TL;DR: AI can speed up vendor risk work, threat detection, application security, and SecOps triage, but the article argues it will augment rather than replace cybersecurity jobs. It cites 3.5 million unfilled cybersecurity roles and a Fortinet study showing 70% of organisations say skills shortages increase risk, underscoring why human oversight still matters.
At a glance
What this is: This is a viewpoint article arguing that AI will reshape cybersecurity work more than it will eliminate security roles.
Why it matters: It matters because IAM, SecOps, and governance teams need to decide which tasks AI can safely automate and where human accountability remains essential.
By the numbers:
- 70% of organizations said the skills shortage and unfilled jobs increases security risks for their organization.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).
👉 Read Prophet's analysis of whether AI will replace cybersecurity jobs
Context
AI is already changing security workflows, but the core governance problem is not whether machines can assist with analysis. It is whether organisations can safely delegate security decisions, triage, and remediation without creating new blind spots in accountability, access, and verification. In practice, that question now sits at the intersection of SecOps, IAM, and emerging AI governance.
The article’s primary claim is that AI will change the shape of cybersecurity jobs rather than remove the need for human practitioners. That is broadly typical of how most enterprises should think about AI adoption today: automate repeatable work, but keep human ownership for exceptions, adversarial judgement, and control enforcement.
Key questions
Q: How should security teams use AI without turning it into a control dependency?
A: Security teams should use AI for summarisation, correlation, and prioritisation, then keep containment in deterministic controls such as access policy, segmentation, and revocation. The key rule is that AI can recommend action, but it should not be the only mechanism that can stop exposure. That separation reduces false confidence and preserves auditability.
Q: Why does AI not eliminate the need for security analysts?
A: Security work is adversarial, context-heavy, and often ambiguous. AI can process patterns quickly, but it cannot reliably judge business impact, resolve contradictory evidence, or explain high-stakes decisions with the transparency that regulated environments require. Analysts remain necessary for interpretation, exception handling, and final accountability.
Q: What do organisations get wrong about AI-driven cyber risk?
A: They often assume the main change is autonomous attackers, when the immediate change is faster and more variable abuse of existing identity pathways. That mistake pushes attention toward speculative defenses instead of scoped access, strong telemetry, and response readiness. The operational risk is already here, even if full autonomy is not.
Q: How should security teams govern AI-enabled workflows that can act on their own?
A: Treat them as identity-governed execution paths, not just software features. Assign a named owner, define least-privilege access, log every tool call, and require revocation paths for credentials and tokens. If the workflow can touch production systems or sensitive data, its permissions must be reviewed with the same discipline used for privileged machine identities.
Technical breakdown
How AI changes security operations workflows
LLMs can accelerate common SecOps tasks by summarising alerts, enriching events with context, and suggesting next steps. That makes them useful in triage, investigation, and response, where the bottleneck is often analyst time rather than raw data volume. But these systems do not remove the need for decision quality. They can mis-rank evidence, miss novel attack patterns, or overstate confidence when the underlying data is incomplete. In security operations, speed only helps if the workflow still preserves validation, escalation, and auditability.
Practical implication: introduce AI as an assistive layer in SecOps, not as the final decision-maker for containment or closure.
Why AI does not eliminate the need for human judgement
Cybersecurity is adversarial, which means defenders are constantly reacting to adaptive attackers rather than fixed rules. Human analysts still matter when an incident involves ambiguous signals, contradictory evidence, or business context that a model cannot infer reliably. AI also struggles with transparency, which creates a governance problem in regulated environments where teams must explain why a decision was made. That is especially relevant when AI is used in investigations that may affect access, customer trust, or incident reporting.
Practical implication: retain human approval for high-impact security decisions and any workflow that requires explainable evidence.
AI skills gaps and the future security workforce
The article points to a future of hybrid teams, where AI handles repetitive analysis and humans focus on strategy, exception handling, and policy. That implies new role design rather than simple headcount reduction. Security teams will need people who can evaluate AI outputs, tune workflows, and govern how automation interacts with access and response processes. The real workforce shift is toward supervision, not replacement.
Practical implication: build training and role definitions around AI oversight, workflow governance, and exception management.
NHI Mgmt Group analysis
AI will reshape security work, but it does not remove the governance burden. The article correctly frames AI as a force multiplier rather than a direct replacement for security teams. In practice, automation shifts where judgement sits, but it does not eliminate the need for ownership, escalation, or evidence review. For IAM and SecOps leaders, the question is not whether AI works, but which decisions must stay under human accountability.
Security teams are moving from task execution to control supervision. When AI handles alert enrichment, drafting, or repetitive review, the human role becomes defining boundaries, validating outputs, and managing exceptions. That changes operating models for SOC and identity programmes alike, especially where access decisions or incident actions have downstream compliance effects. Practitioners should treat AI as part of the control plane, not just the productivity layer.
