Tom Findling
Opinion

Cybersecurity may be first enterprise function to move from copilots to autonomous AI

"Accelerating threats are making that shift necessary," writes Tom Findling, co-founder and CEO of Conifers, "with humans setting the boundaries."

For most of the enterprise, AI is still being built as a copilot: a smarter assistant that helps people work faster while humans remain firmly in control. Cybersecurity may be one of the first places where that model changes.
We are already seeing the beginnings of that transition in production. Large enterprises that initially insisted on keeping a human directly in the loop are seeing AI agents successfully take on meaningful parts of security operations that previously required significant human effort. As these systems prove themselves, organizations are becoming more comfortable expanding their autonomy, with humans moving from approving every decision to supervising the system, defining its boundaries and stepping in when needed.
1 View gallery
Tom Findling
Tom Findling
Tom Findling
(Roei Shor)
The technology is still young, but it has matured remarkably quickly. Security teams are already using it to scale their operations, move faster and shift more operational work to AI, while keeping people focused on areas where human judgment and context matter most. That makes the move toward autonomy much less theoretical than it was even a year ago.
Cybersecurity also has little choice but to move quickly. AI is changing the scale and economics of cyberattacks, allowing agents to chain familiar techniques together, operate in parallel and execute complex, multi-stage attacks with limited human involvement. And the risk is not limited to malicious actors. Recent incidents at leading AI labs have shown that powerful agents pursuing poorly constrained goals can create real security incidents without malicious intent. The common challenge is speed and scale: agents can now act, adapt and execute faster than humans can investigate and respond.
Human-speed defense is becoming a fundamental limitation in an agent-driven world.
That matters far beyond the security industry. Cybersecurity protects businesses, financial systems, healthcare, critical infrastructure and governments. If the ability to create and execute attacks scales faster than our ability to defend against them, the consequences become an economic resilience and national security problem.
Fortunately, security is unusually well positioned for this transition. Decades of investment have created enormous amounts of telemetry, threat intelligence, automation and connectivity across security systems. Cybersecurity also attracts significant technical talent and capital, and security teams have historically been aggressive adopters of technologies that can materially improve their defenses.
But autonomy cannot simply mean investigating alerts faster. The bigger opportunity is to bring the different parts of security operations together into a unified operational fabric that can continuously understand the threat landscape, recognize which threats actually matter to an organization, identify weaknesses in its defenses and adapt as conditions change.
That moves security from being primarily reactive toward becoming more proactive and resilient. Instead of waiting for something to happen and then beginning an investigation, AI can continuously look for threats, learn from what it finds and help defenses adapt before the next attack arrives. And it has to end with action.
An AI system that detects or investigates an attack in minutes but then waits hours for people to decide what to do has solved only part of the problem. As attacks accelerate, containment, remediation and mitigation have to accelerate with them.
Machine-speed detection without machine-speed containment still leaves a human-speed gap.
The goal is therefore not simply autonomous investigation. It is a security operation capable of connecting understanding with action: identifying what matters, investigating it, adapting defenses and, when appropriate, containing or remediating the threat before it becomes a larger incident.
That does not mean removing humans from cybersecurity.
Autonomy has levels. Some decisions will remain human-in-the-loop. Others can become human-on-the-loop, with AI operating while people supervise. And certain high-confidence actions can increasingly happen autonomously within clearly defined permissions and guardrails. I think of it as AI moving into the driver’s seat while the human moves into the passenger seat.
People still determine where the system is going. They provide context, establish objectives and boundaries, control permissions, challenge decisions and handle exceptions and escalations. As the technology becomes more capable, strong governance and guardrails become more important, not less. The analyst’s role changes with it. Instead of manually executing every investigation and workflow, security professionals increasingly operate the defense itself: supervising it, improving it, providing context and determining where autonomy should expand or where human judgment remains necessary.
The initial vision for enterprise AI was largely built around the copilot: AI assisting people while humans remained firmly in control. Cybersecurity may point toward a different destination. In some enterprise functions, AI may not remain an assistant sitting beside the human. It may become the frontline operator, working continuously and at machine speed, while humans provide the judgment, context and control around it.
Cybersecurity may simply be the first place where that transition becomes unavoidable.
Tom Findling is co-founder and CEO of Conifers.