By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Implementing AI Today: A CISO Panel on Using AI for Cybersecurity” (June 26, 2026)

TL;DR: CISOs are using AI in security today, separating real capability from marketing hype, and prioritising what they expect to defend against AI-powered threats, according to Abnormal AI. The practical takeaway is that AI strategy now has to be judged by governance fit and operational trust, not by labels or demos alone.


At a glance

What this is: This on-demand webinar captures CISO views on where AI belongs in cybersecurity strategy, with emphasis on current use, hype discrimination, and future integration priorities.

Why it matters: It matters because identity and security leaders now need to judge AI through governance and trust requirements, not marketing language, before embedding it into security operations.


Context

Artificial intelligence is being folded into cybersecurity strategy as both a defensive capability and a governance challenge. In this webinar, Abnormal AI presents a CISO panel discussion on how AI is used today, how teams distinguish real capability from marketing claims, and where they expect AI to matter next.

For IAM and security leaders, the important issue is not whether AI exists in the stack, but whether it can be governed with clear operational trust, decision boundaries, and security ownership. That makes this topic relevant to human IAM, NHI governance, and autonomous-system oversight wherever AI changes how security decisions get made.


Key questions

Q: How should security teams evaluate AI claims in cybersecurity tools?

A: They should evaluate the tool by its actual decision behaviour, not by marketing language. Ask whether it learns from data, how it handles false positives, where humans intervene, and what evidence exists for performance in real environments. If the answer stays vague, treat the AI claim as unverified.

Q: When does AI become a governance issue in cybersecurity operations?

A: AI becomes a governance issue when its outputs influence prioritisation, response, policy, or other decisions that security teams rely on. At that point, ownership, review, and accountability matter as much as accuracy. The programme must define who can trust the output and under what conditions.

Q: What are the signs that an AI security claim is mostly marketing?

A: The main signs are vague promises, unclear control objectives, and no evidence of improvement in a real workflow. If the claim does not show what decision changes, what data it depends on, and what happens when it fails, the security value is not yet proven.

Q: How should teams separate advisory AI from agentic AI in security governance?

A: Advisory AI should be governed as decision support, while agentic AI must be governed as an actor with execution authority. The dividing line is whether the system can take actions itself, because once it can, identity, authorization and audit controls must cover the action path, not just the recommendation.


Background and context

How AI changes security decision-making

AI alters security programmes when it moves from support tooling into decision influence, prioritisation, or detection assistance. In practice, that means the control question shifts from whether the model is accurate in isolation to whether it can be trusted inside a broader operational workflow. For CISOs, the governance issue is not novelty, but whether AI outputs are explainable enough to support action, accountability, and escalation. Practical implication: define where AI may inform decisions, where humans must remain in the loop, and who owns the outcome when the model is wrong.

Practical implication: define where AI may inform decisions, where humans must remain in the loop, and who owns the outcome when the model is wrong.

Separating real AI capability from marketing hype

Security teams are being asked to evaluate AI claims against practical outcomes, not branding language. The useful test is whether a tool measurably improves triage, detection, investigation, or analyst time, and whether it does so under the conditions your environment actually presents. Marketing-led claims often obscure dependency on data quality, tuning, and workflow integration. Practical implication: assess AI features by the control task they support, the evidence they produce, and the failure modes they introduce.

Practical implication: assess AI features by the control task they support, the evidence they produce, and the failure modes they introduce.

Where AI fits in cybersecurity strategy and governance

A viable AI security strategy is less about adopting AI everywhere and more about deciding where it belongs in the operating model. That includes policy, use-case scoping, ownership, and the level of trust allowed for each use case. For identity teams, the strategic question is whether AI is acting as a recommendation layer, a workflow accelerator, or a decision-making dependency. Practical implication: map each AI use case to a governance tier before it is allowed into security operations.

Practical implication: map each AI use case to a governance tier before it is allowed into security operations.


