In the News

AI in Security Always Has an Answer. That’s Exactly the Problem.

by Dan Pagel, CEO & Board Director//9 min read/

Published in US Cybersecurity MagazinePublished in US Cybersecurity Magazine

At some point in the last year, most security leaders have sat in a room where AI surfaced a recommendation that felt off. Not wrong, exactly, just incomplete. The data behind it was real, the picture behind the data wasn't.

Despite all of its advancements, it will produce an answer based on the data it has been fed, regardless of whether that picture is complete.

That gap is familiar to anyone who’s made a hard call under pressure. When a piece of the picture is missing, good practitioners say so; they slow down, ask the question, validate the assumption. That friction is part of how sound decisions get made.

AI doesn’t work the same way. Despite all of its advancements, it will produce an answer based on the data it has been fed, regardless of whether that picture is complete. It doesn’t pause. It doesn’t qualify. It just answers.

Security AI is largely operating this way today. While its outputs aren’t necessarily wrong, without visibility across an organization’s full environment, the quality of its decisions can deteriorate and trust in the security program along with it. Organizations that want to change that need to start with a robust, unified data foundation, with embedded governance and explainability, before they ask AI to do anything more.

VOLUME IS NOT THE PROBLEM. COMPLETENESS IS.

Large enterprises routinely process hundreds to millions of findings every day. The hard part is sifting through those signals to determine what will cause the most risk. And for that, connection is key.

Last year, 31% of breaches began from vulnerability exploitation, a 7% uptick from the previous year. And in 2025, roughly 1 to 3 percent of published CVEs were exploited in the wild, but the timeline between disclosure and weaponization keeps shrinking. This is especially true with the recent introductions of Claude Mythos and ChatGPT 5.5. AI is lowering the barrier to exploitation, while increasing the speed at which attackers can test and operationalize new techniques. What once took nefarious actors weeks increasingly happens in days.

That means security teams are under pressure to prioritize faster – and better – while working from environments that are often incomplete or inconsistent underneath the surface. A vulnerability may look critical in one organization and largely irrelevant in another.

9/17/26, 2:19 PM AI in Security Always Has an Answer. That's Exactly the Problem. - United States Cybersecurity Magazine https://www.uscybersecurity.net/csmag/ai-in-security-always-has-an-answer-thats-exactly-the-problem/ 2/8

The answer changes depending on reachability, compensating controls, business criticality, identity exposure, network paths, and whether an asset connects to something attackers actually care about.

The CVE itself is only part of the story. With disconnected data, a platform can still generate a recommendation. It just won’t be the right one for your business.

THE GOAL HAS ALWAYS BEEN THE SAME. THE EXECUTION CAPACITY HAS CHANGED.

Whether you call it RBVM, CTEM, or exposure management, this critical security category is evolving, but the underlying objective remains the same. Security teams want to identify the exposures most likely to create real risk inside their critical environments and address those first. What limited progress historically was not intent. It was execution capacity.

Most programs compensated by operating at broad scale, closing as many findings as possible, reducing backlog, and assuming they would catch the most exploitable vulnerabilities in the process. Given the available tooling at the time, that approach made sense.

But AI has changed the equation. Organizations can now correlate far more data than before, enriching findings with environmental relationships, attack chain analysis, real-time threat intelligence, reachability modeling, and organization-specific context at enterprise scale.

That correlation can only fuel a strong exposure management program if the underlying picture is reasonably complete. AI amplifies whatever foundation already exists underneath it. So before asking it to do more, organizations need to make sure what it’s working from is actually worth amplifying.

THE RISK CHANGES ONCE AGENTS START ACTING

A human analyst working with incomplete information will usually slow down, ask questions, and validate assumptions before acting.

Conversation becomes more serious when we consider moving AI from making recommendations with a human in the loop to autonomous execution. This is where bad data stops being an inconvenience and becomes an operational risk.

A human analyst working with incomplete information will usually slow down, ask questions, and validate assumptions before acting. AI agents don’t naturally introduce that friction. They keep operating against whatever they were given. That compounds quickly. A finding that should have been treated as critical gets deprioritized. A remediation ticket lands with the wrong team while the exposure window stays open. A compensating control gets evaluated without anyone knowing it was already bypassed. By the time someone realizes the underlying picture was incomplete, the downstream actions may already be difficult to unwind.

Over time, those breakdowns erode trust between security and infrastructure teams. And once trust deteriorates, remediation velocity slows regardless of how capable the AI appears on paper. The decisions need to be sound and explainable from the start, not retrofitted after something goes wrong.

Autonomous systems have a place in security operations. But earning the right to use themstarts well before the first agent is deployed.

START WITH THE OPERATIONAL BOTTLENECKS

One of the most practical uses for agentic AI today is removing the clerical friction surrounding remediation. Most enterprises still spend enormous amounts of time answering operational questions before anything even gets fixed. Who owns the asset? Are multiple tools reporting the same issue differently? Which team should receive the work?Does the routing logic reflect how the organization actually operates?

The problems are difficult precisely because enterprise environments are messy. CMDBs are incomplete, asset tagging becomes inconsistent, tools overlap, and infrastructure changes faster than governance processes can keep up. Many fixes should be owned byITOPS or application teams rather than security.

This is where AI can deliver immediate value without unnecessary risk. Inferring asset ownership patterns, deduplicating findings across scanners, routing work accurately. These are areas where agents can improve remediation velocity in measurable ways. And when agents do these things well, it builds the foundation to extend autonomy further. Trust gets earned incrementally, not granted upfront.

EXPLAINABILITY IS A GOVERNANCE ISSUE

Security leaders are already seeing broader governance discussions emerge around AI accountability, particularly in heavily regulated industries like healthcare and financial services. The same pressure is moving toward cybersecurity programs. Leadership teams increasingly want to understand how AI-driven decisions are being made and whether the underlying reasoning can be defended during an incident review or audit.

Explainability is therefore key to scaling AI decisions that security teams can actually stand behind. If practitioners can understand why something was prioritized, what data and relationships led to a decision, they will trust it. As these workflows scale, that visibility must be maintained or confidence will contract quickly.

The transition won’t be driven by model capability. It will be driven by whether teams believe the system understands enough of the environment to act responsibly.

THE FOUNDATION MATTERS MORE THAN THE SPEED

Faster answers don’t automatically create better outcomes. In some cases, they simply accelerate bad assumptions at scale. The organizations making the most progress right now are not treating AI as an add-on tool. They are focusing first on the quality, correlation, and completeness of the data foundation that powers it. From there, autonomy becomes easier to extend responsibly and organizations can start tackling vulnerabilities with theprecision and speed the threat environment actually demands.

D
Dan Pagel
Chief Executive Officer & Board Director
Dan Pagel leads Brinqa with a focused mission: empowering enterprises to align technology with business risk and protect what matters most. With over 15 years of leadership experience in cybersecurity and enterprise software, Dan has a proven track record of building customer-centric organizations, fostering innovation, and driving growth.
See all of Dan's postsArrow Right

Ready to Unify Your Cyber Risk Lifecycle?

Get a DemoArrow RightGet a DemoArrow Right