TL;DR: In an Innovate 2025 on-demand session, Lamont Orange and Dan Shiebler discuss how security leaders can distinguish genuine AI capability from marketing claims, and why measurable operational impact matters more than labels in modern threat defence, according to Abnormal AI. The governance test is whether AI changes security decisions, response quality, and resilience rather than simply adding automation.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Opening the AI Black Box: Best Practices for Utilizing AI in Cybersecurity”.
Key questions
Q: How should security teams evaluate whether an AI security tool is real or just marketing?
A: Security teams should ask whether the tool changes measurable outcomes such as detection quality, triage speed, or decision accuracy.
Q: When should organisations trust AI-enabled security controls?
A: They should trust them only when the system’s learning behaviour, input data, error handling, and human oversight are clear and measurable.
Practitioner guidance
- Define an AI impact threshold Set a minimum evidence standard for any AI-enabled security control, including the operational metric it must improve and the baseline it must beat.
- Map AI claims to security outcomes Require each claimed AI capability to map to a specific outcome such as detection quality, response speed, analyst load, or triage precision.
- Separate automation from adaptive behaviour Review whether the control is following fixed rules or actually changing behaviour based on context, patterns, or learned signals.
Bottom line: The central issue is not whether a security tool uses AI language, but whether it changes operational outcomes in ways teams can measure.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
True AI in security is defined by outcome change, not label change. A product earns analytical weight when it alters detection quality, decision quality, or response quality in measurable ways. That distinction matters because cybersecurity is crowded with rule-based automation presented as intelligence. Security leaders should treat AI as a control-efficacy question, not a branding category.
A question worth separating out:
Q: How should security teams evaluate AI features in identity platforms?
A: They should ask whether the AI feature changes an actual control decision, such as access approval, step-up authentication, or session termination. If it only produces a score or recommendation, it supports analysis but does not improve governance by itself. The value appears when AI is tied to an enforceable workflow and measurable risk reduction.
👉 Read our full editorial: True AI in cybersecurity: separating impact from marketing hype