Skip to content

AI as cybersecurity staff: How agentic systems are reshaping threat response

Cybersecurity teams are increasingly deploying AI-driven agentic systems to automate threat detection, response, and compliance. A new report by CertiK explores how these systems are being integrated as operational staff rather than mere tools, highlighting both the efficiency gains and the risks, including accountability gaps and regulatory uncertainty.

Editor, Lazyfounder

Published 6 min read
AI as cybersecurity staff: How agentic systems are reshaping threat response
Image: Credit: Canva via source

Cybersecurity teams are increasingly deploying AI-driven agentic systems to automate threat detection, response, and compliance. A new report by CertiK explores how these systems are being integrated as operational staff rather than mere tools, highlighting both the efficiency gains and the risks, including accountability gaps and regulatory uncertainty.

30 SEC SUMMARY

  • AI-driven agentic systems are reshaping cybersecurity by automating threat detection, response, and compliance tasks.
  • Security teams are treating AI as staff rather than tools, enabling autonomous investigation and action on threats.
  • Challenges include accountability, automation bias, and unclear regulatory frameworks for autonomous AI agents.
  • AML penalties exceeded $900 million in early 2025, accelerating demand for AI-driven compliance solutions.
  • CertiK recommends defined scopes of authority, decision records, and human oversight for AI agents.

TABLE OF CONTENTS

  • AI as cybersecurity staff: A new operational model
  • Automation in compliance and threat detection
  • Risks and regulatory challenges
  • The future of AI in security operations
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • AI’s role in security is shifting from anomaly detection to autonomous threat response, including suspending compromised accounts and investigating threats.
  • Agentic AI systems are being adopted to address talent shortages and the speed of modern cyberattacks.
  • AML penalties topped $900 million in early 2025, driving demand for AI-driven compliance solutions.
  • Risks include prompt injection attacks, automation bias, and unclear regulatory frameworks for auditing AI decisions.
  • CertiK recommends defined authority, decision records, and human oversight for AI agents in security operations.

AI as cybersecurity staff: A new operational model

Security teams are redefining AI’s role in their operations, moving beyond traditional use cases like anomaly detection. According to The Next Web, AI systems are now being treated less like tools and more like staff, capable of independently investigating threats, making decisions, and taking action. For example, agentic AI can suspend compromised accounts or flag suspicious activity without waiting for human intervention.

This shift is driven by the need for faster response times in industries like cryptocurrency and financial services, where attacks unfold at machine speed. The persistent talent shortage in cybersecurity has also accelerated adoption, as AI agents can handle repetitive or complex tasks at scale.

Automation in compliance and threat detection

AI’s expanding role extends to regulatory compliance, where agentic systems can automate due diligence on new customers and draft suspicious activity reports. This is particularly relevant in financial services, where anti-money laundering (AML) penalties exceeded $900 million in the first half of 2025 alone, according to The Next Web.

In the cryptocurrency sector, AI agents are being deployed to detect and respond to threats like oracle manipulation within the same block. For instance, these systems can pause vulnerable functions or trigger circuit breakers autonomously, reducing the window for exploits. The same report notes that North Korea-linked hackers converted 86.29% of stolen Ethereum into Bitcoin within a month of the Bybit exploit, underscoring the need for real-time intervention.

Risks and regulatory challenges

While AI agents offer efficiency gains, they also introduce new risks. The Next Web highlights concerns like prompt injection attacks, where tampered inputs could trick AI into approving fraudulent transactions or disabling security controls. Another challenge is automation bias, where human analysts grow overly reliant on AI decisions after repeated successes, potentially overlooking errors.

Regulatory uncertainty adds another layer of complexity. The report points out that frameworks for auditing autonomous AI agents are still undeveloped, leaving companies unclear about how to demonstrate compliance or accountability. CertiK warns that without proper oversight, AI-driven decisions could become a liability in regulatory or legal disputes.

To mitigate these risks, CertiK recommends defining clear scopes of authority for AI agents, maintaining records of their decisions, and establishing handoff points for human review. These measures aim to balance automation with accountability, ensuring AI operates within predictable boundaries.

The future of AI in security operations

The adoption of agentic AI is expected to change how security teams allocate their time. Instead of manually reviewing alerts, analysts may shift toward overseeing autonomous systems, validating their decisions, and refining their parameters. This could free up resources for higher-level strategic work, such as improving threat intelligence or designing more robust security protocols.

However, the transition also raises questions about workforce dynamics. As AI takes on more operational tasks, companies may need to upskill employees to manage these systems effectively. The report suggests that startups and enterprises alike must invest in governance frameworks to ensure AI aligns with organizational goals and regulatory expectations.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

Founders and operators in cybersecurity and compliance should see this shift as a double-edged sword. On one hand, agentic AI systems can significantly reduce response times and operational costs, especially in high-speed environments like crypto and financial services. On the other, the risks—automation bias, prompt injection attacks, and regulatory ambiguity—demand robust governance frameworks.

For startups, this trend could level the playing field, allowing smaller teams to compete with larger players by automating complex workflows. However, the lack of clear audit trails for AI decisions may become a liability if regulators or courts challenge outcomes. The CertiK recommendations are a practical starting point: define authority, document decisions, and keep humans in the loop.

Ultimately, the move toward AI as "staff" rather than tools signals a broader shift in how businesses manage trust and accountability. Founders should weigh the efficiency gains against the potential for unintended consequences, particularly in industries where mistakes carry heavy penalties.

Key takeaways

  • AI is evolving from a supportive tool in security to an autonomous agent capable of independent decision-making.
  • Agentic AI systems can perform tasks like suspending compromised accounts, investigating threats, and drafting compliance reports without human intervention.
  • The rise of AI-driven security is driven by factors like talent shortages, rising compliance penalties, and the need for real-time threat response.
  • Risks include prompt injection attacks, automation bias, and regulatory uncertainty around auditing AI decisions.
  • CertiK advises companies to implement clear scopes of authority, decision records, and human oversight for AI agents.

FAQ

What is an agentic AI system in cybersecurity?

An agentic AI system in cybersecurity is an autonomous tool designed to investigate threats, make decisions, and take actions—such as suspending compromised accounts or drafting compliance reports—without human intervention. Unlike traditional AI, which only flags anomalies, agentic AI operates independently within defined parameters.

What are the risks of using AI agents in security operations?

Key risks include prompt injection attacks, where malicious inputs can trick AI into making incorrect decisions, and automation bias, where humans over-rely on AI recommendations. Additionally, regulatory frameworks for auditing AI decisions are still unclear, creating potential compliance challenges.

How can companies mitigate risks when deploying AI agents?

CertiK recommends defining clear scopes of authority for AI agents, maintaining records of their decisions, and establishing human oversight mechanisms. This ensures accountability and reduces the likelihood of errors or regulatory violations.

Why are security teams adopting agentic AI systems?

Security teams are adopting these systems to address talent shortages, improve response times to cyber threats, and reduce the burden of repetitive tasks like compliance checks. The speed of modern attacks, particularly in industries like cryptocurrency, also demands faster-than-human intervention.

Related on Lazyfounder

Sources

  1. The Next Web · 2026-10-05
    Security teams are starting to treat AI like staff, and that means managing it

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us