The conversation about artificial intelligence in cybersecurity can easily swing between two extremes.

At one end, AI appears capable of automating almost any task and replacing much of human work. At the other, it is dismissed as an overhyped technology that adds noise and risk.

Neither extreme is particularly useful to me.

I prefer a more concrete question:

Where in a security workflow can AI improve a decision, reduce friction, or add context without degrading control or judgment?

That question changes the conversation considerably.

AI does not need to be the center of the process

One of the most common mistakes when exploring AI is starting with the technology and then looking for a problem to attach it to.

In cybersecurity, that can be especially costly because many processes already have clear constraints: confidentiality, traceability, data quality, response time, accountability for decisions, and the need to understand why an action was taken.

That is why I find it more useful to begin with the workflow.

Where does a person lose time? Where is context missing? Where is interpretation repeated? Where is information spread across several tools? Where does a response take too long because someone first has to translate technical data before a decision can be made?

Those are places where AI may start to make sense.

Interpret information before automating actions

In many security operations, the first useful contribution is not automating the final decision but improving understanding.

A tool may generate findings, events, configurations, or technical results. The challenge is not always obtaining more data; often it is understanding what that data means within a specific environment.

AI can help:

  • summarize lengthy technical information;
  • relate findings to known context;
  • turn technical data into explanations for different audiences;
  • identify questions that should be asked before a decision;
  • support the documentation of analysis and decisions;
  • reduce repetitive manual work in preparation tasks.

In these cases, AI acts as a support layer. It does not have to become the authority that decides.

Speed without judgment can make the problem worse

Automating a bad decision only allows it to be executed faster.

If input data is incomplete, context is poor, or there is no clear rule for when a person must intervene, speed can amplify mistakes.

That is why serious uses of AI in security should answer questions such as:

  • what information can it access?;
  • what information should not leave a particular environment?;
  • which actions can it suggest and which can it execute?;
  • what evidence is recorded?;
  • how is an answer validated before it is used?;
  • who retains responsibility for the decision?

These questions are not barriers to innovation. They are part of the design.

Some tasks still need a human control point

A recommendation can be technically reasonable and still be inappropriate for a specific organization.

There may be an operating window, a business dependency, a contractual condition, a secondary risk, or another constraint that the model does not know.

Professional judgment appears precisely in that space: understanding incomplete information, recognizing constraints, and deciding which trade-off makes sense.

That is why I am more interested in AI that amplifies judgment than AI that tries to replace it.

Value can come from small improvements

Not every use case needs a complex platform or a high degree of autonomy.

Sometimes the most useful outcome is simpler:

  • reducing the time required to prepare an analysis;
  • improving the quality of an explanation;
  • querying distributed information more naturally;
  • preparing a first draft of documentation;
  • helping compare options before a decision;
  • identifying inconsistencies or gaps that a person should review.

These changes may look modest, but when they occur inside frequent tasks they can significantly improve the way people work.

The question that matters most to me

When I evaluate applied AI for cybersecurity, I am not especially interested in whether an implementation looks sophisticated.

I want to know whether it leaves the process in a better state.

Does the person understand more? Make better decisions? Spend less time on friction? Have more context? Can they explain what happened? Do they retain control over data and actions?

If the answer is yes, there is probably real value.

If the main improvement is that we can now say we use AI, we probably have not found the right problem yet.

For me, the opportunity is to connect AI with concrete security needs: interpret better, decide with more context, reduce friction, and automate only what can truly be automated without sacrificing control.