When generative AI exploded into the mainstream, cybersecurity found itself caught between excitement and anxiety. AI promised to help security teams move faster, uncover more threats and automate repetitive work. At the same time, it gave attackers new ways to scale phishing, discover vulnerabilities and exploit systems at unprecedented speed.
A few years later, the conversation has become far more grounded. AI is no longer viewed as either a silver bullet or an existential threat. Instead, security leaders are learning where it genuinely adds value and where human judgment, governance and operational discipline remain irreplaceable.
That may be the biggest reason to appreciate AI this year.
AI is accelerating both sides of the cybersecurity battle
Few technologies have compressed the pace of cybersecurity like AI. Security teams can analyze more data, uncover vulnerabilities faster and respond more quickly than ever before. Unfortunately, attackers are benefiting from the same capabilities.
As Dhruv Majumdar, VP of Security Solutions at Fleet Device Management, explains, AI is dramatically shortening the gap between discovering a vulnerability and seeing it weaponized.
“AI is helping security researchers uncover vulnerabilities faster than ever before, but it’s also accelerating the speed at which those same weaknesses can be exploited, from days to hours.”
That changing reality makes AI-assisted and eventually autonomous patching inevitable. But Majumdar argues that automation alone isn’t enough. Autonomous systems must understand business context as well as technical risk. A patch shouldn’t reboot a trader’s workstation during a billion-dollar transaction or disconnect a CEO from an important board meeting simply because an update became available. The organizations that combine AI-driven speed with intelligent operational guardrails will ultimately have the advantage.
The cybersecurity workforce is changing
One of the most persistent misconceptions surrounding AI is that it will replace cybersecurity professionals. In reality, it’s changing what expertise looks like.
Laurent Halimi, CEO and founder of Cyberr, believes AI knowledge is rapidly becoming as fundamental as traditional cybersecurity skills. Understanding prompt engineering, LLM risks and the ways attackers weaponize AI is quickly becoming part of the baseline skillset, even for entry-level security practitioners.
“Cybersecurity professionals who invest in AI skills today will likely be the ones leading security teams tomorrow.”
Rather than eliminating jobs, AI is creating new specializations and raising expectations across the industry. The next generation of security leaders will likely be those who combine strong security fundamentals with practical AI expertise.
AI still needs experienced humans
For all of AI’s capabilities, cybersecurity continues to demonstrate that context matters.
According to Gunter Ollmann, CTO at Cobalt, organizations are becoming more realistic about where automation succeeds and where it doesn’t. Cobalt’s research found that 78% of security teams have seen automated scanning tools miss critical vulnerabilities, while support for fully automated pentesting has fallen to just 9%.
Those findings reinforce an important lesson: AI excels at scale, repetitive analysis and identifying patterns, but human researchers remain essential for uncovering business logic flaws, behavioral weaknesses and complex attack paths that require judgment rather than pattern matching.
As organizations increasingly deploy AI applications themselves, that balance between intelligent tooling and expert adversarial testing will become even more important.
Identity isn’t just for humans anymore
As enterprises deploy AI agents capable of making decisions and interacting with sensitive systems, identity management is entering unfamiliar territory.
According to Bojan Simic, CEO and co-founder of HYPR, organizations need to apply the same identity principles they’ve developed for people to non-human actors.
“If you can’t answer exactly who an agent is acting on behalf of, what its boundaries are, and how to stop it in real time, you don’t have a policy.”
That means every AI agent should have verifiable ownership, clearly defined permissions and real-time oversight that allows humans to intervene immediately if an agent behaves unexpectedly. Governing non-human identities may become one of the defining security challenges of the AI era.
Organizations need to prepare for AI failures
Much of the industry’s focus has centered on AI governance, but governance alone won’t prevent incidents.
Models hallucinate. Agents make unintended decisions. Sensitive information leaks.
As AI becomes embedded across customer service, finance, software development and healthcare, those failures increasingly resemble operational crises rather than isolated technology issues.
Arvind Parthasarathi, CEO and founder of CYGNVS, points to Gartner research showing that both sanctioned and unsanctioned AI agents are already widespread inside enterprises, while the OECD AI Incidents and Hazards Monitor recorded hundreds of AI-related incidents in a single month.
“When an AI agent misbehaves, organizations need to activate a cross-functional machinery spanning IT, security, legal, executives, as well as external providers like law firms.”
Preparing for AI incidents may soon become just as important as defending against ransomware.
Better AI begins with better data
While attention often focuses on increasingly powerful models, Amit Shuster, VP of Product and Engineering at Vetric, argues that data deserves far more recognition.
“The real workhorse of the AI era is the data underneath it.”
Attackers are already using AI to automate fraud, impersonate executives and scale cybercrime. Defenders can only keep pace if their own AI systems have access to richer, broader and more timely data than the attackers they’re trying to stop.
AI is finally giving security tools context
Traditional security products have spent decades relying on rules, signatures and pattern matching. They could detect activity, but rarely understood whether it actually mattered.
Roi Vanunu, Director of Product Management at Jazz, believes AI fundamentally changes that equation.
For years, legacy data loss prevention tools struggled because they lacked business context. They could identify that data had moved but couldn’t understand whether the action was legitimate or risky. AI now makes it possible to evaluate intent, user behavior and business context at a scale humans alone could never achieve.
“For the first time, it’s possible to build security tools that don’t just detect—they understand.”
Appreciating AI also means understanding its limits
Perhaps the healthiest perspective comes from Corey Thuen, CEO and co-founder of Gravwell, who argues that AI’s greatest misconception is that it somehow changed how computers think.
It didn’t.
Instead, AI changed how humans interact with computers. That distinction matters because attackers are now “social engineering computers” through prompt injection rather than simply social engineering people.
AI deserves enormous credit for helping researchers uncover vulnerabilities at scale, Thuen says, but organizations shouldn’t mistake fluent language for genuine reasoning. AI predicts text exceptionally well, yet it still lacks the situational understanding needed to distinguish between a legitimate instruction and a cleverly crafted malicious one.
As AI becomes embedded across every aspect of enterprise security, organizations must understand both its extraordinary capabilities and its very human limitations. Learning how to achieve that balance together is worth celebrating.