AI introduces a new supervision problem in identity and access workflows. Once security teams allow AI to assist with investigation or remediation, the model itself becomes a governed actor in the process. That raises questions about approvals, logging, privilege boundaries, and who is accountable when an automated recommendation is wrong. For identity programmes, the most important control shift is from static permissions to auditable delegation.
Human expertise remains the differentiator in adversarial environments. The article’s strongest point is that attackers adapt faster than policy templates do. AI can help with scale, but it cannot replace the contextual reasoning required when signals conflict or when the blast radius of a mistake is high. The practical conclusion is that AI should narrow analyst load, not dilute decision authority.
AI governance debt: the operational risk of scaling automation faster than accountability. This article points toward a category problem that many teams are already creating. If organisations expand AI use across security operations without redefining ownership, review, and logging, they accumulate hidden governance debt. Practitioners should design the operating model before they expand the tooling footprint.
What this signals
AI supervision will become a standard control domain inside security programmes. As AI enters triage and investigative workflows, teams will need explicit policy on what the model may recommend, what it may execute, and how overrides are recorded. The identity angle matters because any AI that touches access, secrets, or privileged response becomes part of the governance surface, not just the productivity stack.
Governance debt will accumulate fastest where AI is adopted without role redesign. Security leaders should expect pressure to automate routine work, but the hidden risk is unmanaged delegation. The practical response is to define supervision patterns now, then align them with NIST Cybersecurity Framework 2.0 govern and respond outcomes.
AI-assisted security will change the evidence standard for operations. Teams will increasingly need to prove not only that an alert was handled, but that the AI output was validated, corrected when necessary, and retained for audit. That is a control problem as much as a tooling problem, and it is especially relevant when AI touches identity-related decisions or privileged remediation.
For practitioners
- Define the human decision boundary Map which SecOps and IAM decisions AI may recommend, which it may execute, and which always require human approval. Treat incident containment, access removal, and customer-impacting actions as high-risk decisions that need explicit accountability and audit trails.
- Limit AI to assistive workflows first Start with low-risk tasks such as alert summarisation, enrichment, and draft investigation notes. Keep validation, escalation, and final remediation in human hands until you can measure model accuracy, drift, and failure modes across real incidents.
- Build oversight into identity and access operations If AI is used to support access reviews, policy drafting, or privileged response actions, log every recommendation, approval, and override. That creates evidence for compliance reviews and helps detect when AI is influencing security decisions outside intended scope.
- Train analysts for AI supervision Update role descriptions so practitioners are assessed on judgement, exception handling, and workflow governance, not only alert throughput. Pair that with hands-on training so teams can recognise when an AI output is incomplete, misleading, or overconfident.
Key takeaways
- AI is more likely to augment cybersecurity work than replace it, because security operations still depend on judgement, context, and accountability.
- The workforce impact is really a governance impact, with AI shifting teams from repetitive execution toward supervision, validation, and exception handling.
- Security leaders should define decision boundaries, logging, and approval paths before AI is allowed into access or incident workflows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | GOVERN | The article is fundamentally about governance of AI use in security work. |
| NIST CSF 2.0 | GV.OV-01 | AI-assisted security work changes governance and oversight expectations. |
| NIST SP 800-53 Rev 5 | AU-12 | AI-supported security decisions need durable logging and evidence retention. |
| ISO/IEC 27001:2022 | A.5.2 | Role clarity is central when automation changes who makes security decisions. |
| MITRE ATT&CK | TA0007 , Discovery; TA0009 , Collection | The article references AI in detection and investigation workflows, where collection and discovery are core. |
Use ATT&CK to validate that AI-assisted analysis still supports the required detection and collection outcomes.
Key terms
- AI supervision: AI supervision is the practice of overseeing model outputs, recommendations, and automated actions so they remain within defined limits. In security operations, it includes approval thresholds, logging, exception handling, and rollback paths for anything AI touches.
- Hybrid security: Hybrid security is the practice of protecting systems that run partly on premises and partly in cloud services. The challenge is that identity, access, and monitoring controls often behave differently across those environments, which creates inconsistent privilege and broader attack paths if governance is fragmented.
- Local Explainability: Local explainability describes why a model produced one specific result for one specific case. It is most useful when a customer, investigator, or reviewer needs a decision reason that is tied to the exact inputs in play, such as a credit denial or a fraud alert.
- Governance Debt: The accumulation of unresolved identity control weaknesses created when teams prioritise speed over lifecycle design. In NHI environments, it shows up as accounts with unclear ownership, undocumented purpose, stale credentials, and no reliable retirement path, all of which make later security work harder.
What's in the full article
Prophet's full article covers the practical workforce and tooling discussion this post intentionally leaves at a strategic level:
- How AI is framed across vendor risk management, threat detection, application security, and SecOps use cases
- The article's argument for hybrid teams and why routine analysis may shift faster than strategic security work
- The discussion of human intuition, explainability, and why current LLMs still struggle in adversarial environments
- Prophet's view of new career paths such as AI security specialists
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management for practitioners building stronger identity control models. It is designed for security teams that need a practical foundation for governing identities and access across modern environments.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org