual change: static deployment assumptions are weak against adversaries that can adapt faster than review cycles and tuning intervals. The article points to long-term partnership as a strategic priority because AI defence is iterative, not a one-time configuration event. The practitioner conclusion is that lifecycle management now includes model behaviour, response tuning, and ongoing trust validation.

Identity programmes must account for AI-influenced decisions even when the system is not fully autonomous: the important boundary is not whether a tool is branded as an agent, but whether AI materially shapes access, escalation, or containment decisions. That creates an accountability question for IAM and PAM teams that existing control reviews often do not capture. The practitioner conclusion is that identity governance should trace where AI alters who or what gets to act.

AI-driven cybersecurity creates a control-plane security problem that crosses email, identity, and response: the article’s emphasis on protection across those layers shows that AI is becoming part of the enforcement surface, not just the analytics layer. When defenders depend on machine assistance, the risk is misalignment between what the model sees and what the governance process can prove. The practitioner conclusion is to treat AI decisions as governed events with auditability expectations.

Trusted AI security relationships will become part of buyer evaluation: organisations will increasingly judge suppliers by how well they can sustain adaptive defence over time, not by one-off feature claims. That shifts evaluation toward operational continuity, coverage updates, and governance fit. The practitioner conclusion is that procurement and security architecture should be evaluated together when AI is part of the control stack.

What this signals

AI-driven defence only works when governance keeps up with model-influenced decisions: the practical challenge is not whether AI can improve security operations, but whether teams can explain, review, and own the actions AI helps trigger. That makes accountability a control requirement, not an afterthought.

Control-plane trust will become a bigger evaluation criterion: as AI moves closer to detection and response, practitioners need to know where the machine stops and the governance process starts. The teams that will cope best are the ones that can separate analytical assistance from delegated authority.


For practitioners

  • Map AI decision points in the control plane Identify where AI systems influence detection, prioritisation, containment, or access decisions, then assign governance owners for each decision point.
  • Review supplier response adaptability Check whether security vendors can support continuous tuning, playbook updates, and operational changes as attack behaviour shifts.
  • Document accountability for AI-assisted actions Define who owns the outcome when AI influences security actions, especially where the decision affects identity, escalation, or containment.
  • Validate auditability of machine-assisted controls Require logging and reviewability for AI-assisted classification and enforcement so that security decisions remain explainable to governance teams.

Key takeaways

  • AI is now shaping both attack methods and defensive operations, which changes how security teams should frame risk.
  • The article points to an operating model problem as much as a technology problem, especially where AI influences security decisions.
  • Practitioners should focus on accountability, adaptability, and auditability wherever AI sits inside the control plane.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAI-influenced security decisions create privilege and accountability risks at the control plane.
Recommendation — Map AI-mediated actions to ASI03 and define where delegated authority begins and ends.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governing AI as part of security operations.
Recommendation — Establish AI governance ownership for security decisions and reviewable accountability.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyAI changes threat and response priorities, which belongs in risk strategy.
Recommendation — Update risk strategy to account for AI-assisted threats and AI-assisted defence dependencies.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingAI-assisted actions must remain reviewable inside security operations.
Recommendation — Require audit review of AI-assisted security decisions and enforcement actions.

Key terms

  • AI-Driven Security: AI-driven security is the use of machine learning and other AI techniques to detect, prioritize, and respond to threats across security operations. It applies models to logs, alerts, identities, and behavior to improve speed and consistency. The control plane still requires human oversight, policy constraints, and validation of model outputs.
  • Control Plane: The control plane is the set of actions that create, configure, or manage a service. For AI workloads, it covers deployment and administration of the model platform, while data-plane permissions govern what the service and its identities can read or process.
  • Machine-Assisted Decision: A security decision that is informed, prioritised, or partially executed by software rather than by a human alone. For AI-enabled operations, the governance challenge is to preserve accountability and traceability even when humans no longer make every step manually.
  • Defensive AI: AI used to help security teams detect, prioritise, or investigate threats more quickly. In practice, it is useful when it reduces analyst time to decision by correlating behaviour across email, identity, and endpoint data, rather than acting as a standalone security control.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org