By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Using AI to Enhance Defensive Cybersecurity” (June 26, 2026)

TL;DR: Research with 125 security and AI leaders by Osterman Research shows defenders are already using behavioural AI and automation to reduce fatigue, improve accuracy, and respond at scale while attackers use generative AI and GANs to press offensive advantages, according to Abnormal AI. The shift is less about tool adoption and more about whether security programmes can absorb AI without creating new governance blind spots.


At a glance

What this is: This webinar summary says security teams are using defensive AI, behavioural AI, and automation to relieve alert overload while attackers increasingly use generative AI and GANs offensively.

Why it matters: It matters because IAM, SOC, and NHI programmes now need to decide where AI improves detection and response, and where it creates new governance blind spots.


Context

Alert overload is a governance problem before it is a tooling problem. When analysts cannot keep up with volume, security teams lose accuracy, delay response, and miss the signals that should drive access, identity, and incident decisions.

This webinar frames defensive AI as a way to reduce fatigue and improve response at scale. The identity security angle is broader than email or SOC operations: any environment that uses AI to accelerate triage or automate response needs clear ownership, review boundaries, and escalation logic.

The article also points to an adversarial shift, with attackers using generative AI and GANs to gain offensive advantage. That makes the quality of defensive decision-making more important than simple alert throughput.


Key questions

Q: How should security teams use AI triage without creating a false sense of accuracy?

A: AI triage should be used as a decision filter, not as an oracle. Teams need to validate that the model is correlating reachability, exploitability, and business context, and they should review samples of both suppressed and promoted findings. If the tool cannot show why an issue was deprioritised, it should not be the sole basis for remediation decisions.

Q: Why does alert overload increase the risk of missed identity compromise?

A: Alert overload forces analysts to sample rather than fully investigate, which means identity abuse can hide inside a backlog until the attacker has already moved beyond the initial foothold. When the queue is too large, the organisation loses confidence in its own visibility. That is why triage capacity is a security control, not just an operational metric.

Q: What are the signs that defensive AI is helping rather than just shifting the workload?

A: Look for shorter decision times, fewer repetitive escalations, better analyst focus on high-risk events, and consistent human review of significant actions. If the team still feels overloaded, or if AI-generated outputs create more exceptions than they remove, the programme is likely adding complexity instead of reducing it.

Q: What should organisations do when generative AI makes attacks harder to spot by content alone?

A: Move detection away from surface cues and toward behaviour, provenance, and response context. Security teams should assume that wording, formatting, and other superficial indicators can be synthetic, so controls need stronger signals about who acted, what changed, and whether the pattern fits expected activity.


Background and context

How behavioural AI reduces alert fatigue

Behavioural AI looks for patterns in user, account, device, or message activity instead of relying only on static rules. In practice, it helps reduce false positives by weighting context, sequence, and deviation from normal behaviour. That is useful when analysts are drowning in repetitive alerts, but it still depends on good baselines and well-governed thresholds. If the model is tuned too broadly, it can hide meaningful anomalies; if tuned too tightly, it recreates the same overload it was meant to fix.

Practical implication: calibrate behavioural detection thresholds against real analyst workload, not just model accuracy.

Automation in SOC response and access decisions

Automation in defensive security is about taking predefined actions when a condition is met, such as enriching an alert, opening a ticket, or isolating a suspicious account. That is different from autonomous behaviour because the sequence is scripted and the decision boundary is defined in advance. For identity and access teams, the key issue is whether automated response can safely touch entitlements, sessions, or credentials without bypassing human review where it still matters.

Practical implication: scope automation to narrow, reversible actions and reserve human approval for access-changing responses.

Why generative AI changes the attacker-defender balance

Generative AI lowers the cost of producing convincing lures, adapting language, and iterating attack content at scale. GANs can also be used to synthesise or refine content that helps attackers evade simple detection patterns. The technical consequence is that defenders can no longer assume that poor grammar, repetitive templates, or obvious artefacts will expose malicious activity. Security programmes need controls that evaluate behaviour, provenance, and escalation patterns rather than surface quality alone.

Practical implication: reinforce detection logic with behavioural and provenance signals instead of relying on content quality cues.


NHI Mgmt Group analysis

Alert overload is now an identity governance problem, not just a SOC problem. When analysts cannot process volume, the control failure is not only missed detections but delayed identity and access decisions. That affects account lockdowns, privilege reviews, and escalation paths across the broader security programme. The implication is that AI value must be measured by whether it improves decision quality, not whether it simply reduces queue length.

