Services Experience Recommendations Blog In the Media Contact Get in touch
← Back to Blog 03 Sep 2026

AI Doesn't Need Another Dashboard. It Needs Permission to Act.

AI Doesn't Need Another Dashboard. It Needs Permission to Act.

For years, cybersecurity has been obsessed with visibility. We wanted to see more of the network, collect more telemetry, correlate more events and detect threats earlier. So we built dashboards. Then we built better dashboards. Then we added machine learning to those dashboards. Now we are adding AI.

But at some point, we have to ask the obvious question: once we can see the attack, what are we actually prepared to do about it? I don't think the next big cybersecurity problem is going to be detection. I think it is going to be authority.

AI potentially gives us something security teams have wanted for decades: the ability to identify, understand and respond to an attack at machine speed. That matters because attacks are increasingly happening at a speed where the traditional SOC model simply cannot keep up.

Yet many organisations are deploying AI into exactly the same operating model they had before. The technology can detect something in seconds, perhaps understand what is happening and recommend the appropriate response, but somebody still has to approve what happens next.

At that point, you haven't really built autonomous defence. You've built an extraordinarily sophisticated alarm system. There is a contradiction here that we need to confront. We have spent years saying security teams are overwhelmed. There are too many alerts, too much infrastructure, too few skilled people and not enough time to investigate everything. We complain that humans cannot respond quickly enough.

Then we introduce technology capable of responding faster than humans and refuse to give it permission to act.

That doesn't make sense. If I don't have a mandate to respond to something while it is happening, I will always be conducting a post-mortem afterwards. It doesn't matter how intelligent the detection technology is. If the response mechanism is still waiting for somebody to make a decision, the attacker retains the advantage.

And this is not simply a problem created by AI. Most organisations haven't properly solved the question of response authority for their human security teams either.

Who is actually allowed to isolate a machine? Who can take a server offline? Who has the authority to interrupt a production process because there is evidence of an attack? In many organisations, those decisions are still unclear, negotiated during an incident or escalated through layers of management.

AI simply exposes how unsustainable that model has become.

If we genuinely want autonomous defence, the mandate has to come from the top. Boards and executive teams need to decide what authority they are prepared to give their security systems before the attack happens, not while everybody is watching it unfold. But giving AI permission to act creates another problem.

You also have to give it enough context to make the right decision. Imagine an AI system detects an infiltration on a machine and determines that the safest technical response is to isolate it. From a cybersecurity perspective, that may be absolutely correct.

Now imagine that machine controls a production line generating a million pounds an hour.

Suddenly the technically correct decision may be the wrong business decision.

Perhaps the threat is contained enough that remediation can happen over several hours without shutting the machine down. Perhaps taking it offline creates far more damage than allowing it to continue operating temporarily under tighter controls.

The AI cannot make that distinction unless the organisation has told it what that asset is, what it does and what happens to the business if it disappears. This is why asset knowledge and business context become so important in an AI-driven SOC.

Security teams have talked about asset management for decades and, frankly, many organisations still don't know what they have.

Shadow IT has made that difficult enough. Business units buy servers, deploy applications and connect devices without security necessarily knowing about them. Then we added cloud infrastructure, remote working, SaaS and increasingly distributed environments. The idea of a neat perimeter containing a perfectly maintained inventory disappeared years ago.

We tolerated that when the operating model was largely reactive. When something serious happened, an analyst investigated it and tried to establish the context.

This becomes much more tricky when AI is expected to make decisions autonomously.

An autonomous system needs to know that this is not just IP address X or endpoint Y. It needs to understand that this machine controls a manufacturing process, that this server supports SAP, that this database contains critical customer information or that taking this particular system offline will stop a revenue-generating operation.

Without that knowledge, autonomy becomes guesswork. Ironically, this is also an area where AI itself can help. It can discover and classify assets, identify relationships, find systems that nobody realised existed and reach out to business owners for missing context. Maintaining an accurate asset database does not need to remain the horrible, manual, multi-year exercise organisations have historically made it.

However the information has to exist somewhere. If the organisation itself doesn't understand what an asset does or how important it is, we cannot reasonably expect an AI system to make an intelligent business decision about it.

This is why I think the conversation around AI in the SOC needs to move beyond models and detection rates.

The technology is becoming capable enough.

The bigger question is whether organisations are operationally ready to use that capability.

This means answering some uncomfortable questions. What decisions can the AI make independently? What can it isolate? What can it block? Under what circumstances should it wait for human approval? Which assets are so critical that different rules apply? And who inside the organisation has the authority to establish those rules?

Those are governance questions, but they are also cybersecurity questions.

The answer cannot simply be that a human must approve everything consequential. That sounds safe until you consider the environment we are trying to defend.

When an attack can unfold in under a minute, waiting ten minutes for somebody to understand an alert, find the right person and approve a response is not caution. It is a vulnerability.

There will obviously be mistakes. Autonomous systems will sometimes make decisions we would rather they had not made. That is precisely why organisations need clear mandates, good asset intelligence, business context and carefully defined boundaries.

But eliminating autonomy because we are afraid of the consequences misses the point.

The objective shouldn't be to build AI that can never make a bad decision. It should be to give AI enough knowledge, context and authority to make the right decision quickly enough to matter.

Otherwise we will continue doing what the security industry has done for years: detecting attacks, generating alerts, filling dashboards and explaining afterwards what happened.

AI gives us the opportunity to change that, but only if we finally give it permission to act.