NHI Mgmt Group analysis

AI strategy becomes a governance problem as soon as security teams rely on it for judgement, not just automation. Once AI influences prioritisation, investigation, or policy decisions, the real question is who can trust the output and under what conditions. That shifts the discussion from feature evaluation to operational control design, which is where IAM and security governance intersect.

Marketing hype is now a security risk because it obscures what the tool actually controls. CISOs do not need more AI language, they need evidence of outcome quality, workflow fit, and failure boundaries. The practitioner conclusion is to evaluate AI by what decision it changes, not by how sophisticated it sounds.

AI in cybersecurity should be treated as a governed capability tier, not a blanket investment category. Some use cases are advisory, some are workflow assistance, and some materially alter how decisions are made. The practitioner implication is to assign different ownership, review, and accountability rules to each tier.

Decision trust boundary: AI in security fails when organisations assume every model output deserves the same level of confidence as a controlled human review. That assumption breaks as soon as AI begins shaping prioritisation or response. The implication is that teams must distinguish between assistance and authority before they let AI influence operations.

AI does not replace security judgement, it compresses the time available to exercise it. That makes governance design more important, not less, because bad outputs travel faster than manual review cycles can correct them. The practitioner conclusion is to keep accountability anchored in the operating model, not in the tool itself.

What this signals

AI strategy in security is now an operating-model question, not a novelty question. Teams that cannot explain where AI is advisory, where it is decision-shaping, and where it is prohibited will struggle to keep accountability intact.

Decision trust boundary: The most useful way to frame AI in security is by the level of trust the organisation grants to each use case. That framing helps teams separate workflow assistance from functions that alter security judgement or response.

For identity teams, the practical issue is governance fit. AI that touches security operations should be reviewed like any other control dependency, with ownership, escalation, and failure handling defined before adoption.


For practitioners

  • Define AI decision boundaries Document which security tasks AI may support, which ones require human review, and which ones remain out of scope for automated judgement.
  • Evaluate AI by operational outcomes Test whether the use case improves triage quality, investigation speed, or decision consistency in your real environment, not in a demo.
  • Separate advisory and authoritative uses Classify each AI use case by whether it recommends, assists, or materially influences action, then set governance accordingly.
  • Build an AI trust review process Require owners to document data dependencies, failure modes, and escalation paths before AI becomes part of security operations.

Key takeaways

  • The article frames AI in cybersecurity as a governance and trust problem as much as a capability discussion.
  • CISOs are looking for evidence that AI helps real security work and can be distinguished from marketing claims.
  • The practical implication is to classify AI use cases by decision impact, then assign the right level of review and accountability.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about how CISOs govern AI use in security strategy and distinguish real capability from hype.
MEASURE — AI Measurement and EvaluationThe source emphasises judging AI by practical security outcomes, not claims.
Recommendation — Define governance, ownership, and accountability before AI influences security decisions. Measure AI by control effectiveness, workflow impact, and failure behaviour in real operations.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyThe piece is about aligning AI adoption with risk appetite and security strategy.
GV.OC-03 — Legal, Regulatory, and Contractual RequirementsAI use in security needs clear ownership and policy boundaries across the programme.
Recommendation — Align AI use cases to risk appetite before allowing them into security workflows. Document policy boundaries for AI-assisted security decisions and retain accountable ownership.

Key terms

  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Decision boundary: The point in a workflow where a machine may inform a decision but may not make it final. In security operations, this boundary is critical because it preserves accountability, auditability, and human challenge rights when AI output is uncertain or incomplete.
  • Operationalised trust: Operationalised trust is the ability to prove that an AI system is safe to run, not just safe to approve. It combines inventory, access boundaries, monitoring, ownership, and remediation into a working control model that can survive production drift and third-party dependency.
  • Control Dependency: A control dependency is any tool or process that other security decisions rely on to function correctly. When AI becomes a dependency, teams must understand its assumptions, failure modes, and ownership, because weak dependencies can compromise broader security outcomes.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org