AI Is Reshaping Cybersecurity Work, But Not Replacing Human Judgment
It’s also creating a dangerous gap between human authority and accountability.
New research from ISC2 suggests AI is reshaping cybersecurity roles, workflows, and decision-making while also increasing the importance of human judgment.
AI is already embedded in cybersecurity work, and we’re all familiar with the narrative that increasingly sophisticated AI tools mean many entry-level tasks—such as basic threat hunting and prioritization—can now be automated. But is that really happening? And is it reshaping the cybersecurity workforce as dramatically as many expected?
ISC2’s latest research, the 2026 AI Pulse Survey, offers some interesting insights into how this narrative is playing out. Based on responses from 856 cybersecurity professionals who use AI in their roles, the survey shows that while AI is saving time in some areas, it is also creating new work related to validation, oversight, and accountability.
AI Is Saving Time Early On, but Reintroducing It Later
One striking finding is that AI is not simply automating routine security tasks. It is increasing the amount of time cybersecurity practitioners spend deciding whether AI-generated outputs can be trusted. About two-thirds of respondents said they now spend more time deciding when to trust or act on AI-generated recommendations (65%) and reviewing or validating AI outputs (63%).
This challenges the common assumption that efficiency gains are an inherent benefit of automation and AI. In practice, cybersecurity professionals must still review, explain, and contextualize algorithmic recommendations before they can act on them safely.
The effect on day-to-day work is mixed. Just over one-third of respondents said they spend less time on hands-on tasks, while nearly as many said they spend more time performing them. A similar split appeared around system oversight. These findings suggest AI is not delivering a uniform productivity boost. Its value depends on the maturity of the tools, the quality of implementation, and teams’ ability to adapt their workflows around them.
Impact on Entry-Level Jobs
The survey also found significant shifts in early-career cybersecurity roles. Fifty-six percent of respondents said AI has somewhat or significantly reduced the need for entry-level positions over the past year. This suggests concerns about traditionally entry-level tasks—such as basic triage, reporting, and log review—being increasingly automated are not unfounded.
However, the picture becomes more nuanced when looking beyond that single finding. More than half of respondents (53%) believe AI is creating new types of entry-level roles, although the survey does not specify what those roles are. Nearly half also said AI has made them more optimistic about their long-term cybersecurity careers.
Nearly two-thirds said AI has not reduced the need for foundational cybersecurity skills.
This creates a challenge for CISOs and broader IT leadership. For years, automation has been viewed as an answer to skills shortages, but while AI may accelerate some processes, it is not yet capable of reliably eliminating the need for professionals who understand networks, systems, risk, and attacker behavior.
The Trust Problem Is Becoming an Operational Risk
The ISC2 survey revealed widespread concern about overreliance on AI recommendations and the potential for undetected errors to scale rapidly across systems. Many respondents also cited concerns about unclear accountability and the challenges of explaining AI-influenced decisions.
Human decision-makers will ultimately be held accountable for their actions, but that becomes problematic when AI makes mistakes. Some practitioners reported being expected to act on AI-generated security outputs without fully understanding how those outputs were produced. Nearly one-quarter said this happens often or very often, while another 40% said it happens sometimes.
That creates a dangerous gap between authority and accountability. If employees are responsible for outcomes, they need the time, training, and authority to challenge AI recommendations. Enterprises should establish clear policies that define when AI can recommend actions, when it can act autonomously, when human approval is required, and who owns the final decision.
Impact on Stress
Nearly half of respondents said AI has reduced their work-related stress over the past year, but almost one-third said it has increased it. The divide appears to be tied to workload and trust. Those reporting higher stress were more likely to spend additional time validating AI outputs.
As with other technologies, AI appears to increase stress for cybersecurity teams when it adds responsibility while reducing control. It is most likely to reduce stress when it removes friction from well-understood processes and leaves humans with clear authority over critical decisions.
Vulnerability Management
The survey also highlights the impact of the newest generation of AI models, including Anthropic’s Mythos, on vulnerability management.
A potential tidal wave of vulnerability discoveries is forcing organizations to rethink patching and prioritization. One respondent described vulnerability discovery as becoming a “high-throughput pipeline,” arguing that defenses must operate at the same speed through smarter workflows and automation rather than increased headcount.
Commenting on the research, ISC2 CEO Scott Beale, CC, said:
“AI is not replacing cybersecurity professionals; it is changing what the profession requires of them.
“As AI takes on more repetitive tasks, while also performing some complex cybersecurity analysis at speed and scale, cybersecurity roles are shifting toward higher-value work. This evolution is not limited to entry-level roles. It changes how work is distributed across security teams, making continued investment in governance, validation practices, mentoring, and skills development essential at every level.”
This article originally appeared on MES Computing’s sister site Computing.