TL;DR: The global 4.8 million-role shortage can be offset by using AI agents to normalise logs, reduce false positives, accelerate investigations, and automate compliance evidence, turning repetitive work into managed machine support, according to Edge Delta. The governance question is no longer whether automation helps, but whether identity, auditability, and human approval boundaries are strict enough to trust it.
NHIMG editorial — based on content published by Edge Delta: how AI agents can multiply security team capacity without replacing people
By the numbers:
- The cybersecurity industry faces 4.8 million unfilled positions globally in 2025, according to Edge Delta.
- One financial services client went from spending 20 hours per week on log source management to zero, according to Edge Delta.
- Edge Delta says most organisations spend 60-70% of total security hours on mechanical work that can be automated.
Questions worth separating out
Q: How should security teams introduce defensive AI without losing control of security decisions?
A: Start by limiting AI to clearly scoped tasks such as enrichment, clustering, and recommendation, then keep humans responsible for any action that changes access, containment, or investigation outcomes.
Q: Why do AI agents create a governance problem for IAM teams?
A: AI agents create a governance problem because they authenticate and act as autonomous software entities with tool access.
Q: What breaks when security automation is built on poor data quality?
A: False positives, alert fatigue, and broken correlations quickly overwhelm analysts and undermine trust in the automation.
Practitioner guidance
- Implement read-only agent pilots first Start with log analysis, evidence collection, or alert summarisation before allowing any write or response capability.
- Define approval gates for agent actions Require human approval for any workflow that changes access, alters evidence, or touches privileged systems.
- Treat agent access as privileged workload access Assign scoped permissions, separate credentials, and audit logging to every agent that interacts with security tooling or data.
What's in the full article
Edge Delta's full analysis covers the operational detail this post intentionally leaves for the source:
- Step-by-step examples of where AI agents can take over ingestion, correlation, and documentation tasks without human bottlenecks.
- Implementation detail on phased rollout from read-only analysis to supervised recommendations and approval-gated action.
- Operational metrics and target thresholds for measuring false positive reduction, investigation efficiency, and compliance readiness.
- Practical examples of how teams can structure weekly and monthly reviews of agent behaviour and exceptions.
👉 Read Edge Delta's analysis of AI agents as force multipliers for security teams →
AI agents as force multipliers for security teams: what changes now?
Explore further
AI agents are becoming operational identities, not just productivity features. Once an AI agent can read logs, classify data, trigger workflows, or prepare evidence, it is participating in control processes that require identity boundaries. That makes governance, scope, and auditability first-order design issues, not implementation details. The practitioner conclusion is simple: if a system can act on security data, it must be governed like a privileged workload, not treated like a passive analytics feature.
A question worth separating out:
Q: Who is accountable when an AI agent makes the wrong change?
A: Accountability sits with the governance chain that approved the access model, not with the agent alone. Teams need a trace from requester to policy decision to identity issuance to action results. If that chain is missing, incident review becomes guesswork and access governance cannot be defended to auditors.
👉 Read our full editorial: AI agents can close the security capability gap without adding headcount