I have had dozens of conversations with security leaders over the last couple of months. Prospects, CISOs, practitioners, people I met walking the floor at Gartner. Different industries, different company sizes, different stacks. And almost every one of them, in their own way, said the same thing to me.
They are anxious about AI. Not in a vague, abstract way. In a specific, keeps-me-up-at-night way.
If I had to boil down everything I am hearing into a single sentence, it would be this: AI is the unknown. It presents a new attack surface, teams do not feel armed to defend it, and most leaders genuinely do not know where to start. That is the feeling underneath almost every conversation I have right now. And I want to talk about it honestly, because I think we are making it far harder than it needs to be.
You would never walk into Home Depot looking for a problem to solve
Here is the pattern I keep seeing. A CISO feels the pressure around AI, so they start shopping. And the market is more than happy to sell to them. There is a flood of tools right now, all promising to secure your AI, all with a slightly different acronym and a slightly cooler logo. So the CISO buys another one. And another. And now they have a pile of things doing a version of the same job, more complexity, and somehow less clarity than when they started.
We would never do this in any other part of our lives. You would never walk into Home Depot and wander the aisles looking for tools in the hope that one of them solves a problem you have not defined yet. You would look at your problem first, analyze it, and then decide what the ideal solution actually looks like. And then, and only then, you would go find the things that help you get there.
Somewhere along the way in security, we flipped that order. We grab the tools first and hope they add up to a strategy. They never do.
So when a leader tells me they are overwhelmed by AI security options, my first question is not “what have you looked at.” It is “what are you actually trying to solve.” And the honest answer, more often than not, is some version of: “I do not know what my people are doing with AI, or what these agents can access inside my environment, so I do not know where to start securing it.”
That is a real problem, and it’s worth solving. But you cannot solve it by buying a dozen products and hoping the gap closes.
The reframe that calms the room
Here is the part that tends to catch people off guard, and it is probably the most important thing I say in these conversations.
This is not a new problem.
I know that is not the popular take. It is very fashionable right now to jump on LinkedIn and declare AI the biggest thing to happen to security since the internet. And to be fair, those people are not wrong about the scale. AI is enormous. But our approach to it is no different than it was when SaaS exploded during the cloud transformation fifteen years ago, or when the internet first flooded the enterprise with users we did not know how to account for.
The playbook has not changed. You discover what is in your environment. You get observability into what it is doing. You build a response capability for when something drifts off course. And you wrap the whole thing in policy, because a policy without something to enforce it is just a document. That is it. Copy that, paste it, and run it for SaaS, for cloud, for digital transformation, for AI. It is always the same.
What is actually happening is that AI arrived so fast that people have not had a moment to sit back and look at it analytically. The speed is what makes it feel insurmountable, not the substance. Once you slow down and name the problem, it stops looking like a monster and starts looking like a category you already know how to defend.
And the category is insider threat.
One of our founders likes to call what we do a neo-retro technology, and I have never found a better description. Because strip away the noise and an AI agent is not some alien new species. It is an account that works at machine speed but looks like a human. It authenticates with real credentials, inherits real permissions, and it acts inside your environment as a trusted identity. That is a non-human identity, and it is the oldest problem in our field wearing a new costume. AI agents are your insider threat. So let us monitor them the way we have always monitored insiders, just faster, and let us stop pretending the fundamentals expired.
What that actually looks like on the ground
If you want proof that this is an old problem in a new costume, look at what leaders are actually bringing to me. One of the most striking examples right now is the fake employee problem, where a completely legitimate, authenticated login turns out to belong to someone who is not who or where they say they are. It is showing up in fintech and healthcare, and nearly everyone who raises it assumes they are the only one dealing with it. They are not.
That story deserves its own piece, and it is the next one I am writing, so I will not compress it here.
The point for now is simpler. When you strip these situations down, they are all the same shape: a trusted identity, real permissions, and behavior behind the login that nobody approved. That is insider threat. The faces keep changing while the pattern stays exactly the same.
Why I would rather watch the driveway than the broken window
The other shift I am hearing leaders reach for, even when they do not have the words for it, is a move from reactive to proactive.
Think about how you actually behave in the real world. If a car is parked outside your house and you watch people get out, walk into your backyard, look in the windows, and try the front door to see if it is unlocked, you do not wait for the break-in. You call the police right then. You have seen the sequence of footsteps that tells you what comes next, and you act on it.
For some reason, in security we do the opposite. We build our programs to respond after the compromise is already complete. Someone has already downloaded the files, the account has already done the damage. And we call that detection. What leaders are telling me, in their own language, is that they are tired of waiting for the break-in. The threats move too fast to depend on an analyst getting their coffee, driving in, sitting down, and clicking approve. They want action to happen in near real time, as the footsteps accumulate.
But here is the nuance that surprised me. They do not want you slamming every account shut. What they want is measured, proportional action. And the concept that lands hardest is what we call a trust budget, though most people do not know the name. The idea is simple. Every identity earns a level of trust. Each risky or anomalous step spends some of it. One deviation, a small deduction. Another, a bigger one. Cross a threshold, and access gets softly contained before it is ever fully cut off.
Picture a developer whose account starts behaving strangely. Instead of killing the account, you quietly revoke the ability to push code or pull down the repository, while leaving them logged in. You have not fired them or locked them out. You have moved them from a position where they could do real harm into one where they cannot. It is the difference between a jail cell and a padded room. You might still be dangerous, but there is nothing around you left to damage.
I expected pushback on this, because people usually hate the idea of automation taking action on its own. But the response has been the opposite. Because the action is moderate, leaders are comfortable with it. It takes the risk from critical to moderate the instant it triggers, it happens while the analysts are asleep, and then the humans wake up and do the real work. We are not replacing anyone. We are just refusing to wait for the window to break.
The one thing I would tell every security leader right now
If you take nothing else from this, take this.
Stop looking for a product that will solve your problems, and start looking for solutions to the actual problem you have. That is how you win this game over the long run.
- Do the analysis work.
- Ask what problem am I truly trying to solve, not who has the best logo, not whether buying another AI tool will plug the gap.
Because everyone’s problem is genuinely different. One company is worried about agents running up queries against their data warehouse. Another is worried about an employee using an unsanctioned AI tool inside a code repository. Those are specific, and they deserve specific answers, not a shopping spree.
And remember how durable the fundamentals are. When I started in this field, the number one issue in the industry was phishing. It is 2026, we have a million tools built to stop it, and the number one issue is still phishing. The face of the threat changes. Quantum will bring its own version of a problem we have already solved before, and we will solve it again the same way, with cryptography we already understand. AI agents are an insider threat problem, and the uncomfortable truth is we never fully solved insider threat to begin with. That is not a reason to panic. It is a reason to lean on what we already know.
The problem in front of you does not get harder than the hardest problems we have already faced. So do not make it harder on yourself than it needs to be. Name the problem. Then go solve it.



