AI in information security isn't Replacing Human Expertise – It's Raising Its Value
- Rachel Gentry
- Jul 10
- 5 min read
Why Agentic AI is the next evolution of enterprise technology, and why human judgement has never been more important.
Artificial Intelligence and Agentic AI represent the next stage in a decades-long evolution of enterprise technology. Rather than replacing human expertise, AI is shifting professional value towards judgement, governance and decision-making. Organisations that combine AI with experienced human insight will consistently make better business decisions than those that rely on automation alone.
The headlines often ask whether AI will replace professionals. I believe that's the wrong question.
The better question is this: How does AI change where professionals create value?
From my perspective, every major technology evolution has followed the same pattern. It removes routine effort, increases consistency and allows experienced people to focus on higher-value work.
Agentic AI is no different.
Key takeaways
Agentic AI is the next logical step after cloud, automation and machine learning
AI increasingly automates reasoning, but not accountability or judgement
Human expertise becomes more valuable as AI raises the quality and consistency of baseline analysis
In information security, AI can identify risks and recommend controls, but experienced professionals must balance business risk, cost and benefit
Organisations with mature governance, good data quality and clear ownership will realise the greatest value from AI
Technology has always evolved towards higher-value work
Looking back over the past three decades, enterprise technology has evolved through a series of connected steps rather than isolated revolutions.
Cloud computing removed much of the complexity of managing physical infrastructure.
Automation eliminated repetitive manual tasks and improved consistency.
Orchestration connected automated processes into end-to-end workflows.
Machine learning enabled systems to identify patterns and make increasingly accurate predictions.
Generative AI transformed the way we analyse information and create knowledge.
Agentic AI is the latest stage of that journey. Rather than simply responding to prompts, AI agents can plan, coordinate and execute multiple tasks towards a defined objective.
Each wave has automated more work.
Each wave has increased productivity.
And each wave has increased the relative value of human judgement.
The technology changes.
The purpose does not.
The Four Levels of Professional Value
One way to understand this evolution is to think about four distinct levels of professional value.
Data
What happened?
Traditional reporting systems answered this question.
Information
Why did it happen?
Analytics platforms and business intelligence tools helped explain events.
Insight
What should I pay attention to?
Modern AI is exceptionally good at identifying trends, highlighting anomalies and surfacing opportunities.
Judgement
What should we actually do?
This is where experienced professionals remain indispensable.
Judgement requires context.
It requires understanding organisational culture, commercial priorities, stakeholder expectations, regulatory obligations and long-term strategy.
Most importantly, judgement requires accountability.
Reasoning can increasingly be automated.
Accountability cannot.
The Xero example
The accounting profession provides an excellent illustration. Modern accounting platforms can analyse historical transactions, identify spending trends and forecast future cash flow. Increasingly, AI can warn a business that it is likely to experience a cash flow shortfall weeks before it happens.
That insight is incredibly valuable.
But it isn't the solution.
The real value comes from the accountant or business adviser who understands the wider context and asks questions such as:
Should payment terms be renegotiated?
Would short-term finance be appropriate?
Should investment be delayed?
Are operational changes available that improve liquidity without harming growth?
What are the commercial and tax implications of each option?
The AI identifies the problem.
The adviser provides the judgement.
One without the other is incomplete.
AI in information security presents exactly the same opportunity
Information security is frequently portrayed as one of the professions most likely to be transformed by AI. I believe that's true - but not because AI replaces security professionals. It changes how they spend their time.
Today's AI systems can already:
Review cloud environments against recognised security benchmarks
Compare configurations with ISO 27001, NIST Cybersecurity Framework and CIS Benchmarks
Identify excessive permissions and configuration weaknesses
Detect inconsistencies across security controls
Generate draft risk assessments
Recommend remediation actions
Produce security documentation and evidence
Agentic AI will take this much further by continuously monitoring environments, correlating findings across multiple systems and proactively recommending improvements before formal reviews even begin. This raises the baseline for every organisation. But it doesn't eliminate the need for expertise.
Experienced security leaders still decide:
Which risks genuinely matter
Which recommendations justify investment
What level of residual risk is acceptable
When security should enable delivery rather than delay it
How to balance cyber risk against commercial opportunity
Whether a control is proportionate for the organisation
These are business decisions.
Not technical ones.
Technology can recommend.
People remain accountable.
AI raises the baseline - not the ceiling
One of the most exciting aspects of AI is its ability to democratise good practice.
Many organisations struggle to maintain consistent documentation, perform comprehensive risk assessments or implement recognised security frameworks because specialist expertise is expensive and often scarce.
AI changes that.
It can produce high-quality first drafts.
It can identify gaps.
It can recommend recognised good practice.
It can continuously monitor compliance.
It can help ensure consistency across thousands of systems.
That doesn't reduce the importance of experienced professionals. It allows them to spend less time producing documentation and more time applying expertise.
Instead of checking configurations manually, they interpret the findings.
Instead of writing policies from scratch, they decide which controls are appropriate.
Instead of compiling reports, they influence strategic decisions.
The value shifts from producing information to applying judgement.
Governance becomes even more important
There is another important lesson that organisations should not overlook. Agentic AI doesn't create good governance. It amplifies whatever already exists.
If an organisation has poor-quality data, inconsistent processes, unclear ownership or weak governance, AI will simply execute those problems faster and at greater scale.
Conversely, organisations with mature governance, reliable information and well-defined security standards will benefit disproportionately because AI has a solid foundation on which to operate.
The organisations that gain the greatest competitive advantage from AI won't necessarily be those with the most advanced AI. They'll be those with the clearest governance, the highest-quality data and the strongest decision-making.
What this means for business leaders
For CEOs, CIOs, CISOs and programme leaders, the challenge isn't deciding whether to adopt AI. That decision has largely been made.
The challenge is determining:
Where AI can safely automate work
Where humans must remain accountable
How governance should evolve alongside AI
How to improve organisational maturity before increasing automation
The organisations that answer these questions well will move faster, manage risk more effectively and make better-informed decisions.
Looking ahead
Every significant technology evolution has automated activity.
Cloud simplified infrastructure.
Automation reduced repetitive effort.
Machine learning accelerated pattern recognition.
Generative AI transformed knowledge work.
Agentic AI will increasingly coordinate and execute complex business activities.
Yet every stage has reinforced the same truth.
Technology can reason.
People provide judgement.
Technology can recommend.
People remain accountable.
Technology can increase efficiency.
People determine purpose.
The future doesn't belong to humans or AI.
It belongs to organisations that understand how to combine the consistency, speed and analytical capability of AI with the experience, judgement and accountability that only people can provide.
Because AI will increasingly become responsible for doing the work.
But people will always remain responsible for deciding what work is worth doing.





Comments