TL;DR: Research with 125 security and AI leaders by Osterman Research shows defenders are already using behavioural AI and automation to reduce fatigue, improve accuracy, and respond at scale while attackers use generative AI and GANs to press offensive advantages, according to Abnormal AI. The shift is less about tool adoption and more about whether security programmes can absorb AI without creating new governance blind spots.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Using AI to Enhance Defensive Cybersecurity”.
Key questions
Q: How should security teams use AI triage without creating a false sense of accuracy?
A: AI triage should be used as a decision filter, not as an oracle.
Q: Why does alert overload increase the risk of missed identity compromise?
A: Alert overload forces analysts to sample rather than fully investigate, which means identity abuse can hide inside a backlog until the attacker has already moved beyond the initial foothold.
Practitioner guidance
- Define AI response boundaries Document which alert types can be enriched, suppressed, escalated, or auto-closed by AI, and require human approval for any step that changes access, privileges, or containment state.
- Measure analyst fatigue reduction Track whether AI-assisted triage reduces repetitive alert handling, time-to-decision, and missed escalations, rather than relying on model performance metrics alone.
- Separate automation from autonomy Inventory where defensive AI makes recommendations versus where it can act directly, then remove approval-free paths for high-impact decisions.
Bottom line: Defensive AI is being used to absorb alert volume, but the core governance question is whether it strengthens human judgement or merely hides operational strain.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Alert overload is now an identity governance problem, not just a SOC problem. When analysts cannot process volume, the control failure is not only missed detections but delayed identity and access decisions. That affects account lockdowns, privilege reviews, and escalation paths across the broader security programme. The implication is that AI value must be measured by whether it improves decision quality, not whether it simply reduces queue length.
A question worth separating out:
Q: What should organisations do when generative AI makes attacks harder to spot by content alone?
A: Move detection away from surface cues and toward behaviour, provenance, and response context. Security teams should assume that wording, formatting, and other superficial indicators can be synthetic, so controls need stronger signals about who acted, what changed, and whether the pattern fits expected activity.
👉 Read our full editorial: Defensive AI is changing how security teams handle alert overload