Behavioural AI is most useful when it changes triage, not when it replaces judgement. The article points to measurable gains from AI-assisted detection and response, but the governance test is whether teams can explain why an alert was prioritised or suppressed. That requires clear policy, reviewability, and ownership. If AI output cannot be audited by humans, it becomes another source of blind trust rather than a control.

Human-centred AI reflects a broader shift toward decision support for overstretched practitioners. Security leaders are trying to absorb more volume without adding more fatigue, and that is where augmentation matters most. The strongest programmes will use AI to compress noise and preserve analyst attention for higher-risk decisions. The practitioner conclusion is simple: use AI to protect judgement, not to obscure it.

Defensive AI is exposing the difference between automation and autonomy. The article discusses AI that helps defenders respond faster, but the underlying governance assumption remains that humans can still review and own high-impact actions. That assumption fails if AI is allowed to move from recommendation into unsupervised response. Practitioners need to preserve that boundary, because speed without accountability is just accelerated drift.

Identity blast radius is the right way to think about AI-enabled security operations. As defensive AI spreads across alerting, enrichment, and response, the question becomes how far one misclassification can travel before a human catches it. That is a governance issue across IAM, PAM, and SOC workflows. Teams should treat AI-enabled decisions as bounded by blast radius, with explicit limits on what can be changed automatically.

What this signals

Defensive AI will matter most where it reduces analyst fatigue without eroding governance. Security programmes should treat every AI-assisted triage decision as a control point, not a convenience layer, because the real risk is that speed masks poor accountability.

The practical boundary is between assistance and authority. Once AI is allowed to shape containment, access, or escalation without a human checkpoint, the organisation has moved from decision support into delegated security execution.


For practitioners

  • Define AI response boundaries Document which alert types can be enriched, suppressed, escalated, or auto-closed by AI, and require human approval for any step that changes access, privileges, or containment state.
  • Measure analyst fatigue reduction Track whether AI-assisted triage reduces repetitive alert handling, time-to-decision, and missed escalations, rather than relying on model performance metrics alone.
  • Separate automation from autonomy Inventory where defensive AI makes recommendations versus where it can act directly, then remove approval-free paths for high-impact decisions.
  • Harden detection against synthetic content Tune controls to look for behavioural anomalies, provenance gaps, and escalation patterns so generative AI and GAN-driven attacks do not pass through content-based heuristics.

Key takeaways

  • Defensive AI is being used to absorb alert volume, but the core governance question is whether it strengthens human judgement or merely hides operational strain.
  • Attackers using generative AI and GANs reduce the value of surface-level detection cues, which pushes defenders toward behavioural and provenance-based controls.
  • Teams should define where AI can assist, where it can act, and where human approval remains mandatory before automation starts changing access or response state.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAI-assisted security operations can mis-handle identity and privilege decisions if autonomy expands.
Recommendation — Limit AI-driven security actions that can alter identity, privilege, or containment without human approval.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about governing defensive AI use in security operations and preserving accountability.
Recommendation — Establish governance for AI-assisted triage, escalation, and response ownership.
NIST CSF 2.0GV.OC-01 — Organizational ContextSecurity teams need to align AI adoption with business risk, operational load, and response expectations.
PR.DS-10 — Resilience and RecoveryDefensive AI is positioned as a response-scale and fatigue-reduction control in high-volume operations.
Recommendation — Align AI-enabled security operations to organisational risk tolerance and response objectives. Use AI to sustain detection and response capacity during high-alert periods.
CIS Controls v8CIS-5 — Account ManagementAlert overload and AI-assisted response affect account actions, escalation, and identity decisions.
Recommendation — Tie AI-driven alerts to accountable account management workflows.

Key terms

  • Defensive AI: AI used to help security teams detect, prioritise, or investigate threats more quickly. In practice, it is useful when it reduces analyst time to decision by correlating behaviour across email, identity, and endpoint data, rather than acting as a standalone security control.
  • Alert Overload: Alert overload occurs when a security team receives more alerts than it can realistically investigate within required timeframes. The condition creates backlog, missed alerts, and inconsistent triage quality. It is often a capacity problem as much as a tooling problem, because the volume of telemetry outpaces available analyst time.
  • Behavioral AI: Behavioral AI is an analytics approach that looks for meaningful deviations in activity patterns rather than relying only on static indicators or signatures. In identity and security operations, it is used to identify suspicious sequences, unusual timing, and context shifts that suggest an attacker is adapting faster than conventional controls.
  • Human-centered AI: Human-centered AI is an operating approach in which the person remains responsible for the decision and the machine provides context, prioritisation, or recommendation. The goal is not to replace judgement, but to make security decisions more consistent, traceable, and defensible.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org