
Artificial intelligence is changing the economics of cybersecurity. Attackers can increasingly use automation to accelerate reconnaissance, vulnerability discovery, and exploitation, while defenders have sophisticated tools for detecting and prioritizing risk. Yet the more worrisome divide is between operations capable of acting at machine speed and those still constrained by human-speed processes.
Recent research illustrates that imbalance: 63% of CISOs believe attackers currently hold the advantage given current levels of AI adoption and advancement, while only 18% believe defenders are ahead. Although 89% say their organizations are at least somewhat prepared for AI-accelerated vulnerability exploitation, just 28% describe themselves as very prepared. The gap points to an operating-model problem: machines can identify risk at speed, but organizations still struggle to act at the same pace.
The bottleneck has moved from finding risk to fixing it
For years, the security industry has invested heavily in improving visibility, and significant parts of vulnerability management can now be automated – from asset discovery to prioritization. Execution, however, remains far more dependent on people.
Sixty-five percent of organizations still perform at least half of their vulnerability and exposure management manually, while only 6% describe their approach as primarily machine-led. The consequences are significant: 60% take more than seven days to remediate a critical vulnerability, and nearly half say at least a quarter of known vulnerabilities remain unremediated for more than 30 days.
Vulnerability volume also continues to grow: 48,185 new CVEs were published in 2025, an average of 132 per day, according to the National Vulnerability Database. A vulnerability can be discovered and prioritized automatically, only to enter a remediation process requiring people to review it, approve a change, coordinate with another team, and execute the fix.
As adversaries accelerate their operations, that human hand-off increasingly determines how long an organization remains exposed. It also takes a toll on defenders: 77% of CISOs surveyed said vulnerability and exposure management contributes at least moderately to team burnout. Simply adding more tools and analysts won’t solve the problem when the workload is growing faster than teams can handle it.
Security automation is moving from recommending action to taking it
This pressure is pushing cybersecurity toward a different model of automation. Historically, security technologies have helped people make decisions: detect an issue, calculate risk, recommend a priority, or create a ticket, then leave a human responsible for what happens next. Increasingly, the question is whether machines should also execute well-understood actions.
Among organizations surveyed, 55% allow automated asset discovery and inventory without human approval, 49% allow automated vulnerability prioritization, and 32% allow automated remediation. That last figure represents an important threshold: automation is moving from identifying what should change to changing the environment itself.
The direction is clear. Forty-five percent of CISOs expect vulnerability and exposure management to become mostly or primarily machine-led within 12 to 18 months. This does not remove security professionals from the process; it shifts their role toward defining policy, establishing boundaries, investigating exceptions, and supervising machine-led systems.
Trust, not technology, will determine how quickly that transition happens
The hardest part of this transition is creating the conditions under which organizations will let autonomous systems act. Fifty-two percent of CISOs cite a lack of trust in automated decisions as an obstacle to greater automation, while 43% point to governance or compliance concerns. Only 21% cite budget constraints.
That makes autonomy a governance problem as much as a technology problem. Security teams need to understand why an automated decision was made, what it will affect, who is accountable, and whether the action can be audited or reversed.
In fact 52% say auditability and explainability would increase their confidence in machine-led remediation, while 51% point to vendor accountability and liability protections. Governance is already adapting, with 81% describing their frameworks as human-led but being modified for greater machine-led operations. The objective should therefore not be autonomy at any cost, but proportional autonomy: allowing machines to act where evidence is strong, impact is understood, and controls are mature, while escalating uncertainty and higher-consequence decisions to people.
Closing the gap between intelligence and action
AI is intensifying a longstanding cybersecurity problem: organizations increasingly have more information about risk than capacity to act upon it. Adding AI to existing processes will not solve that imbalance if every machine-generated recommendation ultimately joins another human queue.
The next phase of cyber defense will depend on closing the gap between intelligence and action, combining machine-speed execution with human governance. Machines can handle repeatable, well-understood work within defined boundaries while people retain responsibility for policy, exceptions, oversight, and judgment.
The organizations that make that transition successfully will need to establish the trust, accountability, and control to automate responsibly. For security leaders, the question is shifting from whether they trust AI to identify cyber risk to whether they can build the operating model required to let it act.



