top of page

AI in information security isn't Replacing Human Expertise – It's Raising Its Value

Why Agentic AI is the next evolution of enterprise technology, and why human judgement has never been more important.


Artificial Intelligence and Agentic AI represent the next stage in a decades-long evolution of enterprise technology. Rather than replacing human expertise, AI is shifting professional value towards judgement, governance and decision-making. Organisations that combine AI with experienced human insight will consistently make better business decisions than those that rely on automation alone.


The headlines often ask whether AI will replace professionals. I believe that's the wrong question.


The better question is this: How does AI change where professionals create value?


From my perspective, every major technology evolution has followed the same pattern. It removes routine effort, increases consistency and allows experienced people to focus on higher-value work.


Agentic AI is no different.


Key takeaways

  • Agentic AI is the next logical step after cloud, automation and machine learning

  • AI increasingly automates reasoning, but not accountability or judgement

  • Human expertise becomes more valuable as AI raises the quality and consistency of baseline analysis

  • In information security, AI can identify risks and recommend controls, but experienced professionals must balance business risk, cost and benefit

  • Organisations with mature governance, good data quality and clear ownership will realise the greatest value from AI


Technology has always evolved towards higher-value work


Looking back over the past three decades, enterprise technology has evolved through a series of connected steps rather than isolated revolutions.

  • Cloud computing removed much of the complexity of managing physical infrastructure.

  • Automation eliminated repetitive manual tasks and improved consistency.

  • Orchestration connected automated processes into end-to-end workflows.

  • Machine learning enabled systems to identify patterns and make increasingly accurate predictions.

  • Generative AI transformed the way we analyse information and create knowledge.


Agentic AI is the latest stage of that journey. Rather than simply responding to prompts, AI agents can plan, coordinate and execute multiple tasks towards a defined objective.

  • Each wave has automated more work.

  • Each wave has increased productivity.

  • And each wave has increased the relative value of human judgement.


The technology changes.

The purpose does not.


The Four Levels of Professional Value

One way to understand this evolution is to think about four distinct levels of professional value.


Data

What happened?

Traditional reporting systems answered this question.


Information

Why did it happen?

Analytics platforms and business intelligence tools helped explain events.


Insight

What should I pay attention to?

Modern AI is exceptionally good at identifying trends, highlighting anomalies and surfacing opportunities.


Judgement

What should we actually do?

This is where experienced professionals remain indispensable.


Judgement requires context.


It requires understanding organisational culture, commercial priorities, stakeholder expectations, regulatory obligations and long-term strategy.


Most importantly, judgement requires accountability.

Reasoning can increasingly be automated.

Accountability cannot.


The Xero example

The accounting profession provides an excellent illustration. Modern accounting platforms can analyse historical transactions, identify spending trends and forecast future cash flow. Increasingly, AI can warn a business that it is likely to experience a cash flow shortfall weeks before it happens.


That insight is incredibly valuable.


But it isn't the solution.


The real value comes from the accountant or business adviser who understands the wider context and asks questions such as:

  • Should payment terms be renegotiated?

  • Would short-term finance be appropriate?

  • Should investment be delayed?

  • Are operational changes available that improve liquidity without harming growth?

  • What are the commercial and tax implications of each option?


The AI identifies the problem.

The adviser provides the judgement.

One without the other is incomplete.


AI in information security presents exactly the same opportunity

Information security is frequently portrayed as one of the professions most likely to be transformed by AI. I believe that's true - but not because AI replaces security professionals. It changes how they spend their time.


Today's AI systems can already:

  • Review cloud environments against recognised security benchmarks

  • Compare configurations with ISO 27001, NIST Cybersecurity Framework and CIS Benchmarks

  • Identify excessive permissions and configuration weaknesses

  • Detect inconsistencies across security controls

  • Generate draft risk assessments

  • Recommend remediation actions

  • Produce security documentation and evidence


Agentic AI will take this much further by continuously monitoring environments, correlating findings across multiple systems and proactively recommending improvements before formal reviews even begin. This raises the baseline for every organisation. But it doesn't eliminate the need for expertise.


Experienced security leaders still decide:

  • Which risks genuinely matter

  • Which recommendations justify investment

  • What level of residual risk is acceptable

  • When security should enable delivery rather than delay it

  • How to balance cyber risk against commercial opportunity

  • Whether a control is proportionate for the organisation


These are business decisions.

Not technical ones.

Technology can recommend.

People remain accountable.


AI raises the baseline - not the ceiling

One of the most exciting aspects of AI is its ability to democratise good practice.

Many organisations struggle to maintain consistent documentation, perform comprehensive risk assessments or implement recognised security frameworks because specialist expertise is expensive and often scarce.


AI changes that.

  • It can produce high-quality first drafts.

  • It can identify gaps.

  • It can recommend recognised good practice.

  • It can continuously monitor compliance.

  • It can help ensure consistency across thousands of systems.


That doesn't reduce the importance of experienced professionals. It allows them to spend less time producing documentation and more time applying expertise.

  • Instead of checking configurations manually, they interpret the findings.

  • Instead of writing policies from scratch, they decide which controls are appropriate.

  • Instead of compiling reports, they influence strategic decisions.


The value shifts from producing information to applying judgement.


Governance becomes even more important

There is another important lesson that organisations should not overlook. Agentic AI doesn't create good governance. It amplifies whatever already exists.


If an organisation has poor-quality data, inconsistent processes, unclear ownership or weak governance, AI will simply execute those problems faster and at greater scale.


Conversely, organisations with mature governance, reliable information and well-defined security standards will benefit disproportionately because AI has a solid foundation on which to operate.


The organisations that gain the greatest competitive advantage from AI won't necessarily be those with the most advanced AI. They'll be those with the clearest governance, the highest-quality data and the strongest decision-making.


What this means for business leaders

For CEOs, CIOs, CISOs and programme leaders, the challenge isn't deciding whether to adopt AI. That decision has largely been made.


The challenge is determining:

  • Where AI can safely automate work

  • Where humans must remain accountable

  • How governance should evolve alongside AI

  • How to improve organisational maturity before increasing automation


The organisations that answer these questions well will move faster, manage risk more effectively and make better-informed decisions.


Looking ahead

Every significant technology evolution has automated activity.

  • Cloud simplified infrastructure.

  • Automation reduced repetitive effort.

  • Machine learning accelerated pattern recognition.

  • Generative AI transformed knowledge work.

  • Agentic AI will increasingly coordinate and execute complex business activities.


Yet every stage has reinforced the same truth.

  • Technology can reason.

  • People provide judgement.

  • Technology can recommend.

  • People remain accountable.

  • Technology can increase efficiency.

  • People determine purpose.


The future doesn't belong to humans or AI.


It belongs to organisations that understand how to combine the consistency, speed and analytical capability of AI with the experience, judgement and accountability that only people can provide.


Because AI will increasingly become responsible for doing the work.

But people will always remain responsible for deciding what work is worth doing.


Rachel Gentry author of the article standing in front of a fireplace and smiling
Rachel Gentry, Founder of RTG Commercial Services Ltd. Rachel Gentry is a technology and information security leader with extensive experience delivering cyber security, governance, risk management and digital transformation across complex public and private sector organisations. She specialises in helping executive teams align technology, security and business strategy, with a particular focus on AI, secure-by-design principles, enterprise architecture and pragmatic governance. Through her writing, Rachel explores how emerging technologies can enable better decision-making, stronger organisational resilience and sustainable business growth.



 
 
 

Comments


bottom of page