Research pillar · Zero Security Theatre

AI-native defensive security

AI makes some attacks cheaper and gives defenders more ways to watch systems continuously. This pillar asks which neglected defensive jobs machines can now do, and which decisions still need a person.

The question

Which defensive work should machines carry, and which decisions must remain with people?

Active · since 2026 · Zero Security Theatre

The division of labour

recommendation

Machines should increasingly do the remembering, the monitoring, the correlation, the testing, the evidence gathering, and the routine enforcement. People should make the decisions that carry consequence: isolate a system, disclose an incident, notify customers, invoke counsel, halt production, or accept a risk.

Models will make mistakes. Some mistakes can be caught on the next pass. An automated disclosure sent in error cannot be recalled, so a person keeps that decision.

Where the machine works and where the person decidesMachines can watch, compare, reconstruct events, and prepare evidence. People keep decisions with legal, clinical, financial, or reputational consequences.Machine workLog correlation and timelinesCredential and secret discoveryControl verification and testingEvidence assembly and draftingHuman decisionsIsolate or halt productionDisclose and notifyInvoke counsel and insuranceAccept or refuse a risk
A named person remains responsible for the consequential decisions.

Work that becomes possible at continuous scale

hypothesis

These jobs were sampled, scheduled, or skipped because nobody could watch them all the time. Machines may now run them continuously. The work still has to show that its error rate is acceptable.

Attack-path reconstruction

Maintaining a current map of how an ordinary foothold reaches valuable systems, updated as identities and configurations change.

Incident timeline construction

Assembling a defensible account of what happened from logs across systems, with each statement tied to its source record.

Control verification

Repeatedly exercising controls against the behaviours they claim to stop, rather than testing once a year.

Secrets and credential discovery

Continuous scanning of repositories, images, logs, and third-party surfaces for exposed material, with automated revocation paths.

Policy to evidence mapping

Connecting a written requirement to the specific operational query that demonstrates it, and flagging requirements with no source.

Adversarial and phishing simulation

Generating varied, current scenarios rather than reusing a template, then measuring behaviour rather than completion.

AI theatre is the obvious failure

inference

Every criticism this area makes of security products applies to AI security products with more force, because the output is fluent and therefore harder to doubt. A model that summarises alerts convincingly while missing the one that mattered produces confidence without resilience.

The test stays the same: what bad outcome does this prevent, detect, contain, recover from, or prove? Judge an AI capability by the same evidence as any other control.

What would prove us wrong?

unknown

The pillar assumes machine-carried continuous defensive work improves measured outcomes.

  • Evidence that AI-assisted triage lowers analyst vigilance enough to offset the coverage gain, a well-documented automation effect in other fields.
  • Results showing that generated incident timelines contain errors at rates that damage legal and regulatory positions.
  • Data showing that attackers gain more from the same capability than defenders do, shifting the correct investment toward recovery rather than detection.

Put this to work

Research decision record

Use the question “Which defensive work should machines carry, and which decisions must remain with people?” on a real case and produce a record another person can challenge.

For
Practitioners, researchers, founders, and operating leaders.
What you keep
A research decision record you can review, revise, and send.
What counts as sound
  • Answers a named decision
  • Separates evidence from assumptions
  • Includes the strongest contrary case
  • Names missing evidence
  • Ends with a test, owner, and date

The result is a working analysis. Check it against source evidence and qualified judgment.

Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.

Review the prompt

You can leave any field blank. The prompt will mark it as not provided.

If the record survives your review, send the question, evidence, unknowns, and requested next step.

Patterns and anti-patterns

  • Pattern

    Machine prepares, human decides

    Automate correlation, reconstruction, testing, and evidence assembly. Keep isolation, disclosure, notification, and risk acceptance with named people, and let authority move only as measured performance supports it.

  • Anti-pattern

    Accepting a fluent AI report as an assessment

    A polished report can sound surer than the facts allow. Require a source record for every generated claim so the reader can check it.

See the full patterns register

Evidence for this pillar

Read the full evidence library

Notes under this pillar

Design Patterns

Operating Theorys