Walk the floor at any major security conference and you will see the same word on almost every booth: AI. It is on the banners, the datasheets, the pitches, and the keynote slides, repeated so often and so confidently that it has started to lose meaning. Every vendor has it, which raises an obvious question: if everyone has AI, why are security teams still losing?
The answer is that most of what gets sold as AI is not AI in any meaningful sense, but merely automation with better branding.
A marketing label masquerading as a capability
“AI-powered” has become the security industry’s version of “new and improved”, a modifier that signals modernity without committing to anything specific. For years, the dominant pattern has been to take isolated, repetitive SOC tasks, script them, and ship the result as an AI product. The toil goes down slightly, the press release goes out, while the fundamental problem stays exactly where it was: security teams are still overwhelmed, attackers are still faster, and the gap between the two continues to widen.
The threat landscape is accelerating at a pace that legacy tools were simply not built for. According to Arctic Wolf’s 2026 Threat Report, average losses per large-enterprise incident in Asia Pacific and Japan reached approximately AUD $202,700, with attackers increasingly cycling through smaller firms and service providers before working up the supply chain.
AI-driven attacks are compressing the window between initial compromise and impact, turning what used to take days into hours, and what used to take hours into minutes. Security teams are being asked to respond at machine speed with tools built for a different era, and the strain is already starting to show.
The trust problem nobody wants to talk about
Despite years of vendor promises, only 30% of cybersecurity teams have successfully integrated AI into their operations, according to a survey by ISC2. Recently, Gartner also placed AI SOC agent market penetration at somewhere between 1% and 5%. Those numbers points to a fact the industry rarely acknowledges openly: buyers are skeptical (for a good reason).
An AI agent that hallucinates, guesses, or surfaces unvalidated outputs in a security context is both unhelpful and actively dangerous. Security analysts already work under significant cognitive load, making high-stakes decisions with incomplete information and tight time pressure, and feeding them unreliable AI outputs at exactly that moment does not assist the analyst so much as it misleads them.
The pressure this creates on people compounds an already serious problem. AI-driven attacks are placing even more burden on teams that are already stretched thin and underfunded, accelerating the burnout and turnover that the industry has struggled to address for years. The expectation that teams will simply absorb faster, more sophisticated threats without better tooling is not so much a strategy as it is wishful thinking.
What “AI-powered” should actually mean
The industry needs to move past the label and start demanding specificity. What does the AI actually do? What happens when it encounters something outside its training, and how does it handle uncertainty? Is a human in the loop, and if so, at what point does the handoff happen? These are not unreasonable questions; in fact, they should be the baseline for any tool that claims to support decision-making in a high-stakes environment.
Rather than optimising purely for speed or automation breadth, we need a solution built around a deterministic architecture where AI agents are constrained to validated, known outcomes, and anything that falls outside that boundary is handed off to a human analyst rather than guessed at.
The bar for AI in security should not be “it automates some things.” It should be “it reliably makes analysts faster and more effective without introducing new failure modes.” Until vendors are held to that standard, “AI-powered” will remain what it largely is today: a label attached to products that deliver incremental efficiency gains while the real capability gap goes unaddressed.
The threat is real, moving fast, and increasingly automated, which means the response needs to be too. But speed without reliability is its own kind of risk, and the industry owes security teams something more rigorous than a booth banner and a promise.












